VYPR

Ssr45 Isherlock Antispam

by Hgiga

CVEs (6)

  • CVE-2020-25848CriDec 31, 2020
    risk 0.64cvss 9.8epss 0.02

    HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.

  • CVE-2021-22848HigMar 18, 2021
    risk 0.46cvss 7.0epss 0.01

    HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege.

  • CVE-2020-35743HigDec 31, 2020
    risk 0.46cvss 7.0epss 0.01

    HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.

  • CVE-2020-35742HigDec 31, 2020
    risk 0.46cvss 7.0epss 0.01

    HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.

  • CVE-2020-35741HigDec 31, 2020
    risk 0.46cvss 7.0epss 0.01

    HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks.

  • CVE-2020-35740HigDec 31, 2020
    risk 0.46cvss 7.0epss 0.01

    HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks.