Slmail
by Seattlelab
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-4595 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2023 | An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve sensitive information stored on the server such as credential files, configuration files, application files, etc., simply by appending any of the following… | ||
| CVE-2023-4593 | Med | 0.42 | 6.5 | 0.01 | Nov 23, 2023 | Path traversal vulnerability whose exploitation could allow an authenticated remote user to bypass SecurityManager's intended restrictions and list a parent directory via any filename, such as a multiple ..%2F value affecting the 'dodoc' parameter in the /MailAdmin_dll.htm file. | ||
| CVE-2023-4594 | Med | 0.40 | 6.1 | 0.00 | Nov 23, 2023 | Stored XSS vulnerability. This vulnerability could allow an attacker to store a malicious JavaScript payload via GET and POST methods on multiple parameters in the MailAdmin_dll.htm file. | ||
| CVE-1999-0098 | 0.00 | — | 0.03 | Apr 1, 1998 | Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities. |
- risk 0.49cvss 7.5epss 0.01
An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve sensitive information stored on the server such as credential files, configuration files, application files, etc., simply by appending any of the following…
- risk 0.42cvss 6.5epss 0.01
Path traversal vulnerability whose exploitation could allow an authenticated remote user to bypass SecurityManager's intended restrictions and list a parent directory via any filename, such as a multiple ..%2F value affecting the 'dodoc' parameter in the /MailAdmin_dll.htm file.
- risk 0.40cvss 6.1epss 0.00
Stored XSS vulnerability. This vulnerability could allow an attacker to store a malicious JavaScript payload via GET and POST methods on multiple parameters in the MailAdmin_dll.htm file.
- CVE-1999-0098Apr 1, 1998risk 0.00cvss —epss 0.03
Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities.