Aleksander Machniak
80 exploits
Active since Aug 2012
Roundcube Webmail < 1.4.15, 1.5.x < 1.5.5, 1.6.x < 1.6.4 - Stored Cross-Site Scripting via SVG in HTML Email
CVSS 6.1
Roundcube Webmail < 1.5.7 and 1.6.x < 1.6.7 - Stored Cross-Site Scripting via List Columns from User Preferences
CVSS 6.1
Roundcube Webmail < 1.5.7 and 1.6.x < 1.6.7 - OS Command Injection via im_convert_path and im_identify_path
CVSS 9.8
Roundcube Webmail < 1.5.12 and 1.6 < 1.6.12 - Information Disclosure via HTML Style Sanitizer
CVSS 7.2
Roundcube Webmail <1.5.13 & <1.6.13 - XSS
CVSS 4.7