VYPR

Acmailer

by Seeds

CVEs (3)

  • CVE-2016-1142CriJan 16, 2016
    risk 0.59cvss 9.1epss 0.01

    Seeds acmailer before 3.8.21 and 3.9.x before 3.9.15 Beta allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.

  • CVE-2015-2971Jul 19, 2015
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in Seeds acmailer before 3.8.18 and 3.9.x before 3.9.12 Beta allows remote authenticated users to delete arbitrary files via a crafted string.

  • CVE-2014-3896Jul 29, 2014
    risk 0.00cvss epss 0.00

    Multiple cross-site request forgery (CSRF) vulnerabilities in CGI programs in Seeds acmailer before 3.8.17 and 3.9.x before 3.9.10 Beta allow remote attackers to hijack the authentication of arbitrary users for requests that modify or delete data, as demonstrated by modifying data affecting authorization.