CVE-2007-6321
RoundCube webmail <2007-12-09 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and earlier versions, when using Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via style sheets containing expression commands.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Tomas Kuliavas · textwebappsphp
https://www.exploit-db.com/exploits/30877
References (7)
Scores
EPSS
0.0692
EPSS Percentile
91.3%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
roundcube/webmail
< 0.1
Timeline
Published
Dec 12, 2007
Tracked Since
Feb 18, 2026