Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown
CVE-2024-4299
Disclosure Date: April 29, 2024 (last updated January 05, 2025)
The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary system commands.
0
Attacker Value
Unknown
CVE-2024-4298
Disclosure Date: April 29, 2024 (last updated April 29, 2024)
The email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary system commands.
0
Attacker Value
Unknown
CVE-2024-4297
Disclosure Date: April 29, 2024 (last updated January 05, 2025)
The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files.
0
Attacker Value
Unknown
CVE-2024-4296
Disclosure Date: April 29, 2024 (last updated January 05, 2025)
The account management interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files.
0
Attacker Value
Unknown
CVE-2023-37292
Disclosure Date: July 21, 2023 (last updated October 08, 2023)
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in HGiga iSherlock 4.5 (iSherlock-user modules), HGiga iSherlock 5.5 (iSherlock-user modules) allows OS Command Injection.This issue affects iSherlock 4.5: before iSherlock-user-4.5-174; iSherlock 5.5: before iSherlock-user-5.5-174.
0
Attacker Value
Unknown
CVE-2021-22848
Disclosure Date: March 18, 2021 (last updated February 22, 2025)
HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege.
0
Attacker Value
Unknown
CVE-2020-35742
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.
0
Attacker Value
Unknown
CVE-2020-25848
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
0
Attacker Value
Unknown
CVE-2020-25850
Disclosure Date: December 31, 2020 (last updated November 28, 2024)
The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.
0
Attacker Value
Unknown
CVE-2020-35740
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks.
0