Записи MailCleaner
10 опубликованных записей вендора mailcleaner.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 10 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-862 Missing Authorization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
51В плане | CVE-2018-20323Готовый эксплойт | www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitrary OS commands.mailcleaner · mailcleaner · CWE-78 | Высокая8,8 | — | 54,5 % | 21 мар. 2019 г. |
41В плане | CVE-2024-3191Эксплойта нет | MailCleaner Email os command injectionmailcleaner · mailcleaner · CWE-78 | Критическая9,8 | — | 5,2 % | 29 апр. 2024 г. |
39Наблюдать | CVE-2024-55560Эксплойта нет | MailCleaner before 28d913e has default values of ssh_host_dsa_key, ssh_host_rsa_key, and ssh_host_ed25519_key that persist after installatio | Критическая9,8 | — | 0,6 % | 8 дек. 2024 г. |
38Наблюдать | CVE-2024-3192Эксплойта нет | MailCleaner Admin Interface cross site scriptingmailcleaner · mailcleaner · CWE-79 | Критическая9,6 | — | 1,0 % | 29 апр. 2024 г. |
36Наблюдать | CVE-2024-3193Эксплойта нет | MailCleaner Admin Endpoints os command injectionmailcleaner · mailcleaner · CWE-78 | Высокая8,8 | — | 4,2 % | 29 апр. 2024 г. |
30Наблюдать | CVE-2019-1010246Эксплойта нет | MailCleaner before c888fbb6aaa7c5f8400f637bcf1cbb844de46cd9 is affected by: Unauthenticated MySQL database password information disclosure.mailcleaner · mailcleaner · CWE-862 | Высокая7,5 | — | 1,4 % | 18 июл. 2019 г. |
28Наблюдать | CVE-2024-3195Эксплойта нет | MailCleaner Admin Endpoints path traversalmailcleaner · mailcleaner · CWE-22 | Высокая7,2 | — | 1,0 % | 29 апр. 2024 г. |
26Наблюдать | CVE-2024-3196Эксплойта нет | MailCleaner SOAP Service dumpConfiguration os command injectionmailcleaner · mailcleaner · CWE-78 | Средняя6,7 | — | 1,7 % | 29 апр. 2024 г. |
24Наблюдать | CVE-2018-18635Эксплойта нет | www/guis/admin/application/controllers/UserController.php in the administration login interface in MailCleaner CE 2018.08 and 2018.09 allowsmailcleaner · mailcleaner · CWE-79 | Средняя6,1 | — | 0,9 % | 24 окт. 2018 г. |
24Наблюдать | CVE-2024-3194Эксплойта нет | MailCleaner Log File Endpoint cross site scriptingmailcleaner · mailcleaner · CWE-79 | Средняя6,1 | — | 0,7 % | 29 апр. 2024 г. |
- CVE-2018-2032351В плане
www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitrary OS commands.
ВысокаяCVSS 8,8Готовый эксплойтEPSS 54 %mailcleaner · mailcleaner21 мар. 2019 г.
- CVE-2024-319141В плане
MailCleaner Email os command injection
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %mailcleaner · mailcleaner29 апр. 2024 г.
- CVE-2024-5556039Наблюдать
MailCleaner before 28d913e has default values of ssh_host_dsa_key, ssh_host_rsa_key, and ssh_host_ed25519_key that persist after installatio
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %8 дек. 2024 г.
- CVE-2024-319238Наблюдать
MailCleaner Admin Interface cross site scripting
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %mailcleaner · mailcleaner29 апр. 2024 г.
- CVE-2024-319336Наблюдать
MailCleaner Admin Endpoints os command injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %mailcleaner · mailcleaner29 апр. 2024 г.
- CVE-2019-101024630Наблюдать
MailCleaner before c888fbb6aaa7c5f8400f637bcf1cbb844de46cd9 is affected by: Unauthenticated MySQL database password information disclosure.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %mailcleaner · mailcleaner18 июл. 2019 г.
- CVE-2024-319528Наблюдать
MailCleaner Admin Endpoints path traversal
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %mailcleaner · mailcleaner29 апр. 2024 г.
- CVE-2024-319626Наблюдать
MailCleaner SOAP Service dumpConfiguration os command injection
СредняяCVSS 6,7Эксплойта нетEPSS 2 %mailcleaner · mailcleaner29 апр. 2024 г.
- CVE-2018-1863524Наблюдать
www/guis/admin/application/controllers/UserController.php in the administration login interface in MailCleaner CE 2018.08 and 2018.09 allows
СредняяCVSS 6,1Эксплойта нетEPSS 1 %mailcleaner · mailcleaner24 окт. 2018 г.
- CVE-2024-319424Наблюдать
MailCleaner Log File Endpoint cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %mailcleaner · mailcleaner29 апр. 2024 г.