Show filters
76 Total Results
Displaying 51-60 of 76
Sort by:
Attacker Value
Unknown
CVE-2016-10074
Disclosure Date: December 30, 2016 (last updated November 25, 2024)
The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address in the (1) From, (2) ReturnPath, or (3) Sender header.
0
Attacker Value
Unknown
CVE-2016-1142
Disclosure Date: January 16, 2016 (last updated November 25, 2024)
Seeds acmailer before 3.8.21 and 3.9.x before 3.9.15 Beta allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-8476
Disclosure Date: December 16, 2015 (last updated October 05, 2023)
Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than CVE-2012-0796.
0
Attacker Value
Unknown
CVE-2015-2971
Disclosure Date: July 19, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in Seeds acmailer before 3.8.18 and 3.9.x before 3.9.12 Beta allows remote authenticated users to delete arbitrary files via a crafted string.
0
Attacker Value
Unknown
CVE-2015-2349
Disclosure Date: March 19, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in defaultnewsletter.php in SuperWebMailer 5.60.0.01190 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTMLForm parameter.
0
Attacker Value
Unknown
CVE-2014-3897
Disclosure Date: July 29, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Homepage Decorator PerlMailer 3.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-3896
Disclosure Date: July 29, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in CGI programs in Seeds acmailer before 3.8.17 and 3.9.x before 3.9.10 Beta allow remote attackers to hijack the authentication of arbitrary users for requests that modify or delete data, as demonstrated by modifying data affecting authorization.
0
Attacker Value
Unknown
CVE-2013-4223
Disclosure Date: May 23, 2014 (last updated October 05, 2023)
The Gentoo Nullmailer package before 1.11-r2 uses world-readable permissions for /etc/nullmailer/remotes, which allows local users to obtain SMTP authentication credentials by reading the file.
0
Attacker Value
Unknown
CVE-2009-4750
Disclosure Date: March 26, 2010 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in home.php in Top Paidmailer allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
0
Attacker Value
Unknown
CVE-2009-2378
Disclosure Date: July 08, 2009 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in formmailer.admin.inc.php in Jax FormMailer 3.0.0 allows remote attackers to execute arbitrary PHP code via a URL in the BASE_DIR[jax_formmailer] parameter.
0