Show filters
35 Total Results
Displaying 11-20 of 35
Sort by:
Attacker Value
Unknown
CVE-2021-22848
Disclosure Date: March 18, 2021 (last updated February 22, 2025)
HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege.
0
Attacker Value
Unknown
CVE-2020-35742
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.
0
Attacker Value
Unknown
CVE-2020-25848
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
0
Attacker Value
Unknown
CVE-2020-35740
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks.
0
Attacker Value
Unknown
CVE-2020-35743
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.
0
Attacker Value
Unknown
CVE-2020-35741
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks.
0
Attacker Value
Unknown
CVE-2016-10990
Disclosure Date: September 17, 2019 (last updated November 27, 2024)
The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header.
0
Attacker Value
Unknown
CVE-2019-17515
Disclosure Date: March 28, 2019 (last updated November 27, 2024)
The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php and inc/cleantalk-comments.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.
0
Attacker Value
Unknown
CVE-2008-6690
Disclosure Date: April 10, 2009 (last updated October 04, 2023)
Unspecified vulnerability in nepa-design.de Spam Protection (nd_antispam) extension 1.0.3 for TYPO3 allows remote attackers to modify configuration via unknown vectors.
0
Attacker Value
Unknown
CVE-2007-0447
Disclosure Date: October 05, 2007 (last updated October 04, 2023)
Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.
0