Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2021-22848

Disclosure Date: March 18, 2021 (last updated February 22, 2025)
HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege.
Attacker Value
Unknown

CVE-2020-35742

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.
Attacker Value
Unknown

CVE-2020-25848

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
Attacker Value
Unknown

CVE-2020-35740

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks.
Attacker Value
Unknown

CVE-2020-35743

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.
Attacker Value
Unknown

CVE-2020-35741

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks.