Vulnerabilities
Vulnerable Software
Mailenable:  >> Mailenable  >> 1.986  Security Vulnerabilities
Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component
CVSS Score
9.8
EPSS Score
0.051
Published
2025-06-03
MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/.. /" are mishandled.
CVSS Score
9.1
EPSS Score
0.002
Published
2019-01-16
MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB after a password-change request.
CVSS Score
9.8
EPSS Score
0.003
Published
2019-01-16
MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.
CVSS Score
6.1
EPSS Score
0.001
Published
2019-01-16


Contact Us

Shodan ® - All rights reserved