Vulnerabilities > Hastymail > Hastymail2 > 2.0.5

DATE CVE VULNERABILITY TITLE RISK
2011-11-30 CVE-2011-4542 SQL Injection vulnerability in Hastymail Hastymail2
Hastymail2 2.1.1 before RC2 allows remote attackers to execute arbitrary commands via the (1) rs or (2) rsargs[] parameter in a mailbox Drafts action to the default URI.
network
low complexity
hastymail CWE-89
7.5
2011-11-29 CVE-2011-4541 Cross-Site Scripting vulnerability in Hastymail Hastymail2
Cross-site scripting (XSS) vulnerability in index.php in Hastymail2 2.1.1 before RC2 allows remote attackers to inject arbitrary web script or HTML via the rs parameter in a mailbox Drafts action.
network
hastymail CWE-79
4.3