cbcvebase.

Alt-N Worldclient vulnerabilities

7 known vulnerabilities affecting alt-n/worldclient.

Total CVEs
7
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM4LOW1

Vulnerabilities

Page 1 of 1
CVE-2000-0660P4MEDIUMCVSS 5.0PoCv2.12000-07-12
CVE-2000-0660 [MEDIUM] CVE-2000-0660: The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
nvd
CVE-2002-1741P4HIGHCVSS 7.2PoCv5.0v5.0.1+4 more2002-12-31
CVE-2002-1741 [HIGH] CVE-2002-1741: Directory traversal vulnerability in WorldClient.cgi in WorldClient for Alt-N Technologies MDaemon 5 Directory traversal vulnerability in WorldClient.cgi in WorldClient for Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to delete arbitrary files via a ".." (dot dot) in the Attachments parameter.
nvd
CVE-2005-4209P4MEDIUMCVSS 4.3PoCv8.1.32005-12-13
CVE-2005-4209 [MEDIUM] CWE-94 CVE-2005-4209: WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from a WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject header of an e-mail message, which prevents the user from being able to access the Inbox folder, possibly due to a cross-site scripting (XSS) vulnerability.
nvd
CVE-2002-1740P4LOWCVSS 2.1PoCv5.02002-12-31
CVE-2002-1740 [LOW] CVE-2002-1740: Buffer overflow in WorldClient.cgi in WorldClient in Alt-N Technologies MDaemon 5.0.5.0 and earlier Buffer overflow in WorldClient.cgi in WorldClient in Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to execute arbitrary code via a long folder name (NewFolder parameter).
nvd
CVE-2005-4266P4HIGHCVSS 7.5v8.1.32005-12-15
CVE-2005-4266 [HIGH] CVE-2005-4266: WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a ra WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the random value.
nvd
CVE-2008-6967P4MEDIUMCVSS 5.0≤ 10.0.1v2.1+7 more2009-08-13
CVE-2008-6967 [MEDIUM] CVE-2008-6967: Multiple unspecified vulnerabilities in WorldClient in Alt-N MDaemon before 10.02 have unknown impac Multiple unspecified vulnerabilities in WorldClient in Alt-N MDaemon before 10.02 have unknown impact and attack vectors, probably related to cross-site scripting (XSS) and WorldClient DLL 10.0.1, a different vulnerability than CVE-2008-6893.
nvd
CVE-2008-6893P4MEDIUMCVSS 4.3v10.0.22009-08-03
CVE-2008-6893 [MEDIUM] CWE-79 CVE-2008-6893: Cross-site scripting (XSS) vulnerability in Alt-N MDaemon WorldClient 10.0.2, when Internet Explorer Cross-site scripting (XSS) vulnerability in Alt-N MDaemon WorldClient 10.0.2, when Internet Explorer 7 is used, allows remote attackers to inject arbitrary web script or HTML via a crafted img tag.
nvd
Alt-N Worldclient vulnerabilities | cvebase