MailSherlock是一套企业邮件审核系统。 HGiga MailSherlock 存在安全漏洞,该漏洞源于不能正确地验证特定的参数。攻击者可利用该漏洞可以利用该漏洞远程发起命令注入攻击,并执行系统的任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HGiga | MailSherlock MSR45/SSR45 | unspecified ~ 115 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-25848 | 9.8 CRITICAL | HGiga MailSherlock - Broken Authentication |
| CVE-2020-25850 | 8.1 HIGH | HGiga MailSherlock - Arbitrary File Download |
| CVE-2020-35740 | 7.0 HIGH | HGiga MailSherlock - XSS -1 |
| CVE-2020-35741 | 7.0 HIGH | HGiga MailSherlock - XSS -2 |
| CVE-2020-35742 | 7.0 HIGH | HGiga MailSherlock - SQL Injection -1 |
| CVE-2020-35743 | 7.0 HIGH | HGiga MailSherlock - SQL Injection -3 |
No comments yet