Search
Search Results (30 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2011-4540 | 1 Atmail | 1 Atmail Open | 2025-04-11 | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in AtMail Open (aka AtMail Open-Source edition) 1.04 allow remote attackers to inject arbitrary web script or HTML via the func parameter to (1) ldap.php or (2) search.php. | ||||
| CVE-2012-1918 | 1 Atmail | 1 Atmail Open | 2025-04-11 | N/A |
| Multiple directory traversal vulnerabilities in (1) compose.php and (2) libs/Atmail/SendMsg.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allow remote attackers to read arbitrary files via a .. (dot dot) in the Attachment[] parameter. | ||||
| CVE-2012-1920 | 1 Atmail | 1 Atmail Open | 2025-04-11 | N/A |
| @Mail WebMail Client in AtMail Open-Source 1.04 and earlier allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function. | ||||
| CVE-2012-1917 | 1 Atmail | 1 Atmail Open | 2025-04-11 | N/A |
| compose.php in @Mail WebMail Client in AtMail Open-Source before 1.05 does not properly handle ../ (dot dot slash) sequences in the unique parameter, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a ..././ (dot dot dot slash dot slash) sequence. | ||||
| CVE-2013-5032 | 1 Atmail | 1 Atmail | 2025-04-11 | N/A |
| Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability than CVE-2013-5031, CVE-2013-5033, and CVE-2013-5034. | ||||
| CVE-2024-24133 | 1 Atmail | 1 Atmail | 2024-11-21 | 9.8 Critical |
| Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page. | ||||
| CVE-2022-31200 | 1 Atmail | 1 Atmail | 2024-11-21 | 6.1 Medium |
| Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms field. | ||||
| CVE-2022-30776 | 1 Atmail | 1 Atmail | 2024-11-21 | 6.1 Medium |
| atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter. | ||||
| CVE-2021-43574 | 1 Atmail | 1 Atmail | 2024-11-21 | 6.1 Medium |
| WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | ||||
| CVE-2012-2593 | 1 Atmail | 1 Atmail | 2024-11-21 | 6.1 Medium |
| Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbitrary web script or HTML via the Date field of an email. | ||||