Show filters
51 Total Results
Displaying 11-20 of 51
Sort by:
Attacker Value
Unknown

CVE-2015-0655

Disclosure Date: February 28, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Unified Web Interaction Manager in Cisco Unified Web and E-Mail Interaction Manager allows remote attackers to inject arbitrary web script or HTML via vectors related to a POST request, aka Bug ID CSCus74184.
0
Attacker Value
Unknown

CVE-2014-2193

Disclosure Date: May 20, 2014 (last updated October 05, 2023)
Cisco Unified Web and E-Mail Interaction Manager places session identifiers in GET requests, which allows remote attackers to inject conversation text by obtaining a valid identifier, aka Bug ID CSCuj43084.
0
Attacker Value
Unknown

CVE-2014-2194

Disclosure Date: May 20, 2014 (last updated October 05, 2023)
system/egain/chat/entrypoint in Cisco Unified Web and E-mail Interaction Manager 9.0(2) allows remote attackers to have an unspecified impact by injecting a spoofed XML external entity.
0
Attacker Value
Unknown

CVE-2014-2192

Disclosure Date: May 20, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Cisco Unified Web and E-mail Interaction Manager 9.0(2) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuj43033.
0
Attacker Value
Unknown

CVE-2008-6873

Disclosure Date: July 23, 2009 (last updated October 04, 2023)
SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parameter to (1) popaccounts.aspx, (2) addressbook.aspx, and (3) emails.aspx.
0
Attacker Value
Unknown

CVE-2009-1591

Disclosure Date: May 08, 2009 (last updated October 04, 2023)
CRLF injection vulnerability in CGI RESCUE Web Mailer before 1.04 allows remote attackers to inject arbitrary HTTP headers, and conduct cross-site scripting (XSS) or HTTP response splitting attacks, via CRLF sequences in an unspecified web form.
0
Attacker Value
Unknown

CVE-2008-5973

Disclosure Date: January 27, 2009 (last updated October 04, 2023)
SQL injection vulnerability in login.aspx in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.
0
Attacker Value
Unknown

CVE-2007-0447

Disclosure Date: October 05, 2007 (last updated October 04, 2023)
Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.
0
Attacker Value
Unknown

CVE-2007-3699

Disclosure Date: October 05, 2007 (last updated October 04, 2023)
The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.
0
Attacker Value
Unknown

CVE-2006-0817

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer before 8.5.0.5 allows remote attackers to include arbitrary files via a full Windows path and drive letter in the (1) language parameter in accounts/inc/include.php and (2) lang_settings parameter in admin/inc/include.php, which is not properly sanitized by the securepath function, a related issue to CVE-2005-4556.
0