atmail 漏洞與 CVE 列表(32)

產品(CPE): — CVE 數: 32

atmail 漏洞概覽

彙總 atmail 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。

常見弱點模式包括 跨站腳本、CSRF、路徑處理缺陷與SQL 注入,在 生產負載與軟體部署 使用場景中可能帶來 工作階段劫持、檔案覆寫與資料外洩 等風險。

相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。

漏洞分布趨勢(近 24 個月)

顯示 12032 CVE 數
«« 第一頁 « 上一頁 第 1 / 2 頁 下一頁 »
CVE 摘要 來源 最高 CVSS EPSS % 公開時間 更新時間
CVE-2024-24133 Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page. [email protected] 9.8 0.64% 2024-02-07 2026-06-17
CVE-2022-31200 Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms field. [email protected] 6.1 0.39% 2023-07-27 2026-06-17
CVE-2022-30776 atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter. [email protected] 6.1 3.95% 2022-05-16 2026-06-17
CVE-2021-43574 WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI. NOTE: This vulnerability only affects products that are no longer supported by the maintainer [email protected] 6.1 2.42% 2021-11-15 2026-06-17
CVE-2012-2593 Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbitrary web script or HTML via the Date field of an email. [email protected] 6.1 6.23% 2020-02-06 2026-06-16
CVE-2017-11617 Cross-site scripting (XSS) vulnerability in atmail prior to version 7.8.0.2 allows remote attackers to inject arbitrary web script or HTML within the body of an email via an IMG element with both single quotes and double quotes. [email protected] 6.1 1.03% 2017-07-25 2026-06-16
CVE-2017-9519 atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account. [email protected] 8.8 0.45% 2017-06-08 2026-06-16
CVE-2017-9518 atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails. [email protected] 8.8 0.45% 2017-06-08 2026-06-16
CVE-2017-9517 atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV. [email protected] 8.8 0.45% 2017-06-08 2026-06-16
CVE-2013-2585 Cross-site scripting (XSS) vulnerability in Atmail Webmail Server 6.6.x before 6.6.3 and 7.0.x before 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php/mail/viewmessage/getattachment/folder/INBOX/uniqueId/<MessageID>/filenameOriginal/. [email protected] 4.3 1.89% 2014-02-12 2026-06-16
CVE-2013-6229 Multiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail Server 7.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) filter parameter to index.php/mail/mail/listfoldermessages/searching/true/selectFolder/INBOX/resultContext/searchResultsTab5 or (2) mailId[] parameter to index.php/mail/mail/movetofolder/fromFolder/INBOX/toFolder/INBOX.Trash. NOTE: the view attachment message process vector is already covered by CVE-2013-2585. [email protected] 4.3 1.78% 2014-02-12 2026-06-16
CVE-2013-6028 Multiple cross-site request forgery (CSRF) vulnerabilities in Atmail Webmail Server before 7.2 allow remote attackers to hijack the authentication of administrators for requests that (1) add user accounts, (2) modify user accounts, (3) delete user accounts, or (4) stop the product's service. [email protected] 6.8 0.83% 2014-01-12 2026-06-16
CVE-2013-6017 Cross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary web script or HTML via the body of an e-mail message, as demonstrated by the SRC attribute of an IFRAME element. [email protected] 4.3 4.37% 2014-01-12 2026-06-16
CVE-2013-5034 Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability than CVE-2013-5031, CVE-2013-5032, and CVE-2013-5033. [email protected] 10.0 1.67% 2014-01-12 2026-06-16
CVE-2013-5033 Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability than CVE-2013-5031, CVE-2013-5032, and CVE-2013-5034. [email protected] 10.0 1.67% 2014-01-12 2026-06-16
CVE-2013-5032 Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability than CVE-2013-5031, CVE-2013-5033, and CVE-2013-5034. [email protected] 10.0 1.67% 2014-01-12 2026-06-16
CVE-2013-5031 Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability than CVE-2013-5032, CVE-2013-5033, and CVE-2013-5034. [email protected] 10.0 1.67% 2014-01-12 2026-06-16
CVE-2012-1920 @Mail WebMail Client in AtMail Open-Source 1.04 and earlier allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function. [email protected] 5.0 2.71% 2012-03-27 2026-06-16
CVE-2012-1919 CRLF injection vulnerability in mime.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to conduct directory traversal attacks and read arbitrary files via a %0A sequence followed by a .. (dot dot) in the file parameter. [email protected] 6.4 2.07% 2012-03-27 2026-06-16
CVE-2012-1918 Multiple directory traversal vulnerabilities in (1) compose.php and (2) libs/Atmail/SendMsg.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allow remote attackers to read arbitrary files via a .. (dot dot) in the Attachment[] parameter. [email protected] 5.0 3.64% 2012-03-27 2026-06-16
«« 第一頁 « 上一頁 第 1 / 2 頁 下一頁 »
cvelogic Threat Intelligence