Atmail kayıtları
atmail üreticisine ait 32 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
32 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2013-5034İstismar yok | Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability thaatmail · atmail | Kritik10,0 | — | %1,7 | 12 Oca 2014 |
41Planlayın | CVE-2013-5033İstismar yok | Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability thaatmail · atmail | Kritik10,0 | — | %1,7 | 12 Oca 2014 |
41Planlayın | CVE-2013-5032İstismar yok | Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability thaatmail · atmail | Kritik10,0 | — | %1,7 | 12 Oca 2014 |
41Planlayın | CVE-2013-5031İstismar yok | Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability thaatmail · atmail | Kritik10,0 | — | %1,7 | 12 Oca 2014 |
39İzleyin | CVE-2024-24133İstismar yok | Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.atmail · atmail · CWE-89 | Kritik9,8 | — | %0,6 | 7 Şub 2024 |
35İzleyin | CVE-2017-9517İstismar yok | atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.atmail · atmail · CWE-352 | Yüksek8,8 | — | %0,5 | 8 Haz 2017 |
35İzleyin | CVE-2017-9519İstismar yok | atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.atmail · atmail · CWE-352 | Yüksek8,8 | — | %0,5 | 8 Haz 2017 |
35İzleyin | CVE-2017-9518İstismar yok | atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails.atmail · atmail · CWE-352 | Yüksek8,8 | — | %0,5 | 8 Haz 2017 |
31İzleyin | CVE-2012-1916İstismar yok | @Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to execute arbitrary code via an e-mail attachment with an exatmail · atmail open | Yüksek7,5 | — | %3,4 | 27 Mar 2012 |
31İzleyin | CVE-2006-0611İstismar yok | Directory traversal vulnerability in compose.pl in @Mail 4.3 and earlier for Windows allows remote attackers to upload arbitrary files to aratmail · atmail | Yüksek7,5 | — | %1,8 | 8 Şub 2006 |
30İzleyin | CVE-2006-6701İstismar yok | Cross-site request forgery (CSRF) vulnerability in util.pl in @Mail WebMail 4.51, and util.php in 5.x before 5.03, allows remote attackers tatmail · atmail webmail · CWE-352 | Yüksek7,5 | — | %1,0 | 22 Ara 2006 |
27İzleyin | CVE-2006-6702İstismar yok | Cross-site scripting (XSS) vulnerability in Global.pm in @Mail before 4.61 allows remote attackers to inject arbitrary web script or HTML viatmail · atmail webmail | Orta6,8 | — | %1,2 | 22 Ara 2006 |
27İzleyin | CVE-2007-2153İstismar yok | Cross-site scripting (XSS) vulnerability in atmail.php in @Mail 5.0 allows remote attackers to inject arbitrary web script or HTML via the uatmail · atmail webmail | Orta6,8 | — | %1,2 | 19 Nis 2007 |
27İzleyin | CVE-2006-6704İstismar yok | Cross-site scripting (XSS) vulnerability in the Webadmin in @Mail before 4.6 allows remote attackers to inject arbitrary web script or HTML atmail · atmail webadmin | Orta6,8 | — | %1,1 | 22 Ara 2006 |
27İzleyin | CVE-2013-6028İstismar yok | Multiple cross-site request forgery (CSRF) vulnerabilities in Atmail Webmail Server before 7.2 allow remote attackers to hijack the authentiatmail · atmail · CWE-352 | Orta6,8 | — | %0,8 | 12 Oca 2014 |
26İzleyin | CVE-2012-2593Kavram kanıtı | Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbiatmail · atmail · CWE-79 | Orta6,1 | — | %6,2 | 6 Şub 2020 |
26İzleyin | CVE-2012-1919İstismar yok | CRLF injection vulnerability in mime.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to conduct directatmail · atmail open · CWE-94 | Orta6,4 | — | %2,0 | 27 Mar 2012 |
25İzleyin | CVE-2022-30776Kavram kanıtı | atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.atmail · atmail · CWE-79 | Orta6,1 | — | %4,3 | 16 May 2022 |
25İzleyin | CVE-2021-43574Kavram kanıtı | WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI.atmail · atmail · CWE-79 | Orta6,1 | — | %2,5 | 15 Kas 2021 |
24İzleyin | CVE-2017-11617İstismar yok | Cross-site scripting (XSS) vulnerability in atmail prior to version 7.8.0.2 allows remote attackers to inject arbitrary web script or HTML watmail · atmail · CWE-79 | Orta6,1 | — | %1,0 | 25 Tem 2017 |
24İzleyin | CVE-2022-31200İstismar yok | Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms fieldatmail · atmail · CWE-79 | Orta6,1 | — | %0,4 | 27 Tem 2023 |
21İzleyin | CVE-2012-1918İstismar yok | Multiple directory traversal vulnerabilities in (1) compose.php and (2) libs/Atmail/SendMsg.php in @Mail WebMail Client in AtMail Open-Sourcatmail · atmail open · CWE-22 | Orta5,0 | — | %3,5 | 27 Mar 2012 |
21İzleyin | CVE-2012-1920İstismar yok | @Mail WebMail Client in AtMail Open-Source 1.04 and earlier allows remote attackers to obtain configuration information via a direct requestatmail · atmail open · CWE-200 | Orta5,0 | — | %2,7 | 27 Mar 2012 |
21İzleyin | CVE-2012-1917İstismar yok | compose.php in @Mail WebMail Client in AtMail Open-Source before 1.05 does not properly handle ../ (dot dot slash) sequences in the unique patmail · atmail open · CWE-22 | Orta5,0 | — | %2,2 | 27 Mar 2012 |
18İzleyin | CVE-2013-6017Kavram kanıtı | Cross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary web script or HTML atmail · atmail · CWE-79 | Orta4,3 | — | %4,4 | 12 Oca 2014 |
- CVE-2013-503441Planlayın
Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability tha
KritikCVSS 10,0İstismar yokEPSS %2atmail · atmail12 Oca 2014
- CVE-2013-503341Planlayın
Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability tha
KritikCVSS 10,0İstismar yokEPSS %2atmail · atmail12 Oca 2014
- CVE-2013-503241Planlayın
Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability tha
KritikCVSS 10,0İstismar yokEPSS %2atmail · atmail12 Oca 2014
- CVE-2013-503141Planlayın
Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability tha
KritikCVSS 10,0İstismar yokEPSS %2atmail · atmail12 Oca 2014
- CVE-2024-2413339İzleyin
Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.
KritikCVSS 9,8İstismar yokEPSS %1atmail · atmail7 Şub 2024
- CVE-2017-951735İzleyin
atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.
YüksekCVSS 8,8İstismar yokEPSS %0atmail · atmail8 Haz 2017
- CVE-2017-951935İzleyin
atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.
YüksekCVSS 8,8İstismar yokEPSS %0atmail · atmail8 Haz 2017
- CVE-2017-951835İzleyin
atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails.
YüksekCVSS 8,8İstismar yokEPSS %0atmail · atmail8 Haz 2017
- CVE-2012-191631İzleyin
@Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to execute arbitrary code via an e-mail attachment with an ex
YüksekCVSS 7,5İstismar yokEPSS %3atmail · atmail open27 Mar 2012
- CVE-2006-061131İzleyin
Directory traversal vulnerability in compose.pl in @Mail 4.3 and earlier for Windows allows remote attackers to upload arbitrary files to ar
YüksekCVSS 7,5İstismar yokEPSS %2atmail · atmail8 Şub 2006
- CVE-2006-670130İzleyin
Cross-site request forgery (CSRF) vulnerability in util.pl in @Mail WebMail 4.51, and util.php in 5.x before 5.03, allows remote attackers t
YüksekCVSS 7,5İstismar yokEPSS %1atmail · atmail webmail22 Ara 2006
- CVE-2006-670227İzleyin
Cross-site scripting (XSS) vulnerability in Global.pm in @Mail before 4.61 allows remote attackers to inject arbitrary web script or HTML vi
OrtaCVSS 6,8İstismar yokEPSS %1atmail · atmail webmail22 Ara 2006
- CVE-2007-215327İzleyin
Cross-site scripting (XSS) vulnerability in atmail.php in @Mail 5.0 allows remote attackers to inject arbitrary web script or HTML via the u
OrtaCVSS 6,8İstismar yokEPSS %1atmail · atmail webmail19 Nis 2007
- CVE-2006-670427İzleyin
Cross-site scripting (XSS) vulnerability in the Webadmin in @Mail before 4.6 allows remote attackers to inject arbitrary web script or HTML
OrtaCVSS 6,8İstismar yokEPSS %1atmail · atmail webadmin22 Ara 2006
- CVE-2013-602827İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in Atmail Webmail Server before 7.2 allow remote attackers to hijack the authenti
OrtaCVSS 6,8İstismar yokEPSS %1atmail · atmail12 Oca 2014
- CVE-2012-259326İzleyin
Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbi
OrtaCVSS 6,1Kavram kanıtıEPSS %6atmail · atmail6 Şub 2020
- CVE-2012-191926İzleyin
CRLF injection vulnerability in mime.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to conduct direct
OrtaCVSS 6,4İstismar yokEPSS %2atmail · atmail open27 Mar 2012
- CVE-2022-3077625İzleyin
atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.
OrtaCVSS 6,1Kavram kanıtıEPSS %4atmail · atmail16 May 2022
- CVE-2021-4357425İzleyin
WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI.
OrtaCVSS 6,1Kavram kanıtıEPSS %2atmail · atmail15 Kas 2021
- CVE-2017-1161724İzleyin
Cross-site scripting (XSS) vulnerability in atmail prior to version 7.8.0.2 allows remote attackers to inject arbitrary web script or HTML w
OrtaCVSS 6,1İstismar yokEPSS %1atmail · atmail25 Tem 2017
- CVE-2022-3120024İzleyin
Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms field
OrtaCVSS 6,1İstismar yokEPSS %0atmail · atmail27 Tem 2023
- CVE-2012-191821İzleyin
Multiple directory traversal vulnerabilities in (1) compose.php and (2) libs/Atmail/SendMsg.php in @Mail WebMail Client in AtMail Open-Sourc
OrtaCVSS 5,0İstismar yokEPSS %4atmail · atmail open27 Mar 2012
- CVE-2012-192021İzleyin
@Mail WebMail Client in AtMail Open-Source 1.04 and earlier allows remote attackers to obtain configuration information via a direct request
OrtaCVSS 5,0İstismar yokEPSS %3atmail · atmail open27 Mar 2012
- CVE-2012-191721İzleyin
compose.php in @Mail WebMail Client in AtMail Open-Source before 1.05 does not properly handle ../ (dot dot slash) sequences in the unique p
OrtaCVSS 5,0İstismar yokEPSS %2atmail · atmail open27 Mar 2012
- CVE-2013-601718İzleyin
Cross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary web script or HTML
OrtaCVSS 4,3Kavram kanıtıEPSS %4atmail · atmail12 Oca 2014