Hgiga Mailsherlock Msr45 Ssr45 vulnerabilities
8 known vulnerabilities affecting hgiga/mailsherlock_msr45_ssr45.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH3MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2020-35851P2CRITICALCVSS 9.8≥ unspecified, < 1152020-12-31
CVE-2020-35851 [CRITICAL] CWE-78 CVE-2020-35851: HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerabili
HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command inject attacks remotely and execute arbitrary commands of the system.
nvd
CVE-2020-25848P3CRITICALCVSS 9.8≥ unspecified, < 243≥ unspecified, < 114+3 more2020-12-31
CVE-2020-25848 [CRITICAL] CWE-287 CVE-2020-25848: HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with de
HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
nvd
CVE-2021-22848P3CRITICALCVSS 9.8≥ iSherlock-user-4.5, < 120≥ iSherlock-antispam-4.5, < 1332021-03-18
CVE-2021-22848 [CRITICAL] CWE-89 CVE-2021-22848: HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL
HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege.
nvd
CVE-2020-35743P3HIGHCVSS 7.6≥ unspecified, < 120≥ unspecified, < 1332020-12-31
CVE-2020-35743 [HIGH] CWE-89 CVE-2020-35743: HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a
HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.
nvd
CVE-2020-35742P3HIGHCVSS 7.6≥ unspecified, < 120≥ unspecified, < 1332020-12-31
CVE-2020-35742 [HIGH] CWE-89 CVE-2020-35742: HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL co
HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.
nvd
CVE-2020-25850P3HIGHCVSS 7.5≥ unspecified, < 1172020-12-31
CVE-2020-25850 [HIGH] CVE-2020-25850: The function, view the source code, of HGiga MailSherlock does not validate specific characters. Rem
The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.
nvd
CVE-2020-35741P4MEDIUMCVSS 6.1≥ unspecified, < 120≥ unspecified, < 1332020-12-31
CVE-2020-35741 [MEDIUM] CWE-79 CVE-2020-35741: HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the
HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks.
nvd
CVE-2020-35740P4MEDIUMCVSS 6.1≥ unspecified, < 120≥ unspecified, < 1332020-12-31
CVE-2020-35740 [MEDIUM] CWE-79 CVE-2020-35740: HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to injec
HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks.
nvd