RoundCube Webmail Multiple HTML-injection Vulnerabilities
BID:61976
Info
RoundCube Webmail Multiple HTML-injection Vulnerabilities
| Bugtraq ID: | 61976 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-5645 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2013 12:00AM |
| Updated: | May 07 2015 05:07PM |
| Credit: | und3r |
| Vulnerable: |
S.u.S.E. openSUSE 12.3 S.u.S.E. openSUSE 12.2 Roundcube Webmail 0.8.6 Roundcube Webmail 0.8.5 Roundcube Webmail 0.7.3 Roundcube Webmail 0.7.2 Roundcube Webmail 0.9.2 Roundcube Webmail 0.8.4 Roundcube Webmail 0.6 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 |
| Not Vulnerable: |
Roundcube Webmail 0.9.3 |
Solution / Fix
RoundCube Webmail Multiple HTML-injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
MandrakeSoft Enterprise Server 5
Mandriva Business Server 1 X86 64
MandrakeSoft Enterprise Server 5 x86_64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
MandrakeSoft Enterprise Server 5
-
Mandriva roundcubemail-0.7.4-0.2mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
Mandriva Business Server 1 X86 64
-
Mandriva roundcubemail-0.8.6-1.1.mbs1.noarch.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva roundcubemail-0.7.4-0.2mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/