Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via vectors involving an embedded image attachment.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2012-1279 | Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via vectors involving an embedded image attachment. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-09-16T19:01:14.157Z
Reserved: 2012-02-21T00:00:00Z
Link: CVE-2012-1253
No data.
Status : Deferred
Published: 2012-06-04T15:55:01.947
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-1253
No data.
OpenCVE Enrichment
No data.
EUVD