Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2012-2571
Disclosure Date: August 12, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in WinWebMail Server 3.8.1.6 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted Cascading Style Sheets (CSS) expression property, (3) a CSS expression property in the STYLE attribute of an arbitrary element, (4) a crafted SRC attribute of an IFRAME element, or (5) UTF-7 text in an HTTP-EQUIV="CONTENT-TYPE" META element.
0
Attacker Value
Unknown
CVE-2009-1467
Disclosure Date: May 05, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the body of a message, related to the email view and incorrect HTML filtering in the cleanHTML function in server/inc/tools.php; or the (2) title, (3) link, or (4) description element in an RSS feed, related to the getHTML function in server/inc/rss/item.php.
0
Attacker Value
Unknown
CVE-2009-1469
Disclosure Date: May 05, 2009 (last updated October 04, 2023)
CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and WebMail Server before 9.4.2 makes it easier for remote attackers to trick a user into disclosing credentials via CRLF sequences preceding a Reply-To header in the subject element of an XML document, as demonstrated by triggering an e-mail message from the server that contains a user's correct credentials, and requests that the user compose a reply that includes this message.
0
Attacker Value
Unknown
CVE-2009-1468
Disclosure Date: May 05, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) sql and (2) order_by elements in an XML search query.
0
Attacker Value
Unknown
CVE-2008-4932
Disclosure Date: November 05, 2008 (last updated October 04, 2023)
webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root.
0
Attacker Value
Unknown
CVE-2003-1192
Disclosure Date: November 03, 2003 (last updated February 22, 2025)
Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET request.
0
Attacker Value
Unknown
CVE-2000-0507
Disclosure Date: June 01, 2000 (last updated February 22, 2025)
Imate Webmail Server 2.5 allows remote attackers to cause a denial of service via a long HELO command.
0