LWN.net Logo

roundcubemail: cross-site scripting

Package(s):roundcubemail CVE #(s):CVE-2007-6321
Created:June 16, 2008 Updated:June 18, 2008
Description:

From the Red Hat bugzilla:

Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and earlier versions, when using Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via style sheets containing expression commands.

Alerts:
Fedora FEDORA-2008-5333 2008-06-14
Fedora FEDORA-2008-5342 2008-06-14
Fedora FEDORA-2008-5315 2008-06-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds