Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2006-2138

Disclosure Date: May 02, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.29 allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter.
0
Attacker Value
Unknown

CVE-2006-0711

Disclosure Date: February 15, 2006 (last updated February 22, 2025)
The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled.
0
Attacker Value
Unknown

CVE-2006-0536

Disclosure Date: February 04, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.27 allows remote attackers to inject arbitrary web script or HTML via the sort parameter. NOTE: some sources say that the affected parameter is "date," but the demonstration URL shows that it is "sort".
0
Attacker Value
Unknown

CVE-2004-1993

Disclosure Date: May 04, 2004 (last updated February 22, 2025)
The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as "`" (backticks) in the password.
0
Attacker Value
Unknown

CVE-2003-1202

Disclosure Date: August 19, 2003 (last updated February 22, 2025)
The checklogin function in omail.pl for omail webmail 0.98.4 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) password, (2) domainname, or (3) username.
0
Attacker Value
Unknown

CVE-2002-0411

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerability in message.php for AeroMail before 1.45 allows remote attackers to execute Javascript as an AeroMail user via an email message with the script in the Subject line.
0
Attacker Value
Unknown

CVE-2002-0410

Disclosure Date: July 26, 2002 (last updated February 22, 2025)
send_message.php in AeroMail before 1.45 allows remote attackers to read arbitrary files on the server, instead of just uploaded files, via an attachment that modifies the filename to be uploaded.
0