Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-1492
Description:steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Style Sheets (CSS) stylesheet, which allows remote authenticated users to trigger arbitrary outbound TCP connections from the server, and possibly obtain sensitive information, via a crafted request.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-1492
44050
http://secunia.com/advisories/44050
[oss-security] 20110324 CVE request: roundcube < 0.5.1 CSRF
http://openwall.com/lists/oss-security/2011/03/24/3
[oss-security] 20110324 Re: CVE request: roundcube < 0.5.1 CSRF
http://openwall.com/lists/oss-security/2011/03/24/4
[oss-security] 20110404 Re: CVE request: roundcube < 0.5.1 CSRF
http://openwall.com/lists/oss-security/2011/04/04/50
http://trac.roundcube.net/changeset/4488
http://trac.roundcube.net/changeset/4488
http://trac.roundcube.net/wiki/Changelog
http://trac.roundcube.net/wiki/Changelog
roundcube-modcss-security-bypass(66613)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66613




© 1998-2025 E-Soft Inc. All rights reserved.