Vulnerabilities > Mailenable > Mailenable Professional > 1.103
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2007-02-15 | CVE-2007-0652 | HTML Injection and Cross-Site Scripting vulnerability in MailEnable Web Mail Client Cross-site request forgery (CSRF) vulnerability in MailEnable Professional before 2.37 allows remote attackers to modify arbitrary configurations and perform unauthorized actions as arbitrary users via a link or IMG tag. | 5.1 |
2007-02-15 | CVE-2007-0651 | HTML Injection and Cross-Site Scripting vulnerability in MailEnable Web Mail Client Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Professional before 2.37 allow remote attackers to inject arbitrary Javascript script via (1) e-mail messages and (2) the ID parameter to (a) right.asp, (b) Forms/MAI/list.asp, and (c) Forms/VCF/list.asp in mewebmail/base/default/lang/EN/. network mailenable | 4.3 |
2006-06-28 | CVE-2006-3277 | Resource Management Errors vulnerability in Mailenable Enterprise and Mailenable Professional The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, allows remote attackers to cause a denial of service (application crash) via a HELO command with a null byte in the argument, possibly triggering a length inconsistency or a missing argument. | 5.0 |