cbcvebase.

Hgiga Mailsherlock Msr45 Ssr45 vulnerabilities

8 known vulnerabilities affecting hgiga/mailsherlock_msr45_ssr45.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH3MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2020-35851P2CRITICALCVSS 9.8≥ unspecified, < 1152020-12-31
CVE-2020-35851 [CRITICAL] CWE-78 CVE-2020-35851: HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerabili HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command inject attacks remotely and execute arbitrary commands of the system.
nvd
CVE-2020-25848P3CRITICALCVSS 9.8≥ unspecified, < 243≥ unspecified, < 114+3 more2020-12-31
CVE-2020-25848 [CRITICAL] CWE-287 CVE-2020-25848: HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with de HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
nvd
CVE-2021-22848P3CRITICALCVSS 9.8≥ iSherlock-user-4.5, < 120≥ iSherlock-antispam-4.5, < 1332021-03-18
CVE-2021-22848 [CRITICAL] CWE-89 CVE-2021-22848: HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege.
nvd
CVE-2020-35743P3HIGHCVSS 7.6≥ unspecified, < 120≥ unspecified, < 1332020-12-31
CVE-2020-35743 [HIGH] CWE-89 CVE-2020-35743: HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.
nvd
CVE-2020-35742P3HIGHCVSS 7.6≥ unspecified, < 120≥ unspecified, < 1332020-12-31
CVE-2020-35742 [HIGH] CWE-89 CVE-2020-35742: HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL co HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.
nvd
CVE-2020-25850P3HIGHCVSS 7.5≥ unspecified, < 1172020-12-31
CVE-2020-25850 [HIGH] CVE-2020-25850: The function, view the source code, of HGiga MailSherlock does not validate specific characters. Rem The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.
nvd
CVE-2020-35741P4MEDIUMCVSS 6.1≥ unspecified, < 120≥ unspecified, < 1332020-12-31
CVE-2020-35741 [MEDIUM] CWE-79 CVE-2020-35741: HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks.
nvd
CVE-2020-35740P4MEDIUMCVSS 6.1≥ unspecified, < 120≥ unspecified, < 1332020-12-31
CVE-2020-35740 [MEDIUM] CWE-79 CVE-2020-35740: HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to injec HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks.
nvd
Hgiga Mailsherlock Msr45 Ssr45 vulnerabilities | cvebase