CVE-2015-2180

HIGH8.8EPSS 2.7%
Published: 1/30/2017Modified: 5/29/2026
Also known as:DEBIAN-CVE-2015-2180

Description

The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References (1)