pineapp records
7 published records for vendor pineapp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 14.3%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
54Plan | CVE-2013-6829Weaponized | admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacharacters in the pinghpineapp · mail-secure · CWE-94 | High7.5 | — | 79.9% | Nov 20, 2013 |
35Monitor | CVE-2013-4987Proof of concept | PineApp Mail-SeCure before 3.70 allows remote authenticated users to gain privileges by leveraging console access and providing shell metachpineapp · mail-secure · CWE-264 | High8.5 | — | 2.6% | Nov 8, 2013 |
33Monitor | CVE-2013-6830Proof of concept | admin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attackers to execute arbitrapineapp · mail-secure 5099sk · CWE-94 | High7.5 | — | 8.9% | Nov 20, 2013 |
28Monitor | CVE-2013-6831Proof of concept | PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict user specifications,pineapp · mail-secure 5099sk · CWE-264 | High7.2 | — | 1.0% | Nov 20, 2013 |
25Monitor | CVE-2013-6828No exploit | admin/management.html in PineApp Mail-SeCure allows remote attackers to bypass authentication and perform a sys_usermng operation via the itpineapp · mail-secure · CWE-287 | Medium6.4 | — | 1.3% | Nov 20, 2013 |
24Monitor | CVE-2021-36720No exploit | PineApp - Mail Secure - Attacker sending a request to :/blocking.php?url=<script>alert(1)</script> and stealing cookies .pineapp · mail secure · CWE-79 | Medium6.1 | — | 0.6% | Dec 8, 2021 |
20Monitor | CVE-2013-6827No exploit | Absolute path traversal vulnerability in admin/viewmsg.php in PineApp Mail-SeCure allows remote attackers to read arbitrary files via a fullpineapp · mail-secure · CWE-22 | Medium5.0 | — | 1.4% | Nov 20, 2013 |
- CVE-2013-682954Plan
admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacharacters in the pingh
HighCVSS 7.5WeaponizedEPSS 80%pineapp · mail-secureNov 20, 2013
- CVE-2013-498735Monitor
PineApp Mail-SeCure before 3.70 allows remote authenticated users to gain privileges by leveraging console access and providing shell metach
HighCVSS 8.5Proof of conceptEPSS 3%pineapp · mail-secureNov 8, 2013
- CVE-2013-683033Monitor
admin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attackers to execute arbitra
HighCVSS 7.5Proof of conceptEPSS 9%pineapp · mail-secure 5099skNov 20, 2013
- CVE-2013-683128Monitor
PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict user specifications,
HighCVSS 7.2Proof of conceptEPSS 1%pineapp · mail-secure 5099skNov 20, 2013
- CVE-2013-682825Monitor
admin/management.html in PineApp Mail-SeCure allows remote attackers to bypass authentication and perform a sys_usermng operation via the it
MediumCVSS 6.4No exploitEPSS 1%pineapp · mail-secureNov 20, 2013
- CVE-2021-3672024Monitor
PineApp - Mail Secure - Attacker sending a request to :/blocking.php?url=<script>alert(1)</script> and stealing cookies .
MediumCVSS 6.1No exploitEPSS 1%pineapp · mail secureDec 8, 2021
- CVE-2013-682720Monitor
Absolute path traversal vulnerability in admin/viewmsg.php in PineApp Mail-SeCure allows remote attackers to read arbitrary files via a full
MediumCVSS 5.0No exploitEPSS 1%pineapp · mail-secureNov 20, 2013