Vulnerabilities > Seeds

DATE CVE VULNERABILITY TITLE RISK
2016-01-16 CVE-2016-1142 OS Command Injection vulnerability in Seeds Acmailer
Seeds acmailer before 3.8.21 and 3.9.x before 3.9.15 Beta allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.
network
low complexity
seeds CWE-78
critical
9.0
2015-07-19 CVE-2015-2971 Path Traversal vulnerability in Seeds Acmailer
Directory traversal vulnerability in Seeds acmailer before 3.8.18 and 3.9.x before 3.9.12 Beta allows remote authenticated users to delete arbitrary files via a crafted string.
network
low complexity
seeds CWE-22
5.5
2014-07-29 CVE-2014-3896 Cross-Site Request Forgery (CSRF) vulnerability in Seeds Acmailer
Multiple cross-site request forgery (CSRF) vulnerabilities in CGI programs in Seeds acmailer before 3.8.17 and 3.9.x before 3.9.10 Beta allow remote attackers to hijack the authentication of arbitrary users for requests that modify or delete data, as demonstrated by modifying data affecting authorization.
network
seeds CWE-352
6.8