<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[Exploit Forums - OSINT & OpSec Methods]]></title>
		<link>https://exploitforums.net/</link>
		<description><![CDATA[Exploit Forums - https://exploitforums.net]]></description>
		<pubDate>Sun, 12 Apr 2026 19:04:58 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[Roundcube Exploit - How to protect your server!]]></title>
			<link>https://exploitforums.net/showthread.php?tid=7</link>
			<pubDate>Fri, 06 Jun 2025 01:13:53 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://exploitforums.net/member.php?action=profile&uid=1">Adamantium</a>]]></dc:creator>
			<guid isPermaLink="false">https://exploitforums.net/showthread.php?tid=7</guid>
			<description><![CDATA[There has recently been news of an exploit (CVE-2025-49113) for sale that allows an attacker to exploit mail application running RoundCube. The exploit existed over a decade and impact RoundCube webmail versions 1.1.0 through 1.6.10. <br />
<br />
Well known hosting providers such as GoDaddy, Hostinger, Dreamhost, OVH and Bluehost provides the RoundCube webmail application often bundled with cPanel and Plesk Control panels.<br />
<br />
Positive Technologies, in a post published on X, said it was able to reproduce CVE-2025-49113, urging users to update to the latest version of Roundcube as soon as possible.<br />
<br />
"This vulnerability allows authenticated users to execute arbitrary commands via PHP object deserialization," the Russian cybersecurity company<br />
<br />
<span style="font-weight: bold;" class="mycode_b">To protect yourself, they urge users to update to the latest version of RoundCube.</span>]]></description>
			<content:encoded><![CDATA[There has recently been news of an exploit (CVE-2025-49113) for sale that allows an attacker to exploit mail application running RoundCube. The exploit existed over a decade and impact RoundCube webmail versions 1.1.0 through 1.6.10. <br />
<br />
Well known hosting providers such as GoDaddy, Hostinger, Dreamhost, OVH and Bluehost provides the RoundCube webmail application often bundled with cPanel and Plesk Control panels.<br />
<br />
Positive Technologies, in a post published on X, said it was able to reproduce CVE-2025-49113, urging users to update to the latest version of Roundcube as soon as possible.<br />
<br />
"This vulnerability allows authenticated users to execute arbitrary commands via PHP object deserialization," the Russian cybersecurity company<br />
<br />
<span style="font-weight: bold;" class="mycode_b">To protect yourself, they urge users to update to the latest version of RoundCube.</span>]]></content:encoded>
		</item>
	</channel>
</rss>