Hgiga MailSherlock是中国恒基(Hgiga)公司的一套企业邮件审核系统。 HGiga MailSherlock 存在SQL注入漏洞,攻击者可利用该漏洞可以在特定cgi页面的URL参数中注入和启动SQL命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HGiga | MailSherlock MSR45/SSR45 | unspecified ~ 120 | - |
|
| HGiga | MailSherlock MSR45/SSR45 | unspecified ~ 133 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-25848 | 9.8 CRITICAL | HGiga MailSherlock - Broken Authentication |
| CVE-2020-25850 | 8.1 HIGH | HGiga MailSherlock - Arbitrary File Download |
| CVE-2020-35851 | 8.1 HIGH | HGiga MailSherlock - Command Injection |
| CVE-2020-35740 | 7.0 HIGH | HGiga MailSherlock - XSS -1 |
| CVE-2020-35741 | 7.0 HIGH | HGiga MailSherlock - XSS -2 |
| CVE-2020-35742 | 7.0 HIGH | HGiga MailSherlock - SQL Injection -1 |
No comments yet