Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
amax information technologies magic winmail server vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2005-3811
Directory traversal vulnerability in admin/main.php in AMAX Magic Winmail Server 4.2 (build 0824) and previous versions allows remote malicious users to overwrite arbitrary files with session information via the sid parameter.
Amax Information Technologies Magic Winmail Server
1 EDB exploit
NA
CVE-2003-0391
Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the PASS command.
Amax Information Technologies Magic Winmail Server
1 EDB exploit
NA
CVE-2005-0313
Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote malicious users to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote authenticated users t...
Amax Information Technologies Magic Winmail Server 4.0
2 EDB exploits
NA
CVE-2005-0315
The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for port scanning.
Amax Information Technologies Magic Winmail Server 4.0
NA
CVE-2005-3692
Cross-site scripting (XSS) vulnerability in AMAX Magic Winmail Server 4.2 (build 0824) and previous versions allows remote malicious users to inject arbitrary web script or HTML via the (1) retid parameter in badlogin.php, (2) Content-Type headers in HTML mails, and (3) HTML mail...
Amax Information Technologies Magic Winmail Server 4.2
NA
CVE-2004-2572
AMAX Magic Winmail Server 3.6 allows remote malicious users to obtain sensitive information by entering (1) invalid characters such as "()" or (2) a large number of characters in the Lookup field on the netaddressbook.php web form, which reveals the path in an ldaplib.p...
Amax Information Technologies Magic Winmail Server 3.6
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-26925
CVE-2023-41826
LFI
CVE-2022-22364
CVE-2024-2887
command injection
remote code execution
CVE-2024-34446
CVE-2022-48699
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started