Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-12640. PoCs published by mbadanoiu.
AI-analyzed exploit summary This repository provides a writeup for CVE-2020-12640, a local PHP file inclusion vulnerability in Roundcube Webmail due to unsanitized plugin parameters. The vulnerability allows path traversal to include arbitrary PHP files, but no exploit code is provided.
Description
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
Exploits (1)
This repository provides a writeup for CVE-2020-12640, a local PHP file inclusion vulnerability in Roundcube Webmail due to unsanitized plugin parameters. The vulnerability allows path traversal to include arbitrary PHP files, but no exploit code is provided.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H