Записи Atmail
32 опубликованных записей вендора atmail.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
32 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2013-5034Эксплойта нет | Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability thaatmail · atmail | Критическая10,0 | — | 1,7 % | 12 янв. 2014 г. |
41В плане | CVE-2013-5033Эксплойта нет | Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability thaatmail · atmail | Критическая10,0 | — | 1,7 % | 12 янв. 2014 г. |
41В плане | CVE-2013-5032Эксплойта нет | Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability thaatmail · atmail | Критическая10,0 | — | 1,7 % | 12 янв. 2014 г. |
41В плане | CVE-2013-5031Эксплойта нет | Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability thaatmail · atmail | Критическая10,0 | — | 1,7 % | 12 янв. 2014 г. |
39Наблюдать | CVE-2024-24133Эксплойта нет | Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.atmail · atmail · CWE-89 | Критическая9,8 | — | 0,6 % | 7 февр. 2024 г. |
35Наблюдать | CVE-2017-9517Эксплойта нет | atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.atmail · atmail · CWE-352 | Высокая8,8 | — | 0,5 % | 8 июн. 2017 г. |
35Наблюдать | CVE-2017-9519Эксплойта нет | atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.atmail · atmail · CWE-352 | Высокая8,8 | — | 0,5 % | 8 июн. 2017 г. |
35Наблюдать | CVE-2017-9518Эксплойта нет | atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails.atmail · atmail · CWE-352 | Высокая8,8 | — | 0,5 % | 8 июн. 2017 г. |
31Наблюдать | CVE-2012-1916Эксплойта нет | @Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to execute arbitrary code via an e-mail attachment with an exatmail · atmail open | Высокая7,5 | — | 3,4 % | 27 мар. 2012 г. |
31Наблюдать | CVE-2006-0611Эксплойта нет | Directory traversal vulnerability in compose.pl in @Mail 4.3 and earlier for Windows allows remote attackers to upload arbitrary files to aratmail · atmail | Высокая7,5 | — | 1,8 % | 8 февр. 2006 г. |
30Наблюдать | CVE-2006-6701Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in util.pl in @Mail WebMail 4.51, and util.php in 5.x before 5.03, allows remote attackers tatmail · atmail webmail · CWE-352 | Высокая7,5 | — | 1,0 % | 22 дек. 2006 г. |
27Наблюдать | CVE-2006-6702Эксплойта нет | Cross-site scripting (XSS) vulnerability in Global.pm in @Mail before 4.61 allows remote attackers to inject arbitrary web script or HTML viatmail · atmail webmail | Средняя6,8 | — | 1,2 % | 22 дек. 2006 г. |
27Наблюдать | CVE-2007-2153Эксплойта нет | Cross-site scripting (XSS) vulnerability in atmail.php in @Mail 5.0 allows remote attackers to inject arbitrary web script or HTML via the uatmail · atmail webmail | Средняя6,8 | — | 1,2 % | 19 апр. 2007 г. |
27Наблюдать | CVE-2006-6704Эксплойта нет | Cross-site scripting (XSS) vulnerability in the Webadmin in @Mail before 4.6 allows remote attackers to inject arbitrary web script or HTML atmail · atmail webadmin | Средняя6,8 | — | 1,1 % | 22 дек. 2006 г. |
27Наблюдать | CVE-2013-6028Эксплойта нет | Multiple cross-site request forgery (CSRF) vulnerabilities in Atmail Webmail Server before 7.2 allow remote attackers to hijack the authentiatmail · atmail · CWE-352 | Средняя6,8 | — | 0,8 % | 12 янв. 2014 г. |
26Наблюдать | CVE-2012-2593Proof of concept | Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbiatmail · atmail · CWE-79 | Средняя6,1 | — | 6,2 % | 6 февр. 2020 г. |
26Наблюдать | CVE-2012-1919Эксплойта нет | CRLF injection vulnerability in mime.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to conduct directatmail · atmail open · CWE-94 | Средняя6,4 | — | 2,0 % | 27 мар. 2012 г. |
25Наблюдать | CVE-2022-30776Proof of concept | atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.atmail · atmail · CWE-79 | Средняя6,1 | — | 4,3 % | 16 мая 2022 г. |
25Наблюдать | CVE-2021-43574Proof of concept | WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI.atmail · atmail · CWE-79 | Средняя6,1 | — | 2,5 % | 15 нояб. 2021 г. |
24Наблюдать | CVE-2017-11617Эксплойта нет | Cross-site scripting (XSS) vulnerability in atmail prior to version 7.8.0.2 allows remote attackers to inject arbitrary web script or HTML watmail · atmail · CWE-79 | Средняя6,1 | — | 1,0 % | 25 июл. 2017 г. |
24Наблюдать | CVE-2022-31200Эксплойта нет | Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms fieldatmail · atmail · CWE-79 | Средняя6,1 | — | 0,4 % | 27 июл. 2023 г. |
21Наблюдать | CVE-2012-1918Эксплойта нет | Multiple directory traversal vulnerabilities in (1) compose.php and (2) libs/Atmail/SendMsg.php in @Mail WebMail Client in AtMail Open-Sourcatmail · atmail open · CWE-22 | Средняя5,0 | — | 3,5 % | 27 мар. 2012 г. |
21Наблюдать | CVE-2012-1920Эксплойта нет | @Mail WebMail Client in AtMail Open-Source 1.04 and earlier allows remote attackers to obtain configuration information via a direct requestatmail · atmail open · CWE-200 | Средняя5,0 | — | 2,7 % | 27 мар. 2012 г. |
21Наблюдать | CVE-2012-1917Эксплойта нет | compose.php in @Mail WebMail Client in AtMail Open-Source before 1.05 does not properly handle ../ (dot dot slash) sequences in the unique patmail · atmail open · CWE-22 | Средняя5,0 | — | 2,2 % | 27 мар. 2012 г. |
18Наблюдать | CVE-2013-6017Proof of concept | Cross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary web script or HTML atmail · atmail · CWE-79 | Средняя4,3 | — | 4,4 % | 12 янв. 2014 г. |
- CVE-2013-503441В плане
Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability tha
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %atmail · atmail12 янв. 2014 г.
- CVE-2013-503341В плане
Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability tha
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %atmail · atmail12 янв. 2014 г.
- CVE-2013-503241В плане
Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability tha
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %atmail · atmail12 янв. 2014 г.
- CVE-2013-503141В плане
Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability tha
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %atmail · atmail12 янв. 2014 г.
- CVE-2024-2413339Наблюдать
Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %atmail · atmail7 февр. 2024 г.
- CVE-2017-951735Наблюдать
atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %atmail · atmail8 июн. 2017 г.
- CVE-2017-951935Наблюдать
atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %atmail · atmail8 июн. 2017 г.
- CVE-2017-951835Наблюдать
atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %atmail · atmail8 июн. 2017 г.
- CVE-2012-191631Наблюдать
@Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to execute arbitrary code via an e-mail attachment with an ex
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %atmail · atmail open27 мар. 2012 г.
- CVE-2006-061131Наблюдать
Directory traversal vulnerability in compose.pl in @Mail 4.3 and earlier for Windows allows remote attackers to upload arbitrary files to ar
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %atmail · atmail8 февр. 2006 г.
- CVE-2006-670130Наблюдать
Cross-site request forgery (CSRF) vulnerability in util.pl in @Mail WebMail 4.51, and util.php in 5.x before 5.03, allows remote attackers t
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %atmail · atmail webmail22 дек. 2006 г.
- CVE-2006-670227Наблюдать
Cross-site scripting (XSS) vulnerability in Global.pm in @Mail before 4.61 allows remote attackers to inject arbitrary web script or HTML vi
СредняяCVSS 6,8Эксплойта нетEPSS 1 %atmail · atmail webmail22 дек. 2006 г.
- CVE-2007-215327Наблюдать
Cross-site scripting (XSS) vulnerability in atmail.php in @Mail 5.0 allows remote attackers to inject arbitrary web script or HTML via the u
СредняяCVSS 6,8Эксплойта нетEPSS 1 %atmail · atmail webmail19 апр. 2007 г.
- CVE-2006-670427Наблюдать
Cross-site scripting (XSS) vulnerability in the Webadmin in @Mail before 4.6 allows remote attackers to inject arbitrary web script or HTML
СредняяCVSS 6,8Эксплойта нетEPSS 1 %atmail · atmail webadmin22 дек. 2006 г.
- CVE-2013-602827Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in Atmail Webmail Server before 7.2 allow remote attackers to hijack the authenti
СредняяCVSS 6,8Эксплойта нетEPSS 1 %atmail · atmail12 янв. 2014 г.
- CVE-2012-259326Наблюдать
Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbi
СредняяCVSS 6,1Proof of conceptEPSS 6 %atmail · atmail6 февр. 2020 г.
- CVE-2012-191926Наблюдать
CRLF injection vulnerability in mime.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to conduct direct
СредняяCVSS 6,4Эксплойта нетEPSS 2 %atmail · atmail open27 мар. 2012 г.
- CVE-2022-3077625Наблюдать
atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.
СредняяCVSS 6,1Proof of conceptEPSS 4 %atmail · atmail16 мая 2022 г.
- CVE-2021-4357425Наблюдать
WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI.
СредняяCVSS 6,1Proof of conceptEPSS 2 %atmail · atmail15 нояб. 2021 г.
- CVE-2017-1161724Наблюдать
Cross-site scripting (XSS) vulnerability in atmail prior to version 7.8.0.2 allows remote attackers to inject arbitrary web script or HTML w
СредняяCVSS 6,1Эксплойта нетEPSS 1 %atmail · atmail25 июл. 2017 г.
- CVE-2022-3120024Наблюдать
Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms field
СредняяCVSS 6,1Эксплойта нетEPSS 0 %atmail · atmail27 июл. 2023 г.
- CVE-2012-191821Наблюдать
Multiple directory traversal vulnerabilities in (1) compose.php and (2) libs/Atmail/SendMsg.php in @Mail WebMail Client in AtMail Open-Sourc
СредняяCVSS 5,0Эксплойта нетEPSS 4 %atmail · atmail open27 мар. 2012 г.
- CVE-2012-192021Наблюдать
@Mail WebMail Client in AtMail Open-Source 1.04 and earlier allows remote attackers to obtain configuration information via a direct request
СредняяCVSS 5,0Эксплойта нетEPSS 3 %atmail · atmail open27 мар. 2012 г.
- CVE-2012-191721Наблюдать
compose.php in @Mail WebMail Client in AtMail Open-Source before 1.05 does not properly handle ../ (dot dot slash) sequences in the unique p
СредняяCVSS 5,0Эксплойта нетEPSS 2 %atmail · atmail open27 мар. 2012 г.
- CVE-2013-601718Наблюдать
Cross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary web script or HTML
СредняяCVSS 4,3Proof of conceptEPSS 4 %atmail · atmail12 янв. 2014 г.