Show filters
61 Total Results
Displaying 51-60 of 61
Sort by:
Attacker Value
Unknown
CVE-2018-1002004
Disclosure Date: December 03, 2018 (last updated November 27, 2024)
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.
0
Attacker Value
Unknown
CVE-2018-1002009
Disclosure Date: December 03, 2018 (last updated November 27, 2024)
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in unsubscribe.html.php:3: via GET reuqest to the email variable.
0
Attacker Value
Unknown
CVE-2018-1002003
Disclosure Date: December 03, 2018 (last updated November 27, 2024)
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.
0
Attacker Value
Unknown
CVE-2018-1002005
Disclosure Date: December 03, 2018 (last updated November 27, 2024)
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:43: via the filter_signup_date parameter.
0
Attacker Value
Unknown
CVE-2018-18461
Disclosure Date: October 18, 2018 (last updated November 27, 2024)
The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via PHP code in attachments[] data to models/attachment.php.
0
Attacker Value
Unknown
CVE-2009-4824
Disclosure Date: April 27, 2010 (last updated October 04, 2023)
Unspecified vulnerability in Kolab Webclient before 1.2.0 in Kolab Server before 2.2.3 allows attackers to have an unspecified impact via vectors related to an "image upload form."
0
Attacker Value
Unknown
CVE-2008-4165
Disclosure Date: September 22, 2008 (last updated October 04, 2023)
admin/user/create_user.php in Kolab Groupware Server 1.0.0 places a user password in an HTTP GET request, which allows local administrators, and possibly remote attackers, to obtain cleartext passwords by reading the ssl_access_log file or the referer string.
0
Attacker Value
Unknown
CVE-2007-4510
Disclosure Date: August 23, 2007 (last updated October 04, 2023)
ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other products, allows remote attackers to cause a denial of service (application crash) via (1) a crafted RTF file, which triggers a NULL dereference in the cli_scanrtf function in libclamav/rtf.c; or (2) a crafted HTML document with a data: URI, which triggers a NULL dereference in the cli_html_normalise function in libclamav/htmlnorm.c. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2006-0213
Disclosure Date: January 14, 2006 (last updated February 22, 2025)
Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier, when authenticating users via secure SMTP, stores authentication credentials in plaintext in the postfix.log file, which allows local users to gain privileges.
0
Attacker Value
Unknown
CVE-2005-4828
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Kolab Server 2.0.0 and 2.0.1 does not properly handle when a large email is sent with a "." in the wrong place, which causes kolabfilter to add another ".", which might break clear-text signatures and attachments. NOTE: it is not clear whether this issue crosses privilege boundaries, so this might not be a vulnerability.
0