Loading vulnerability details…
CVSS v3.1
N/A
EPSS
4.71%
Published
Jan 30, 2017
Modified
May 12, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.
Weaknesses (CWE)
Affected Products (1)
References (4)