FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-2937

This CVE name corresponds to:

Entered Topic
2011-09-13 roundcube -- XSS vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-2937
Phase Assigned(20110727)

Description

Cross-site scripting (XSS) vulnerability in the UI messages functionality in Roundcube Webmail before 0.5.4 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.

References

Source Reference
MLIST [oss-security] 20110818 CVE request: roundcube XSS before 0.5.4
MLIST [oss-security] 20110819 Re: CVE request: roundcube XSS before 0.5.4
CONFIRM http://sourceforge.net/news/?group_id=139281&id=302769
CONFIRM http://trac.roundcube.net/browser/tags/roundcubemail/v0.5.4/CHANGELOG
CONFIRM http://trac.roundcube.net/changeset/5037
CONFIRM http://trac.roundcube.net/ticket/1488030
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=731786
CONFIRM http://support.apple.com/kb/HT5130
APPLE APPLE-SA-2012-02-01-1
BID 49229