<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[iRedMail — Security: XSS vulnerability in roundcubemai-0.2-stable]]></title>
	<link rel="self" href="http://www.iredmail.org/forum/feed-atom-topic4.xml" />
	<updated>2009-05-20T16:39:06Z</updated>
	<generator>PunBB</generator>
	<id>http://www.iredmail.org/forum/topic4-security-xss-vulnerability-in-roundcubemai02stable.html</id>
		<entry>
			<title type="html"><![CDATA[Re: Security: XSS vulnerability in roundcubemai-0.2-stable]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post122.html#p122" />
			<content type="html"><![CDATA[<p>Successfully applied.</p>]]></content>
			<author>
				<name><![CDATA[gscott187]]></name>
				<uri>http://www.iredmail.org/forum/user33.html</uri>
			</author>
			<updated>2009-05-20T16:39:06Z</updated>
			<id>http://www.iredmail.org/forum/post122.html#p122</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Security: XSS vulnerability in roundcubemai-0.2-stable]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post29.html#p29" />
			<content type="html"><![CDATA[<p>Thank you.</p>]]></content>
			<author>
				<name><![CDATA[nothingelse]]></name>
				<uri>http://www.iredmail.org/forum/user11.html</uri>
			</author>
			<updated>2009-05-07T14:15:35Z</updated>
			<id>http://www.iredmail.org/forum/post29.html#p29</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Security: XSS vulnerability in roundcubemai-0.2-stable]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post6.html#p6" />
			<content type="html"><![CDATA[<p>Hi, all.</p><p>All users use iRedMail-0.4.0 which ships roundcubemail-0.2-stable should<br />apply this patch *as soon as possible*.</p><p>Description:</p><p>&nbsp; &nbsp;There&#039;s a cross-site scripting (XSS) vulnerability in RoundCube<br />&nbsp; &nbsp;Webmail (roundcubemail) 0.2 stable allows remote attackers to inject<br />&nbsp; &nbsp;arbitrary web script or HTML via the background attribute embedded<br />&nbsp; &nbsp;in an HTML e-mail message.</p><p>Reference:</p><p>&nbsp; &nbsp;* CVE-2009-0413<br />&nbsp; &nbsp; &nbsp;<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0413">http://cve.mitre.org/cgi-bin/cvename.cg … -2009-0413</a></p><p>Patch attachted. Please follow the steps to apply it.</p><p>&nbsp; &nbsp;* Backup your current roundcubemail directory. e.g. copy the whole<br />&nbsp; &nbsp; &nbsp;directory to /opt/backup/.</p><div class="codebox"><pre><code># cp -rfp /var/www/roundcubemail-0.2-stable/ /opt/backup/</code></pre></div><p>&nbsp; &nbsp;* Download the patch, upload it to your mail server. We assume<br />&nbsp; &nbsp; &nbsp;you upload it to /opt/</p><p>&nbsp; &nbsp;* Change directory and apply the patch:</p><div class="codebox"><pre><code># cd /var/www/roundcubemail-0.2-stable/
# patch -p1 &lt; /opt/roundcubemail-CVE-2009-0413.patch
patching file program/lib/washtml.php</code></pre></div>]]></content>
			<author>
				<name><![CDATA[ZhangHuangbin]]></name>
				<uri>http://www.iredmail.org/forum/user2.html</uri>
			</author>
			<updated>2009-05-06T10:27:35Z</updated>
			<id>http://www.iredmail.org/forum/post6.html#p6</id>
		</entry>
</feed>
