mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 15:15:46 +02:00
701 B
701 B
CVE-2015-2180
Description
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.
POC
Reference
- https://github.com/roundcube/roundcubemail/issues/4757
- https://github.com/roundcube/roundcubemail/issues/4757