Vulnerabilities (CVE)

Filtered by vendor Macallan Subscribe
Filtered by product Mail Solution
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-0798 1 Macallan 1 Mail Solution 2024-02-04 5.5 MEDIUM N/A
Multiple directory traversal vulnerabilities in the IMAP service in Macallan Mail Solution before 4.8.05.004 allow remote authenticated users to read e-mails of other users or create, modify, or delete directories via a .. (dot dot) in the argument to the (1) CREATE, (2) SELECT, (3) DELETE, or (4) RENAME commands.
CVE-2004-2071 1 Macallan 1 Mail Solution 2024-02-04 7.5 HIGH N/A
Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authentication in the web interface via an HTTP GET request with two slashes ("//") after the server name.