CVE-2015-2180Injection in Webmail

CWE-74Injection8 documents6 sources
Severity
8.8HIGHNVD
EPSS
2.7%
top 14.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 30
Latest updateMay 14

Description

The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

3
GHSA
GHSA-hp2w-q4f4-jq5w: The DBMail driver in the Password plugin in Roundcube before 12022-05-14
OSV
CVE-2015-2180: The DBMail driver in the Password plugin in Roundcube before 12017-01-30
CVEList
CVE-2015-2180: The DBMail driver in the Password plugin in Roundcube before 12017-01-30

📋Vendor Advisories

1
Debian
CVE-2015-2180: roundcube - The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote...2015

💬Community

3
Bugzilla
CVE-2015-2180 roundcubemail: New password not sanitized against injecting shell meta characters in DBMail driver [epel-6]2017-01-31
Bugzilla
CVE-2015-2180 roundcubemail: New password not sanitized against injecting shell meta characters in DBMail driver [epel-5]2017-01-31
Bugzilla
CVE-2015-2180 roundcubemail: New password not sanitized against injecting shell meta characters in DBMail driver2017-01-31
CVE-2015-2180 — Injection in Roundcube Webmail | cvebase