CVE-2013-1904: Path Traversal
Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to read arbitrary files via a full pathname in the value parameter for the genericmessagefooter setting in a save-perf action to index.php, as exploited in the wild in March 2013.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1904?
CVE-2013-1904 has been categorized as a medium severity vulnerability due to its potential to allow remote file access.
How do I fix CVE-2013-1904?
To mitigate CVE-2013-1904, upgrade Roundcube Webmail to version 0.7.3 or higher or 0.8.6 or higher.
What kind of systems are affected by CVE-2013-1904?
CVE-2013-1904 affects Roundcube Webmail versions before 0.7.3 and the 0.8.x series before 0.8.6.
What is the impact of exploiting CVE-2013-1904?
Exploiting CVE-2013-1904 allows attackers to read arbitrary files on the server via a crafted request.
Is CVE-2013-1904 easy to exploit?
CVE-2013-1904 can be exploited with a single crafted request and requires no authentication, making it relatively easy for remote attackers.