CVE-2015-2180

HIGH

Roundcube Webmail < 1.1 - Remote Code Execution via DBMail Password Shell Metacharacters

Title source: llm
STIX 2.1

Description

The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96387
Exploit, Vendor Advisory x_refsource_confirm
https://github.com/roundcube/roundcubemail/issues/4757

Scores

CVSS v3 8.8
EPSS 0.0471
EPSS Percentile 90.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-74
Status published
Products (1)
roundcube/webmail < 1.1
Published Jan 30, 2017
Tracked Since Feb 18, 2026