CVE-2015-8770
published 2016-01-29CVE-2015-8770: Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows…
PriorityP261high7.5CVSS 3.0
AVNACHPRLUINSUCHIHAH
EXPLOIT
EPSS
22.21%
97.4th percentile
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | roundcube | < roundcube 1.1.4+dfsg.1-1 (bookworm) | roundcube 1.1.4+dfsg.1-1 (bookworm) |
| roundcube | roundcube_webmail | <= 1.0.7 | — |
| roundcube | roundcube_webmail | — | — |
| roundcube | roundcube_webmail | — | — |
| roundcube | roundcube_webmail | — | — |
| roundcube | roundcube_webmail | — | — |
| roundcube | roundcube_webmail | >= 0 < 1.1.4+dfsg.1-1 | 1.1.4+dfsg.1-1 |
| roundcube | roundcube_webmail | >= 0 < 1.1.4+dfsg.1-1 | 1.1.4+dfsg.1-1 |
| roundcube | roundcube_webmail | >= 0 < 1.1.4+dfsg.1-1 | 1.1.4+dfsg.1-1 |
| roundcube | roundcube_webmail | >= 0 < 1.1.4+dfsg.1-1 | 1.1.4+dfsg.1-1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor HTTP POST requests to /index.php containing path traversal sequences (e.g. '../../') in the '_skin' parameter ↗
- →A simple exploit will send HTTP POST request to vulnerable script and will load a new skin from '/tmp' folder — alert on _skin values referencing /tmp or other non-standard paths ↗
- →If 'skin_include_php' is enabled in Roundcube config, successful exploitation allows arbitrary PHP code execution from attacker-controlled skin files — flag this config setting as a high-risk indicator ↗
- ·Exploitation severity escalates to RCE only when 'skin_include_php' is set to true in Roundcube configuration ↗
- ·Exploitation requires both valid Roundcube user credentials AND the ability to create files on the vulnerable host (e.g., shared hosting environments) ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xc26-wfvp-2xpj: Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html
ghsa_unreviewed·2022-05-14
CVE-2015-8770 [HIGH] CWE-22 GHSA-xc26-wfvp-2xpj: Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.
OSV
CVE-2015-8770: Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html
osv·2016-01-29·CVSS 7.5
CVE-2015-8770 [HIGH] CVE-2015-8770: Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.
Debian
CVE-2015-8770: roundcube - Directory traversal vulnerability in the set_skin function in program/include/rc...
vendor_debian·2015·CVSS 7.5
CVE-2015-8770 [HIGH] CVE-2015-8770: roundcube - Directory traversal vulnerability in the set_skin function in program/include/rc...
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.
Scope: local
bookworm: resolved (fixed in 1.1.4+dfsg.1-1)
bullseye: resolved (fixed in 1.1.4+dfsg.1-1)
forky: resolved (fixed in 1.1.4+dfsg.1-1)
sid: resolved (fixed in 1.1.4+dfsg.1-1)
trixie: resolved (fixed in 1.1.4+dfsg.1-1)
No detection rules found.
Bugzilla
CVE-2015-8770 roundcubemail: roundcube: remote code execution [epel-all]
bugzilla·2016-01-15·CVSS 7.5
CVE-2015-8770 [HIGH] CVE-2015-8770 roundcubemail: roundcube: remote code execution [epel-all]
CVE-2015-8770 roundcubemail: roundcube: remote code execution [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2015-8770 roundcube: remote code execution
bugzilla·2016-01-15·CVSS 7.5
CVE-2015-8770 [HIGH] CVE-2015-8770 roundcube: remote code execution
CVE-2015-8770 roundcube: remote code execution
High-Tech Bridge Security Research Lab discovered a path traversal vulnerability in a popular webmail client Roundcube. Vulnerability can be exploited to gain access to sensitive information and under certain circumstances to execute arbitrary code and totally compromise the vulnerable server.
The vulnerability exists due to insufficient sanitization of "_skin" HTTP POST parameter in "/index.php" script when changing between different skins of the web application. A remote authenticated attacker can use path traversal sequences (e.g. "../../") to load a new skin from arbitrary location on the system, readable by the webserver.
Original report with reproducer:
http://seclists.org/bugtraq/2016/Jan/60
Discussion:
Created roundcubemail track
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00030.htmlhttp://packetstormsecurity.com/files/135274/Roundcube-1.1.3-Path-Traversal.htmlhttp://trac.roundcube.net/changeset/10e5192a2b/githubhttp://trac.roundcube.net/ticket/1490620http://www.debian.org/security/2016/dsa-3541http://www.securityfocus.com/archive/1/537304/100/0/threadedhttps://roundcube.net/news/2015/12/26/updates-1.1.4-and-1.0.8-released/https://security.gentoo.org/glsa/201603-03https://www.exploit-db.com/exploits/39245/https://www.htbridge.com/advisory/HTB23283http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00030.htmlhttp://packetstormsecurity.com/files/135274/Roundcube-1.1.3-Path-Traversal.htmlhttp://trac.roundcube.net/changeset/10e5192a2b/githubhttp://trac.roundcube.net/ticket/1490620http://www.debian.org/security/2016/dsa-3541http://www.securityfocus.com/archive/1/537304/100/0/threadedhttps://roundcube.net/news/2015/12/26/updates-1.1.4-and-1.0.8-released/https://security.gentoo.org/glsa/201603-03https://www.exploit-db.com/exploits/39245/https://www.htbridge.com/advisory/HTB23283
2016-01-29
Published