VYPR

Active Web Mail

Sign in to watch

by Activewebsoftwares

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2008-68730.030.00Jul 23, 2009SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parameter to (1) popaccounts.aspx, (2) addressbook.aspx, and (3) emails.aspx.
CVE-2008-59730.030.00Jan 27, 2009SQL injection vulnerability in login.aspx in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.