Vulnerabilities > Mailenable > Mailenable Professional > 1.13

DATE CVE VULNERABILITY TITLE RISK
2007-02-15 CVE-2007-0652 HTML Injection and Cross-Site Scripting vulnerability in MailEnable Web Mail Client
Cross-site request forgery (CSRF) vulnerability in MailEnable Professional before 2.37 allows remote attackers to modify arbitrary configurations and perform unauthorized actions as arbitrary users via a link or IMG tag.
network
high complexity
mailenable
5.1
2007-02-15 CVE-2007-0651 HTML Injection and Cross-Site Scripting vulnerability in MailEnable Web Mail Client
Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Professional before 2.37 allow remote attackers to inject arbitrary Javascript script via (1) e-mail messages and (2) the ID parameter to (a) right.asp, (b) Forms/MAI/list.asp, and (c) Forms/VCF/list.asp in mewebmail/base/default/lang/EN/.
network
mailenable
4.3
2006-06-28 CVE-2006-3277 Resource Management Errors vulnerability in Mailenable Enterprise and Mailenable Professional
The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, allows remote attackers to cause a denial of service (application crash) via a HELO command with a null byte in the argument, possibly triggering a length inconsistency or a missing argument.
network
low complexity
mailenable CWE-399
5.0