VYPR

Active Web Mail

by Active Web Mail

CVEs (4)

  • CVE-2025-42599CriKEVApr 18, 2025
    risk 0.76cvss 9.8epss 0.03

    Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition.

  • CVE-2025-52462MedJul 2, 2025
    risk 0.40cvss 6.1epss 0.00

    Cross-site scripting vulnerability exists in Active! mail 6 BuildInfo: 6.30.01004145 to 6.60.06008562. If this vulnerability is exploited, an arbitrary script may be executed on the logged-in user's web browser when the user is accessing a specially crafted URL.

  • CVE-2008-6873Jul 23, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parameter to (1) popaccounts.aspx, (2) addressbook.aspx, and (3) emails.aspx.

  • CVE-2008-5973Jan 27, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in login.aspx in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.