Show filters
32 Total Results
Displaying 1-10 of 32
Sort by:
Attacker Value
Unknown
CVE-2024-24133
Disclosure Date: February 07, 2024 (last updated February 17, 2024)
Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.
0
Attacker Value
Unknown
CVE-2022-31200
Disclosure Date: July 27, 2023 (last updated October 08, 2023)
Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms field.
0
Attacker Value
Unknown
CVE-2022-30776
Disclosure Date: May 16, 2022 (last updated February 23, 2025)
atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.
0
Attacker Value
Unknown
CVE-2021-43574
Disclosure Date: November 15, 2021 (last updated February 23, 2025)
WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
0
Attacker Value
Unknown
CVE-2012-2593
Disclosure Date: February 06, 2020 (last updated February 21, 2025)
Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbitrary web script or HTML via the Date field of an email.
0
Attacker Value
Unknown
CVE-2017-11617
Disclosure Date: July 25, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in atmail prior to version 7.8.0.2 allows remote attackers to inject arbitrary web script or HTML within the body of an email via an IMG element with both single quotes and double quotes.
0
Attacker Value
Unknown
CVE-2017-9517
Disclosure Date: June 08, 2017 (last updated November 26, 2024)
atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.
0
Attacker Value
Unknown
CVE-2017-9518
Disclosure Date: June 08, 2017 (last updated November 26, 2024)
atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails.
0
Attacker Value
Unknown
CVE-2017-9519
Disclosure Date: June 08, 2017 (last updated November 26, 2024)
atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.
0
Attacker Value
Unknown
CVE-2013-2585
Disclosure Date: February 12, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Atmail Webmail Server 6.6.x before 6.6.3 and 7.0.x before 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php/mail/viewmessage/getattachment/folder/INBOX/uniqueId/<MessageID>/filenameOriginal/.
0