Zero-day Vulnerability Database

Change view:

Zero-day vulnerabilities discovered: 1

PHP inlcuding in Roundcube Webmail
CVE-2013-1904

PHP including

The vulnerability allows a remote attacker to include arbitrary files on the target system.

The weakness exists due to improper sanitization of user-supplied data within "steps/mail/sendmail.inc" script when parsing "generic_message_footer" HTTP parameter passed to "/index.php" script. A remote attacker can send a specially crafted HTTP request to the "index.php" script, include and execute arbitrary PHP script on the affected server.

Successful exploitation of the vulnerability may lead to system compromise.

Note: the vulnerability was being actively exploited.

Software: Roundcube

Known/fameous malware:

Exploit-FHV!CVE2013-1493 (McAfee)
Exp/20131493-G (Sophos)
Exp/20131493-A (Sophos)
Exploit.Java.CVE-2013-1493.gen (Kaspersky)
Java/CVE_2013_1493.NT!exploit

Vulnerability Scanning SaaS

Vulnerability scanning SaaS service is online 3-rd generation vulnerability scanner with scheduled assessments and vulnerability subscription. You can use service to check security of your network perimeter.