Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
atmail vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2022-30776
atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.
Atmail Atmail 6.5.0
NA
CVE-2022-31200
Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms field.
Atmail Atmail 5.62
7.5
CVSSv2
CVE-2012-1916
@Mail WebMail Client in AtMail Open-Source prior to 1.05 allows remote malicious users to execute arbitrary code via an e-mail attachment with an executable extension, leading to the creation of an executable file under tmp/.
Atmail Atmail Open
5
CVSSv2
CVE-2012-1917
compose.php in @Mail WebMail Client in AtMail Open-Source prior to 1.05 does not properly handle ../ (dot dot slash) sequences in the unique parameter, which allows remote malicious users to conduct directory traversal attacks and read arbitrary files via a ..././ (dot dot dot sl...
Atmail Atmail Open
5
CVSSv2
CVE-2012-1918
Multiple directory traversal vulnerabilities in (1) compose.php and (2) libs/Atmail/SendMsg.php in @Mail WebMail Client in AtMail Open-Source prior to 1.05 allow remote malicious users to read arbitrary files via a .. (dot dot) in the Attachment[] parameter.
Atmail Atmail Open
6.4
CVSSv2
CVE-2012-1919
CRLF injection vulnerability in mime.php in @Mail WebMail Client in AtMail Open-Source prior to 1.05 allows remote malicious users to conduct directory traversal attacks and read arbitrary files via a %0A sequence followed by a .. (dot dot) in the file parameter.
Atmail Atmail Open
5
CVSSv2
CVE-2012-1920
@Mail WebMail Client in AtMail Open-Source 1.04 and previous versions allows remote malicious users to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.
Atmail Atmail Open
6.8
CVSSv2
CVE-2007-2153
Cross-site scripting (XSS) vulnerability in atmail.php in @Mail 5.0 allows remote malicious users to inject arbitrary web script or HTML via the username parameter.
Atmail Atmail Webmail
4.3
CVSSv2
CVE-2013-6229
Multiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail Server 7.0.2 allow remote malicious users to inject arbitrary web script or HTML via the (1) filter parameter to index.php/mail/mail/listfoldermessages/searching/true/selectFolder/INBOX/resultContext/searchResu...
Atmail Atmail 7.0.2
3 EDB exploits
6.8
CVSSv2
CVE-2006-6704
Cross-site scripting (XSS) vulnerability in the Webadmin in @Mail prior to 4.6 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors involving "unescaped data in the database."
Atmail Atmail Webadmin
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
encryption
CVE-2024-4331
CVE-2024-26925
arbitrary code
CVE-2006-4304
CVE-2024-25458
CVE-2024-27077
reflected XSS
CVE-2024-4059
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »