[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-4078Date: (C)2011-11-03   (M)2023-12-22


include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an arbitrary URL, and cause a denial of service (resource consumption and inbox outage), via a Subject header containing only a URL, a related issue to CVE-2011-3379.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
BID-50402
SSRT100877
http://openwall.com/lists/oss-security/2011/10/26/6
http://trac.roundcube.net/ticket/1488086
webmail-uri-dos(71025)

CPE    28
cpe:/a:roundcube:webmail:0.3:beta
cpe:/a:roundcube:webmail:0.1:beta2
cpe:/a:roundcube:webmail:0.5.3
cpe:/a:roundcube:webmail:0.1:rc2
...
CWE    1
CWE-399
OVAL    1
oval:org.secpod.oval:def:1300054

© SecPod Technologies