Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2021-36720

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
PineApp - Mail Secure - Attacker sending a request to :/blocking.php?url=<script>alert(1)</script> and stealing cookies .
Attacker Value
Unknown

CVE-2013-6828

Disclosure Date: November 20, 2013 (last updated October 05, 2023)
admin/management.html in PineApp Mail-SeCure allows remote attackers to bypass authentication and perform a sys_usermng operation via the it parameter.
0
Attacker Value
Unknown

CVE-2013-6830

Disclosure Date: November 20, 2013 (last updated October 05, 2023)
admin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attackers to execute arbitrary commands via shell metacharacters in the nsserver parameter during an nslookup operation.
0
Attacker Value
Unknown

CVE-2013-6831

Disclosure Date: November 20, 2013 (last updated October 05, 2023)
PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict user specifications, which allows local users to gain privileges via a sudo command that leverages access to the qmailq account.
0
Attacker Value
Unknown

CVE-2013-6829

Disclosure Date: November 20, 2013 (last updated October 05, 2023)
admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacharacters in the pinghost parameter during a ping operation.
0
Attacker Value
Unknown

CVE-2013-6827

Disclosure Date: November 20, 2013 (last updated October 05, 2023)
Absolute path traversal vulnerability in admin/viewmsg.php in PineApp Mail-SeCure allows remote attackers to read arbitrary files via a full pathname in the msg parameter.
0
Attacker Value
Unknown

CVE-2013-4987

Disclosure Date: November 08, 2013 (last updated October 05, 2023)
PineApp Mail-SeCure before 3.70 allows remote authenticated users to gain privileges by leveraging console access and providing shell metacharacters in a "system ping" command.
0
Attacker Value
Unknown

CVE-2007-2021

Disclosure Date: April 12, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Pineapple Technologies Lore 1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang_path parameter to third_party/phpmailer/class.phpmailer.php or the (2) get_plugin_file_path parameter to third_party/smarty/libs/plugins/function.html_checkboxes.php. NOTE: the affected files might be from other software packages, so this might not be a vulnerability in Lore itself. NOTE: (1) might be the same issue as CVE-2006-5734.4.
0
Attacker Value
Unknown

CVE-2007-1905

Disclosure Date: April 10, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using "&lt;&quot;&lt;".
0
Attacker Value
Unknown

CVE-2006-2836

Disclosure Date: June 06, 2006 (last updated October 04, 2023)
SQL injection vulnerability in comment.php in Pineapple Technologies Lore 1.5.6 and earlier allows remote attackers to execute arbitrary SQL commands via the article_id parameter.
0