Show filters
34 Total Results
Displaying 31-34 of 34
Sort by:
Attacker Value
Unknown
CVE-2020-10511
Disclosure Date: April 15, 2020 (last updated February 21, 2025)
HGiga C&Cmail CCMAILQ before olln-base-6.0-418.i386.rpm and CCMAILN before olln-base-5.0-418.i386.rpm contains insecure configurations. Attackers can exploit these flaws to access unauthorized functionality via a crafted URL.
0
Attacker Value
Unknown
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It …
Disclosure Date: June 03, 2019 (last updated November 27, 2024)
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email sources into whitelist via user/save_list.php?ACSION=&type=email&category=white&locate=big5&cmd=add&new=hacker@socialengineering.com&new_memo=&add=%E6%96%B0%E5%A2%9E without any authorizes.
0
Attacker Value
Unknown
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It …
Disclosure Date: June 03, 2019 (last updated November 27, 2024)
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin/cf_new.cgi?chief=&wk_group=full&cf_name=test&cf_account=test&cf_email=&cf_acl=Management&apply_lang=&dn= without any authorizes.
0
Attacker Value
Unknown
SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds
Disclosure Date: February 11, 2019 (last updated November 27, 2024)
SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds allows an unauthenticated user to extract the subjects of the emails of other users within the enterprise via the select_mid parameter in an letgo.cgi request.
0