CVE-2015-2180

The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:roundcube:webmail:*:rc:*:*:*:*:*:*

Information

Published : 2017-01-30 14:59

Updated : 2018-10-30 09:27


NVD link : CVE-2015-2180

Mitre link : CVE-2015-2180


JSON object : View

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Advertisement

dedicated server usa

Products Affected

roundcube

  • webmail