LWN.net Logo

roundcubemail: cross-site scripting

Package(s):roundcubemail CVE #(s):CVE-2012-6121
Created:February 18, 2013 Updated:February 20, 2013
Description: From the Red Hat bugzilla:

A cross-site scripting (XSS) flaws were round in the way Round Cube Webmail, a browser-based multilingual IMAP client, performed sanitization of 'data' and 'vbscript' URLs. A remote attacker could provide a specially-crafted URL that, when opened would lead to arbitrary JavaScript, VisualBasic script or HTML code execution in the context of Round Cube Webmail's user session.

Alerts:
Fedora FEDORA-2013-2195 2013-02-18
Fedora FEDORA-2013-2177 2013-02-18
openSUSE openSUSE-SU-2013:0307-1 2013-02-19

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds