{"id":"CVE-2015-2180","details":"The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.","modified":"2026-04-16T01:48:26.162801942Z","published":"2017-01-30T22:59:00Z","withdrawn":"2026-01-27T04:13:52.700674Z","references":[{"type":"EVIDENCE","url":"https://github.com/roundcube/roundcubemail/issues/4757"},{"type":"WEB","url":"http://www.securityfocus.com/bid/96387"}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}