v-webmail records
8 published records for vendor v-webmail.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
33Monitor | CVE-2006-2665Proof of concept | PHP remote file inclusion vulnerability in includes/mailaccess/pop3/core.php in V-Webmail 1.3 allows remote attackers to execute arbitrary Pv-webmail · v-webmail | High7.5 | — | 8.8% | May 30, 2006 |
31Monitor | CVE-2006-2666Proof of concept | PHP remote file inclusion vulnerability in includes/mailaccess/pop3.php in V-Webmail 1.5 through 1.6.4 allows remote attackers to execute arv-webmail · v-webmail | High7.5 | — | 3.6% | May 30, 2006 |
30Monitor | CVE-2008-3063No exploit | SQL injection vulnerability in login.php in V-webmail 1.5.0 might allow remote attackers to execute arbitrary SQL commands via the username v-webmail · v-webmail · CWE-89 | High7.5 | — | 1.1% | Oct 7, 2008 |
20Monitor | CVE-2006-0793No exploit | frameset.php in V-webmail 1.6.2 allows remote attackers to conduct phishing attacks by referencing arbitrary websites in the rframe parametev-webmail · v-webmail | Medium5.0 | — | 1.4% | Feb 19, 2006 |
20Monitor | CVE-2006-0794No exploit | help.php in V-webmail 1.6.2 allows remote attackers to obtain the installation path via unspecified invalid parameters.v-webmail · v-webmail | Medium5.0 | — | 1.4% | Feb 19, 2006 |
20Monitor | CVE-2008-3060No exploit | V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (includes/local.hooks.php)v-webmail · v-webmail · CWE-200 | Medium5.0 | — | 1.2% | Oct 7, 2008 |
18Monitor | CVE-2006-0792Proof of concept | Cross-site scripting (XSS) vulnerability in preferences.personal.php in V-webmail 1.6.2 allows remote attackers to inject arbitrary web scriv-webmail · v-webmail | Medium4.3 | — | 1.8% | Feb 19, 2006 |
17Monitor | CVE-2008-3061No exploit | Open redirect vulnerability in redirect.php in V-webmail 1.5.0 allows remote attackers to redirect users to arbitrary web sites and conduct v-webmail · v-webmail | Medium4.3 | — | 1.0% | Oct 7, 2008 |
- CVE-2006-266533Monitor
PHP remote file inclusion vulnerability in includes/mailaccess/pop3/core.php in V-Webmail 1.3 allows remote attackers to execute arbitrary P
HighCVSS 7.5Proof of conceptEPSS 9%v-webmail · v-webmailMay 30, 2006
- CVE-2006-266631Monitor
PHP remote file inclusion vulnerability in includes/mailaccess/pop3.php in V-Webmail 1.5 through 1.6.4 allows remote attackers to execute ar
HighCVSS 7.5Proof of conceptEPSS 4%v-webmail · v-webmailMay 30, 2006
- CVE-2008-306330Monitor
SQL injection vulnerability in login.php in V-webmail 1.5.0 might allow remote attackers to execute arbitrary SQL commands via the username
HighCVSS 7.5No exploitEPSS 1%v-webmail · v-webmailOct 7, 2008
- CVE-2006-079320Monitor
frameset.php in V-webmail 1.6.2 allows remote attackers to conduct phishing attacks by referencing arbitrary websites in the rframe paramete
MediumCVSS 5.0No exploitEPSS 1%v-webmail · v-webmailFeb 19, 2006
- CVE-2006-079420Monitor
help.php in V-webmail 1.6.2 allows remote attackers to obtain the installation path via unspecified invalid parameters.
MediumCVSS 5.0No exploitEPSS 1%v-webmail · v-webmailFeb 19, 2006
- CVE-2008-306020Monitor
V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (includes/local.hooks.php)
MediumCVSS 5.0No exploitEPSS 1%v-webmail · v-webmailOct 7, 2008
- CVE-2006-079218Monitor
Cross-site scripting (XSS) vulnerability in preferences.personal.php in V-webmail 1.6.2 allows remote attackers to inject arbitrary web scri
MediumCVSS 4.3Proof of conceptEPSS 2%v-webmail · v-webmailFeb 19, 2006
- CVE-2008-306117Monitor
Open redirect vulnerability in redirect.php in V-webmail 1.5.0 allows remote attackers to redirect users to arbitrary web sites and conduct
MediumCVSS 4.3No exploitEPSS 1%v-webmail · v-webmailOct 7, 2008