hMailServer 6.0.0 至 6.3.5 版本的 REST API 监听器存在主机头验证缺失以及管理员登录失败速率限制缺失的问题,攻击者可通过 DNS 重绑定技术,利用受害者浏览器对服务器管理员密码进行暴力破解。该监听器默认处于禁用状态,启用后绑定在本地回环地址(loopback);但它并未对请求中的 Host 头进行有效验证,且来自回环地址的管理员密码登录失败请求不会被自动封禁或延迟处理。攻击者可以构造一个将主机名重绑定到 127.0.0.1 的网页,并在服务器上以管理员身份打开该网页。由于上述缺陷,该
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progressive Robot Ltd | hMailServer | 6.0.0 ~ 6.3.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103647 | 8.0 HIGH | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in hM |
| CVE-2026-103010 | 7.8 HIGH | Heap-based Buffer Overflow in hMailServer |
| CVE-2026-107573 | 7.8 HIGH | Incorrect Default Permissions in hMailServer |
| CVE-2026-104658 | 7.8 HIGH | Reliance on Untrusted Inputs in a Security Decision in hMailServer |
| CVE-2026-104660 | 7.8 HIGH | Missing Authorization in hMailServer |
| CVE-2026-103649 | 7.5 HIGH | Synchronous Access of Remote Resource without Timeout in hMailServer |
| CVE-2026-107577 | 7.5 HIGH | Loop with Unreachable Exit Condition ('Infinite Loop') in hMailServer |
| CVE-2026-107574 | 7.5 HIGH | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107579 | 7.5 HIGH | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107576 | 7.5 HIGH | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107584 | 7.4 HIGH | Not Failing Securely ('Failing Open') in hMailServer |
| CVE-2026-104704 | 7.4 HIGH | Cleartext Transmission of Sensitive Information in hMailServer |
| CVE-2026-107578 | 6.7 MEDIUM | Improper Link Resolution Before File Access ('Link Following') in hMailServer |
| CVE-2026-103011 | 6.5 MEDIUM | Heap-based Buffer Overflow in hMailServer |
| CVE-2026-107572 | 6.5 MEDIUM | Inefficient Regular Expression Complexity in hMailServer |
| CVE-2026-107581 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107582 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107580 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107583 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107587 | 5.9 MEDIUM | Improper Certificate Validation in hMailServer |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet