Aleksander Machniak
80 exploits
Active since Aug 2012
Roundcube Webmail - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS 8.1
Roundcube Webmail - Server-Side Request Forgery (SSRF)
CVSS 7.2
Roundcube Webmail - Always-Incorrect Control Flow Implementation
CVSS 7.5
Roundcube Webmail - Incorrect Resource Transfer Between Spheres
CVSS 6.5
Roundcube Webmail - Incorrect Resource Transfer Between Spheres
CVSS 6.5
Roundcube Webmail - Incorrect Resource Transfer Between Spheres
CVSS 3.7
Roundcube Webmail - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS 7.2
Roundcube Webmail - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS 4.4
Roundcube Webmail - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS 8.1
Roundcube Webmail - Server-Side Request Forgery (SSRF)
CVSS 7.2
Roundcube Webmail - Always-Incorrect Control Flow Implementation
CVSS 7.5
Roundcube Webmail - Incorrect Resource Transfer Between Spheres
CVSS 6.5
Roundcube Webmail - Incorrect Resource Transfer Between Spheres
CVSS 6.5
Roundcube Webmail - Incorrect Resource Transfer Between Spheres
CVSS 3.7
Roundcube Webmail - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS 7.2
Roundcube Webmail - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS 4.4
Roundcube Webmail < 0.8.1 - Cross-Site Scripting via Email Signature
Roundcube Webmail <1.0.6, <1.1.2 - Info Disclosure
CVSS 6.5
Roundcube Webmail < 1.1.8 and 1.2.x < 1.2.4 - Cross-Site Scripting via SVG CSS Token Sequence
CVSS 6.1
Roundcube Webmail < 1.4.4 - Stored Cross-Site Scripting via HTML Message CDATA
CVSS 6.1
Roundcube Webmail <1.4.4 - Path Traversal
CVSS 9.8
Roundcube Webmail < 1.4.4 - Remote Code Execution via Shell Metacharacters in Image Configuration
CVSS 9.8
Roundcube Webmail < 1.3.12 and 1.4.x < 1.4.5 - Stored Cross-Site Scripting via XML Attachment Preview
CVSS 6.1
Roundcube Webmail < 1.3.15 and 1.4.8 - Stored Cross-Site Scripting via SVG in HTML Messages
CVSS 6.1
Roundcube < 1.3.17 and 1.4.x < 1.4.12 - SQL Injection via Search Parameters
CVSS 9.8