Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
atmail vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2007-2153
Cross-site scripting (XSS) vulnerability in atmail.php in @Mail 5.0 allows remote malicious users to inject arbitrary web script or HTML via the username parameter.
Atmail Atmail Webmail
NA
CVE-2006-6704
Cross-site scripting (XSS) vulnerability in the Webadmin in @Mail prior to 4.6 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors involving "unescaped data in the database."
Atmail Atmail Webadmin
NA
CVE-2012-1916
@Mail WebMail Client in AtMail Open-Source prior to 1.05 allows remote malicious users to execute arbitrary code via an e-mail attachment with an executable extension, leading to the creation of an executable file under tmp/.
Atmail Atmail Open
NA
CVE-2012-1917
compose.php in @Mail WebMail Client in AtMail Open-Source prior to 1.05 does not properly handle ../ (dot dot slash) sequences in the unique parameter, which allows remote malicious users to conduct directory traversal attacks and read arbitrary files via a ..././ (dot dot dot sl...
Atmail Atmail Open
NA
CVE-2012-1918
Multiple directory traversal vulnerabilities in (1) compose.php and (2) libs/Atmail/SendMsg.php in @Mail WebMail Client in AtMail Open-Source prior to 1.05 allow remote malicious users to read arbitrary files via a .. (dot dot) in the Attachment[] parameter.
Atmail Atmail Open
NA
CVE-2012-1919
CRLF injection vulnerability in mime.php in @Mail WebMail Client in AtMail Open-Source prior to 1.05 allows remote malicious users to conduct directory traversal attacks and read arbitrary files via a %0A sequence followed by a .. (dot dot) in the file parameter.
Atmail Atmail Open
NA
CVE-2012-1920
@Mail WebMail Client in AtMail Open-Source 1.04 and previous versions allows remote malicious users to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.
Atmail Atmail Open
6.1
CVSSv3
CVE-2022-30776
atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.
Atmail Atmail 6.5.0
6.1
CVSSv3
CVE-2021-43574
WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Atmail Atmail 6.5.0
6.1
CVSSv3
CVE-2022-31200
Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms field.
Atmail Atmail 5.62
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-38028
CVE-2024-32406
CVE-2024-25624
IMAP
CVE-2024-2310
CVE-2024-0874
CVE-2024-20359
XXE
remote code execution
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »