Description
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
Remediation
References
Related Vulnerabilities
WordPress Plugin Easy Plugin for AdSense Cross-Site Request Forgery (6.06)
WordPress Plugin Googmonify Multiple Vulnerabilities (0.5.1)
Riot.js Resource Management Errors Vulnerability (CVE-2016-10527)
WordPress Plugin My Calendar Cross-Site Scripting (3.2.17)
Internet Information Services Other Vulnerability (CVE-2001-0508)