CVE-2005-4368 Information

Description

roundcube webmail Alpha with a default high verbose level ($rcmail_config[‘debug_level’] = 1) allows remote attackers to obtain the full path of the application via an invalid_task parameter which leaks the path in an error message.

Reference

http://www.securityfocus.com/archive/1/418851/100/0/threaded http://www.securityfocus.com/archive/1/419710/100/0/threaded http://www.securityfocus.com/archive/1/422168/100/0/threaded

Share on: