Show filters
46 Total Results
Displaying 11-20 of 46
Sort by:
Attacker Value
Unknown
CVE-2022-22793
Disclosure Date: February 14, 2022 (last updated October 07, 2023)
Cybonet - PineApp Mail Relay Local File Inclusion. Attacker can send a request to : /manage/mailpolicymtm/log/eml_viewer/email.content.body.php?filesystem_path=ENCDODED PATH and by doing that, the attacker can read Local Files inside the server.
0
Attacker Value
Unknown
CVE-2022-22794
Disclosure Date: February 14, 2022 (last updated October 07, 2023)
Cybonet - PineApp Mail Relay Unauthenticated Sql Injection. Attacker can send a request to: /manage/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /manage/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1 and by doing that, the attacker can run Remote Code Execution in one liner.
0
Attacker Value
Unknown
CVE-2021-38370
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.
0
Attacker Value
Unknown
CVE-2020-35191
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
0
Attacker Value
Unknown
CVE-2020-35189
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
0
Attacker Value
Unknown
CVE-2020-35185
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
0
Attacker Value
Unknown
CVE-2020-29575
Disclosure Date: December 08, 2020 (last updated February 22, 2025)
The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. Systems using the elixir Linux Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password.
0
Attacker Value
Unknown
CVE-2020-29581
Disclosure Date: December 08, 2020 (last updated February 22, 2025)
The official spiped docker images before 1.5-alpine contain a blank password for a root user. Systems using the spiped docker container deployed by affected versions of the docker image may allow an remote attacker to achieve root access with a blank password.
0
Attacker Value
Unknown
CVE-2020-29578
Disclosure Date: December 08, 2020 (last updated February 22, 2025)
The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.
0
Attacker Value
Unknown
CVE-2020-14929
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.
0