{"id":"CVE-2015-2180","details":"The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.","modified":"2026-04-16T06:26:14.919365347Z","published":"2017-01-30T22:59:00Z","references":[{"type":"ADVISORY","url":"https://github.com/roundcube/roundcubemail/issues/4757"},{"type":"EVIDENCE","url":"https://github.com/roundcube/roundcubemail/issues/4757"},{"type":"WEB","url":"http://www.securityfocus.com/bid/96387"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}