Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Open Webmail MEDIUM 6.8
CVE-2006-2190

Cross-site scripting (XSS) vulnerability in ow-shared.pl in OpenWebMail (OWM) 2.51 and earlier allows remote attackers to inject arbitrary web script…

Fix: after 2.51
Fix from $1,600 2006-05-04
Open Webmail HIGH 7.5
CVE-2005-1435

Open WebMail (OWM) before 2.51 20050430 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename.

Fix: after 2.51
Fix from $1,950 2005-05-03
Open Webmail HIGH 10.0
CVE-2004-2284

The read_list_from_file function in vacation.pl for OpenWebmail before 2.32 20040629 allows remote attackers to execute arbitrary commands via shell …

Patch available
Fix from $1,950 2004-12-31
Open Webmail MEDIUM 5.0
CVE-2004-2458

Open WebMail 2.30 and earlier, when use_syshomedir is disabled or create_syshomedir is enabled, creates new directories before authenticating, which …

Patch available
Fix from $1,600 2004-12-31
Open Webmail MEDIUM 6.8
CVE-2004-0520EPSS 7%

Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via th…

Patch available
Fix from $1,600 2004-08-18
Open Webmail MEDIUM 6.8
CVE-2004-0639EPSS 6%

Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via …

Patch available
Fix from $1,600 2004-08-06
Open Webmail MEDIUM 5.0
CVE-2002-2410

openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists o…

No fix yet
Fix from $1,600 2002-12-31
Open Webmail HIGH 7.2
CVE-2002-1385

openwebmail_init in Open WebMail 1.81 and earlier allows local users to execute arbitrary code via .. (dot dot) sequences in a login name, such as th…

Patch available
Fix from $1,950 2002-12-26