NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86338  CVE-2015-5381  Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.    4.3  Medium  2017-06-04  2017-05-31  View
86339  CVE-2015-5382  program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.    Medium  2017-06-04  2017-05-31  View
86340  CVE-2015-5383  Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) logs directory.    Medium  2017-06-04  2017-05-31  View
86342  CVE-2015-5468  Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to includes/download.php.    Medium  2017-06-04  2017-06-01  View
86343  CVE-2015-5469  Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter to includes/download.php.    Medium  2017-06-04  2017-05-31  View

Page 1542 of 17672, showing 5 records out of 88360 total, starting on record 7706, ending on 7710

Actions