VDB

GCVE-110-MAGEIA-2013-325

GCVE-110-MAGEIA-2013-325
Advisory Published
Vulnetix · Advisory published November 18, 2013
It was discovered that roundcube does not properly sanitize the _session parameter in steps/utils/save_pref.inc during saving preferences. The vulnerability can be exploited to overwrite configuration settings and subsequently allowing random file access, manipulated SQL queries and even code execution (CVE-2013-6172).

Affected Products

VendorProductVersionsPlatforms
Mageiaroundcubemail0 (affected), 0.9.5-1.mga3 (unaffected)
Mageiaroundcubemail0 (affected), 0.7.4-1.3.mga2 (unaffected)

Browse GCVE Records

73,877 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›