Atmail records
32 published records for vendor atmail.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
32 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2013-5034No exploit | Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability thaatmail · atmail | Critical10.0 | — | 1.7% | Jan 12, 2014 |
41Plan | CVE-2013-5033No exploit | Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability thaatmail · atmail | Critical10.0 | — | 1.7% | Jan 12, 2014 |
41Plan | CVE-2013-5032No exploit | Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability thaatmail · atmail | Critical10.0 | — | 1.7% | Jan 12, 2014 |
41Plan | CVE-2013-5031No exploit | Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability thaatmail · atmail | Critical10.0 | — | 1.7% | Jan 12, 2014 |
39Monitor | CVE-2024-24133No exploit | Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.atmail · atmail · CWE-89 | Critical9.8 | — | 0.6% | Feb 7, 2024 |
35Monitor | CVE-2017-9517No exploit | atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.atmail · atmail · CWE-352 | High8.8 | — | 0.5% | Jun 8, 2017 |
35Monitor | CVE-2017-9519No exploit | atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.atmail · atmail · CWE-352 | High8.8 | — | 0.5% | Jun 8, 2017 |
35Monitor | CVE-2017-9518No exploit | atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails.atmail · atmail · CWE-352 | High8.8 | — | 0.5% | Jun 8, 2017 |
31Monitor | CVE-2012-1916No exploit | @Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to execute arbitrary code via an e-mail attachment with an exatmail · atmail open | High7.5 | — | 3.4% | Mar 27, 2012 |
31Monitor | CVE-2006-0611No exploit | Directory traversal vulnerability in compose.pl in @Mail 4.3 and earlier for Windows allows remote attackers to upload arbitrary files to aratmail · atmail | High7.5 | — | 1.8% | Feb 8, 2006 |
30Monitor | CVE-2006-6701No exploit | Cross-site request forgery (CSRF) vulnerability in util.pl in @Mail WebMail 4.51, and util.php in 5.x before 5.03, allows remote attackers tatmail · atmail webmail · CWE-352 | High7.5 | — | 1.0% | Dec 22, 2006 |
27Monitor | CVE-2006-6702No exploit | Cross-site scripting (XSS) vulnerability in Global.pm in @Mail before 4.61 allows remote attackers to inject arbitrary web script or HTML viatmail · atmail webmail | Medium6.8 | — | 1.2% | Dec 22, 2006 |
27Monitor | CVE-2007-2153No exploit | Cross-site scripting (XSS) vulnerability in atmail.php in @Mail 5.0 allows remote attackers to inject arbitrary web script or HTML via the uatmail · atmail webmail | Medium6.8 | — | 1.2% | Apr 19, 2007 |
27Monitor | CVE-2006-6704No exploit | Cross-site scripting (XSS) vulnerability in the Webadmin in @Mail before 4.6 allows remote attackers to inject arbitrary web script or HTML atmail · atmail webadmin | Medium6.8 | — | 1.1% | Dec 22, 2006 |
27Monitor | CVE-2013-6028No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in Atmail Webmail Server before 7.2 allow remote attackers to hijack the authentiatmail · atmail · CWE-352 | Medium6.8 | — | 0.8% | Jan 12, 2014 |
26Monitor | CVE-2012-2593Proof of concept | Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbiatmail · atmail · CWE-79 | Medium6.1 | — | 6.2% | Feb 6, 2020 |
26Monitor | CVE-2012-1919No exploit | CRLF injection vulnerability in mime.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to conduct directatmail · atmail open · CWE-94 | Medium6.4 | — | 2.0% | Mar 27, 2012 |
25Monitor | CVE-2022-30776Proof of concept | atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.atmail · atmail · CWE-79 | Medium6.1 | — | 4.3% | May 16, 2022 |
25Monitor | CVE-2021-43574Proof of concept | WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI.atmail · atmail · CWE-79 | Medium6.1 | — | 2.5% | Nov 15, 2021 |
24Monitor | CVE-2017-11617No exploit | Cross-site scripting (XSS) vulnerability in atmail prior to version 7.8.0.2 allows remote attackers to inject arbitrary web script or HTML watmail · atmail · CWE-79 | Medium6.1 | — | 1.0% | Jul 25, 2017 |
24Monitor | CVE-2022-31200No exploit | Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms fieldatmail · atmail · CWE-79 | Medium6.1 | — | 0.4% | Jul 27, 2023 |
21Monitor | CVE-2012-1918No exploit | Multiple directory traversal vulnerabilities in (1) compose.php and (2) libs/Atmail/SendMsg.php in @Mail WebMail Client in AtMail Open-Sourcatmail · atmail open · CWE-22 | Medium5.0 | — | 3.5% | Mar 27, 2012 |
21Monitor | CVE-2012-1920No exploit | @Mail WebMail Client in AtMail Open-Source 1.04 and earlier allows remote attackers to obtain configuration information via a direct requestatmail · atmail open · CWE-200 | Medium5.0 | — | 2.7% | Mar 27, 2012 |
21Monitor | CVE-2012-1917No exploit | compose.php in @Mail WebMail Client in AtMail Open-Source before 1.05 does not properly handle ../ (dot dot slash) sequences in the unique patmail · atmail open · CWE-22 | Medium5.0 | — | 2.2% | Mar 27, 2012 |
18Monitor | CVE-2013-6017Proof of concept | Cross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary web script or HTML atmail · atmail · CWE-79 | Medium4.3 | — | 4.4% | Jan 12, 2014 |
- CVE-2013-503441Plan
Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability tha
CriticalCVSS 10.0No exploitEPSS 2%atmail · atmailJan 12, 2014
- CVE-2013-503341Plan
Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability tha
CriticalCVSS 10.0No exploitEPSS 2%atmail · atmailJan 12, 2014
- CVE-2013-503241Plan
Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability tha
CriticalCVSS 10.0No exploitEPSS 2%atmail · atmailJan 12, 2014
- CVE-2013-503141Plan
Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability tha
CriticalCVSS 10.0No exploitEPSS 2%atmail · atmailJan 12, 2014
- CVE-2024-2413339Monitor
Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.
CriticalCVSS 9.8No exploitEPSS 1%atmail · atmailFeb 7, 2024
- CVE-2017-951735Monitor
atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.
HighCVSS 8.8No exploitEPSS 0%atmail · atmailJun 8, 2017
- CVE-2017-951935Monitor
atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.
HighCVSS 8.8No exploitEPSS 0%atmail · atmailJun 8, 2017
- CVE-2017-951835Monitor
atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails.
HighCVSS 8.8No exploitEPSS 0%atmail · atmailJun 8, 2017
- CVE-2012-191631Monitor
@Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to execute arbitrary code via an e-mail attachment with an ex
HighCVSS 7.5No exploitEPSS 3%atmail · atmail openMar 27, 2012
- CVE-2006-061131Monitor
Directory traversal vulnerability in compose.pl in @Mail 4.3 and earlier for Windows allows remote attackers to upload arbitrary files to ar
HighCVSS 7.5No exploitEPSS 2%atmail · atmailFeb 8, 2006
- CVE-2006-670130Monitor
Cross-site request forgery (CSRF) vulnerability in util.pl in @Mail WebMail 4.51, and util.php in 5.x before 5.03, allows remote attackers t
HighCVSS 7.5No exploitEPSS 1%atmail · atmail webmailDec 22, 2006
- CVE-2006-670227Monitor
Cross-site scripting (XSS) vulnerability in Global.pm in @Mail before 4.61 allows remote attackers to inject arbitrary web script or HTML vi
MediumCVSS 6.8No exploitEPSS 1%atmail · atmail webmailDec 22, 2006
- CVE-2007-215327Monitor
Cross-site scripting (XSS) vulnerability in atmail.php in @Mail 5.0 allows remote attackers to inject arbitrary web script or HTML via the u
MediumCVSS 6.8No exploitEPSS 1%atmail · atmail webmailApr 19, 2007
- CVE-2006-670427Monitor
Cross-site scripting (XSS) vulnerability in the Webadmin in @Mail before 4.6 allows remote attackers to inject arbitrary web script or HTML
MediumCVSS 6.8No exploitEPSS 1%atmail · atmail webadminDec 22, 2006
- CVE-2013-602827Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in Atmail Webmail Server before 7.2 allow remote attackers to hijack the authenti
MediumCVSS 6.8No exploitEPSS 1%atmail · atmailJan 12, 2014
- CVE-2012-259326Monitor
Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbi
MediumCVSS 6.1Proof of conceptEPSS 6%atmail · atmailFeb 6, 2020
- CVE-2012-191926Monitor
CRLF injection vulnerability in mime.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to conduct direct
MediumCVSS 6.4No exploitEPSS 2%atmail · atmail openMar 27, 2012
- CVE-2022-3077625Monitor
atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.
MediumCVSS 6.1Proof of conceptEPSS 4%atmail · atmailMay 16, 2022
- CVE-2021-4357425Monitor
WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI.
MediumCVSS 6.1Proof of conceptEPSS 2%atmail · atmailNov 15, 2021
- CVE-2017-1161724Monitor
Cross-site scripting (XSS) vulnerability in atmail prior to version 7.8.0.2 allows remote attackers to inject arbitrary web script or HTML w
MediumCVSS 6.1No exploitEPSS 1%atmail · atmailJul 25, 2017
- CVE-2022-3120024Monitor
Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms field
MediumCVSS 6.1No exploitEPSS 0%atmail · atmailJul 27, 2023
- CVE-2012-191821Monitor
Multiple directory traversal vulnerabilities in (1) compose.php and (2) libs/Atmail/SendMsg.php in @Mail WebMail Client in AtMail Open-Sourc
MediumCVSS 5.0No exploitEPSS 4%atmail · atmail openMar 27, 2012
- CVE-2012-192021Monitor
@Mail WebMail Client in AtMail Open-Source 1.04 and earlier allows remote attackers to obtain configuration information via a direct request
MediumCVSS 5.0No exploitEPSS 3%atmail · atmail openMar 27, 2012
- CVE-2012-191721Monitor
compose.php in @Mail WebMail Client in AtMail Open-Source before 1.05 does not properly handle ../ (dot dot slash) sequences in the unique p
MediumCVSS 5.0No exploitEPSS 2%atmail · atmail openMar 27, 2012
- CVE-2013-601718Monitor
Cross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary web script or HTML
MediumCVSS 4.3Proof of conceptEPSS 4%atmail · atmailJan 12, 2014