Vulnerabilities > Activewebsoftwares > Active WEB Mail > High

DATE CVE VULNERABILITY TITLE RISK
2009-07-23 CVE-2008-6873 SQL Injection vulnerability in Activewebsoftwares Active web Mail 4.0
SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parameter to (1) popaccounts.aspx, (2) addressbook.aspx, and (3) emails.aspx.
network
low complexity
activewebsoftwares CWE-89
7.5
2009-01-27 CVE-2008-5973 SQL Injection vulnerability in Activewebsoftwares Active web Mail 4.0
SQL injection vulnerability in login.aspx in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.
network
low complexity
activewebsoftwares CWE-89
7.5