cbcvebase.

Stalker Communigate Pro vulnerabilities

9 known vulnerabilities affecting stalker/communigate_pro.

Total CVEs
9
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM8

Vulnerabilities

Page 1 of 1
CVE-2006-0468P3HIGHCVSS 7.5PoCv5.0v5.0.1+12 more2006-01-30
CVE-2006-0468 [HIGH] CVE-2006-0468: CommuniGate Pro Core Server before 5.0.7 allows remote attackers to cause a denial of service (crash CommuniGate Pro Core Server before 5.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via LDAP messages with negative BER lengths, and possibly other vectors, as demonstrated by the ProtoVer LDAP test suite.
nvd
CVE-2000-0634P4MEDIUMCVSS 5.0PoCv3.2.42000-04-03
CVE-2000-0634 [MEDIUM] CVE-2000-0634: The web administration interface for CommuniGate Pro 3.2.5 and earlier allows remote attackers to re The web administration interface for CommuniGate Pro 3.2.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.
nvd
CVE-2007-2718P4MEDIUMCVSS 4.3PoC≤ 5.1.82007-05-16
CVE-2007-2718 [MEDIUM] CVE-2007-2718: Cross-site scripting (XSS) vulnerability in the WebMail system in Stalker CommuniGate Pro 5.1.8 and Cross-site scripting (XSS) vulnerability in the WebMail system in Stalker CommuniGate Pro 5.1.8 and earlier, when using Microsoft Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via crafted STYLE tags.
nvd
CVE-2003-1481P4MEDIUMCVSS 5.8PoCv3.1v3.2.4+12 more2003-12-31
CVE-2003-1481 [MEDIUM] CWE-200 CVE-2003-1481: CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack mail sessions via an e-mail with an IMG tag that references a malicious URL that captures the referer.
nvd
CVE-2000-1002P4MEDIUMCVSS 5.0PoCv3.3.22000-12-11
CVE-2000-1002 [MEDIUM] CVE-2000-1002: POP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid username POP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to determine valid email addresses on the server for SPAM attacks.
nvd
CVE-2018-3815P4MEDIUMCVSS 5.7v6.22018-01-08
CVE-2018-3815 [MEDIUM] CWE-287 CVE-2018-3815: The "XML Interface to Messaging, Scheduling, and Signaling" (XIMSS) protocol implementation in Commu The "XML Interface to Messaging, Scheduling, and Signaling" (XIMSS) protocol implementation in CommuniGate Pro (CGP) 6.2 suffers from a Missing XIMSS Protocol Validation attack that leads to an email spoofing attack, allowing a malicious authenticated attacker to send a message from any source email address. The attack uses an HTTP POST request to a /
nvd
CVE-2005-1007P4MEDIUMCVSS 5.0v4.3c1v4.3c22005-05-02
CVE-2005-1007 [MEDIUM] CVE-2005-1007: Unknown vulnerability in the LIST functionality in CommuniGate Pro before 4.3c3 allows remote attack Unknown vulnerability in the LIST functionality in CommuniGate Pro before 4.3c3 allows remote attackers to cause a denial of service (server crash) via certain multipart messages.
nvd
CVE-1999-0865P4MEDIUMCVSS 5.0v3.11999-12-03
CVE-1999-0865 [MEDIUM] CVE-1999-0865: Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port. Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port.
nvd
CVE-2002-2375P4MEDIUMCVSS 5.0≤ 4.0b42002-12-31
CVE-2002-2375 [MEDIUM] CWE-22 CVE-2002-2375: Directory traversal vulnerability in CommuniGate Pro 4.0b4 and possibly earlier versions allows remo Directory traversal vulnerability in CommuniGate Pro 4.0b4 and possibly earlier versions allows remote attackers to list the contents of the WebUser directory and its parent directory via a (1) .. (dot dot) or (2) . (dot) in a URL. NOTE: it is not clear whether this issue reveals any more information regarding directory structure than is already availa
nvd
Stalker Communigate Pro vulnerabilities | cvebase