Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
atmail atmail webmail vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2012-2593
Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote malicious users to inject arbitrary web script or HTML via the Date field of an email.
Atmail Atmail 6.4.0
1 EDB exploit
8 Github repositories
NA
CVE-2013-2585
Cross-site scripting (XSS) vulnerability in Atmail Webmail Server 6.6.x prior to 6.6.3 and 7.0.x prior to 7.0.3 allows remote malicious users to inject arbitrary web script or HTML via the PATH_INFO to index.php/mail/viewmessage/getattachment/folder/INBOX/uniqueId/<MessageID&g...
Atmail Atmail 6.6.0
Atmail Atmail 7.0.0
Atmail Atmail 7.0.1
Atmail Atmail 6.6.1
Atmail Atmail 6.6.2
NA
CVE-2013-6229
Multiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail Server 7.0.2 allow remote malicious users to inject arbitrary web script or HTML via the (1) filter parameter to index.php/mail/mail/listfoldermessages/searching/true/selectFolder/INBOX/resultContext/searchResu...
Atmail Atmail 7.0.2
3 EDB exploits
NA
CVE-2013-6028
Multiple cross-site request forgery (CSRF) vulnerabilities in Atmail Webmail Server prior to 7.2 allow remote malicious users to hijack the authentication of administrators for requests that (1) add user accounts, (2) modify user accounts, (3) delete user accounts, or (4) stop th...
Atmail Atmail
Atmail Atmail 7.1.5
Atmail Atmail 6.4.0
Atmail Atmail 6.3.6
Atmail Atmail 6.3.5
Atmail Atmail 6.3.4
Atmail Atmail 6.20.10
Atmail Atmail 7.1.3
Atmail Atmail 7.1.1
Atmail Atmail 6.6.1
Atmail Atmail 6.5.0
Atmail Atmail 6.4.1
Atmail Atmail 6.3.3
Atmail Atmail 6.3.1
Atmail Atmail 6.20.13
Atmail Atmail 6.20.11
Atmail Atmail 7.1.0
Atmail Atmail 6.6.4
Atmail Atmail 6.6.3
Atmail Atmail 6.6.2
Atmail Atmail 6.20.8
Atmail Atmail 6.20.7
NA
CVE-2013-6017
Cross-site scripting (XSS) vulnerability in Atmail Webmail Server prior to 7.2 allows remote malicious users to inject arbitrary web script or HTML via the body of an e-mail message, as demonstrated by the SRC attribute of an IFRAME element.
Atmail Atmail
Atmail Atmail 7.1.5
Atmail Atmail 6.6.2
Atmail Atmail 6.6.1
Atmail Atmail 6.3.5
Atmail Atmail 6.3.4
Atmail Atmail 6.20.6
Atmail Atmail 6.20.5
Atmail Atmail 6.20.4
Atmail Atmail 7.1.1
Atmail Atmail 7.1.0
Atmail Atmail 6.4.2
Atmail Atmail 6.4.1
Atmail Atmail 6.3.1
Atmail Atmail 6.3.0
Atmail Atmail 6.20.11
Atmail Atmail 6.20.10
Atmail Atmail 7.1.4
Atmail Atmail 7.1.3
Atmail Atmail 7.1.2
Atmail Atmail 6.6.0
Atmail Atmail 6.5.0
1 EDB exploit
NA
CVE-2012-1916
@Mail WebMail Client in AtMail Open-Source prior to 1.05 allows remote malicious users to execute arbitrary code via an e-mail attachment with an executable extension, leading to the creation of an executable file under tmp/.
Atmail Atmail Open
NA
CVE-2012-1917
compose.php in @Mail WebMail Client in AtMail Open-Source prior to 1.05 does not properly handle ../ (dot dot slash) sequences in the unique parameter, which allows remote malicious users to conduct directory traversal attacks and read arbitrary files via a ..././ (dot dot dot sl...
Atmail Atmail Open
NA
CVE-2012-1919
CRLF injection vulnerability in mime.php in @Mail WebMail Client in AtMail Open-Source prior to 1.05 allows remote malicious users to conduct directory traversal attacks and read arbitrary files via a %0A sequence followed by a .. (dot dot) in the file parameter.
Atmail Atmail Open
NA
CVE-2012-1918
Multiple directory traversal vulnerabilities in (1) compose.php and (2) libs/Atmail/SendMsg.php in @Mail WebMail Client in AtMail Open-Source prior to 1.05 allow remote malicious users to read arbitrary files via a .. (dot dot) in the Attachment[] parameter.
Atmail Atmail Open
NA
CVE-2012-1920
@Mail WebMail Client in AtMail Open-Source 1.04 and previous versions allows remote malicious users to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.
Atmail Atmail Open
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5248
CVE-2024-3110
CVE-2024-5552
CVE-2024-29415
HTML injection
CVE-2024-3095
TCP
type confusion
CVE-2024-1800
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »