Description
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin weForms-Easy Drag & Drop Contact Form Builder For WordPress CSV Injection (1.4.7)
OpenSSL Uncontrolled Resource Consumption Vulnerability (CVE-2016-6307)
WordPress Plugin Qiniu Uploader Cross-Site Scripting (0.1)
IBM WebSEAL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1886)