Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2012-4668
HistoryAug 25, 2012 - 10:29 a.m.

CVE-2012-4668

2012-08-2510:29:53
Debian Security Bug Tracker
security-tracker.debian.org
14
cve-2012-4668
cross-site scripting
roundcube webmail
remote attackers
arbitrary web script
html
email signature
unix

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.003

Percentile

71.3%

Cross-site scripting (XSS) vulnerability in Roundcube Webmail 0.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the signature in an email.

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.003

Percentile

71.3%

Related for DEBIANCVE:CVE-2012-4668