CVE-2015-2180: High severity Roundcube Webmail vulnerability
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2180?
CVE-2015-2180 is categorized as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2015-2180?
To fix CVE-2015-2180, update to Roundcube version 1.1.0 or later where the vulnerability has been addressed.
Who is affected by CVE-2015-2180?
CVE-2015-2180 affects users of Roundcube webmail versions prior to 1.1.0 that utilize the DBMail driver in the Password plugin.
What type of attack does CVE-2015-2180 enable?
CVE-2015-2180 enables remote attackers to execute arbitrary commands on the server through crafted input.
Is there a known exploit for CVE-2015-2180?
While specific exploits for CVE-2015-2180 are not publicly disclosed, the nature of the vulnerability indicates the risk of exploitation is significant.