RSS   Vulnerabilities for 'Socketmail'   RSS

2007-10-23
 
CVE-2007-5649

CWE-79
 

 
Cross-site scripting (XSS) vulnerability in lostpwd.php in Creative Digital Resources SocketMail 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the lost_id parameter.

 
2006-05-31
 
CVE-2006-2681

CWE-94
 

 
PHP remote file inclusion vulnerability in SocketMail Lite and Pro 2.2.6 and earlier, when register_globals and magic_quotes are enabled, allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter to (1) index.php and (2) inc-common.php.

 


Copyright 2024, cxsecurity.com

 

Back to Top