Vulnerabilities > Hastymail > Hastymail2 > 2.0.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2011-11-30 | CVE-2011-4542 | SQL Injection vulnerability in Hastymail Hastymail2 Hastymail2 2.1.1 before RC2 allows remote attackers to execute arbitrary commands via the (1) rs or (2) rsargs[] parameter in a mailbox Drafts action to the default URI. | 7.5 |
2011-11-29 | CVE-2011-4541 | Cross-Site Scripting vulnerability in Hastymail Hastymail2 Cross-site scripting (XSS) vulnerability in index.php in Hastymail2 2.1.1 before RC2 allows remote attackers to inject arbitrary web script or HTML via the rs parameter in a mailbox Drafts action. | 4.3 |