Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2021-36720
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
PineApp - Mail Secure - Attacker sending a request to :/blocking.php?url=<script>alert(1)</script> and stealing cookies .
0
Attacker Value
Unknown
CVE-2013-6828
Disclosure Date: November 20, 2013 (last updated October 05, 2023)
admin/management.html in PineApp Mail-SeCure allows remote attackers to bypass authentication and perform a sys_usermng operation via the it parameter.
0
Attacker Value
Unknown
CVE-2013-6830
Disclosure Date: November 20, 2013 (last updated October 05, 2023)
admin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attackers to execute arbitrary commands via shell metacharacters in the nsserver parameter during an nslookup operation.
0
Attacker Value
Unknown
CVE-2013-6831
Disclosure Date: November 20, 2013 (last updated October 05, 2023)
PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict user specifications, which allows local users to gain privileges via a sudo command that leverages access to the qmailq account.
0
Attacker Value
Unknown
CVE-2013-6829
Disclosure Date: November 20, 2013 (last updated October 05, 2023)
admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacharacters in the pinghost parameter during a ping operation.
0
Attacker Value
Unknown
CVE-2013-6827
Disclosure Date: November 20, 2013 (last updated October 05, 2023)
Absolute path traversal vulnerability in admin/viewmsg.php in PineApp Mail-SeCure allows remote attackers to read arbitrary files via a full pathname in the msg parameter.
0
Attacker Value
Unknown
CVE-2013-4987
Disclosure Date: November 08, 2013 (last updated October 05, 2023)
PineApp Mail-SeCure before 3.70 allows remote authenticated users to gain privileges by leveraging console access and providing shell metacharacters in a "system ping" command.
0
Attacker Value
Unknown
CVE-2007-2021
Disclosure Date: April 12, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Pineapple Technologies Lore 1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang_path parameter to third_party/phpmailer/class.phpmailer.php or the (2) get_plugin_file_path parameter to third_party/smarty/libs/plugins/function.html_checkboxes.php. NOTE: the affected files might be from other software packages, so this might not be a vulnerability in Lore itself. NOTE: (1) might be the same issue as CVE-2006-5734.4.
0
Attacker Value
Unknown
CVE-2007-1905
Disclosure Date: April 10, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using "<"<".
0
Attacker Value
Unknown
CVE-2006-2836
Disclosure Date: June 06, 2006 (last updated October 04, 2023)
SQL injection vulnerability in comment.php in Pineapple Technologies Lore 1.5.6 and earlier allows remote attackers to execute arbitrary SQL commands via the article_id parameter.
0