Description
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Gravity Upload Ajax Arbitrary File Upload (1.1)
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-29208)
WordPress Plugin WP Google Maps Cross-Site Scripting (8.1.11)
WordPress Plugin Videox7 UGC 'listid' Parameter Cross-Site Scripting (2.5.3.2)
WordPress Plugin Custom Global Variables Cross-Site Scripting (1.0.5)