Roundcube Webmail是一款基于浏览器的开源IMAP客户端,它支持地址薄管理、信息搜索、拼写检查等。 Roundcube Webmail 1.5.7及之前版本和1.6.8之前的1.6.x版本存在安全漏洞,该漏洞源于存在跨站脚本漏洞,远程攻击者可以通过带有危险Content-Type标头的恶意电子邮件附件窃取和发送受害者的电子邮件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | POCof Roundcube vulnerabilities CVE-2024-42008 and CVE-2024-42010 | https://github.com/victoni/Roundcube-CVE-2024-42008-and-CVE-2024-42010-POC | POC Details |
| 2 | The scripts in this repository are made to abuse CVE-2024-42008 and CVE-2024-42009. Both of these CVEs are vulnerabilities found on Roundcube 1.6.7 | https://github.com/Foxer131/CVE-2024-42008-9-exploit | POC Details |
| 3 | None | https://github.com/rpgsec/Roundcube-CVE-2024-42008-POC | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-7466 | 2.4 LOW | PMWeb Web Application Firewall cross site scripting |
| CVE-2024-41380 | Microweber 安全漏洞 | |
| CVE-2024-41200 | KMPlayer 安全漏洞 | |
| CVE-2024-41376 | DzzOffice 安全漏洞 | |
| CVE-2024-41381 | microweber 安全漏洞 | |
| CVE-2024-40096 | Who - Caller ID, Spam Block 安全漏洞 | |
| CVE-2024-40531 | UAB Pantera CRM 安全漏洞 | |
| CVE-2024-40530 | UAB Pantera CRM 安全漏洞 | |
| CVE-2024-40498 | PuneethReddyHc Online Shopping System Advanced 安全漏洞 | |
| CVE-2024-42010 | Roundcube Webmail 安全漏洞 | |
| CVE-2024-42009 | Roundcube Webmail 安全漏洞 |
No comments yet