Aleksander Machniak
80 exploits
Active since Aug 2012
Roundcube Webmail < 1.3.17 and 1.4.x < 1.4.12 - Cross-Site Scripting via Attachment Filename Extension
CVSS 6.1
Roundcube < 1.3.17 and 1.4.x < 1.4.12 - SQL Injection via Search Parameters
CVSS 9.8
Roundcube < 1.4.13 and 1.5.x < 1.5.2 - Cross-Site Scripting via Crafted CSS Token Sequences
CVSS 6.1
Crypt_GPG < 1.6.7 - Argument Injection via GPG Command Options
CVSS 5.3
Roundcube <1.4.14, <1.5.4, <1.6.3 - XSS
CVSS 6.1
Roundcube Webmail < 1.4.15, 1.5.x < 1.5.5, 1.6.x < 1.6.4 - Stored Cross-Site Scripting via SVG in HTML Email
CVSS 6.1
Roundcube Webmail < 1.5.7 and 1.6.x < 1.6.7 - Cross-Site Scripting via SVG Animate Attributes
CVSS 6.1
Roundcube Webmail < 1.5.10 and 1.6.x < 1.6.11 - Authenticated Remote Code Execution via PHP Object Deserialization
CVSS 9.9
Roundcube Webmail <1.5.13 & <1.6.13 - XSS
CVSS 4.7
Roundcube Webmail <1.5.13 & <1.6.13 - XSS
CVSS 4.7
Roundcube Webmail <1.5.13 & <1.6.13 - XSS
CVSS 4.7
Roundcube Webmail <1.5.13 & <1.6.13 - XSS
CVSS 4.7
Roundcube Webmail <1.5.14 - Deserialization
CVSS 3.7
Roundcube Webmail < 1.5.14, 1.6.0-1.6.14, 1.7-beta-1.7-rc5 - IMAP Injection via Search Command Arguments
CVSS 3.1
Roundcube Webmail <1.5.14, 1.6.0-1.6.14, 1.7-beta-1.7-rc5 - Stored Cross-Site Scripting via HTML Attachment Preview
CVSS 6.1
Roundcube Webmail <1.5.14 - Auth Bypass
CVSS 4.2
Roundcube Webmail <1.5.14, 1.6.0-1.6.14, 1.7-beta-1.7-rc5 - Information Disclosure via Background Attribute Bypass
CVSS 5.3
Roundcube Webmail < 1.5.14, 1.6.0-1.6.14, 1.7-beta-1.7-rc5 - Information Disclosure via SVG Animate Attribute Bypass
CVSS 5.3
Roundcube Webmail <1.5.14 - CSS Sanitization Bypass
CVSS 5.3
Roundcube Webmail < 1.5.15, 1.6.0-1.6.15, 1.7-beta-1.7-rc5 - Information Disclosure via SVG Animate Element Bypass
CVSS 5.3
Roundcube Webmail <1.5.13 & <1.6.13 - XSS
CVSS 4.3
Roundcube Webmail <1.5.13 & <1.6.13 - XSS
CVSS 4.7
Roundcube Webmail <1.5.14 - Deserialization
CVSS 3.7
Roundcube Webmail < 1.5.14, 1.6.0-1.6.14, 1.7-beta-1.7-rc5 - IMAP Injection via Search Command Arguments
CVSS 3.1
Roundcube Webmail <1.5.14, 1.6.0-1.6.14, 1.7-beta-1.7-rc5 - Stored Cross-Site Scripting via HTML Attachment Preview
CVSS 6.1