Skip to main content

Vendor archive

afterlogic CVEs

Beta · best-effort

12 CVEs tagged to vendor afterlogic1 Critical, 2 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2023-43176

Published Oct 3, 2023

A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26294

Published Mar 7, 2021

An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26293

Published Mar 4, 2021

An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allow directory traversal to create new files (such as an execu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-16238

Published Sep 12, 2019

Afterlogic Aurora through 8.3.9-build-a3 has XSS that can be leveraged for session hijacking by retrieving the session cookie from the administrator login.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2587

Published Aug 12, 2012

Multiple cross-site scripting (XSS) vulnerabilities in AfterLogic MailSuite Pro 6.3 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4743

Published Mar 26, 2010

Multiple cross-site scripting (XSS) vulnerabilities in history-storage.aspx in AfterLogic WebMail Pro 4.7.10 and earlier allow remote attackers to inject arbitrary web script or H…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0631

Published Feb 6, 2008

Multiple ActiveX controls in MailBee.dll in MailBee Objects 5.5 allow remote attackers to (1) overwrite arbitrary files via the SaveToDisk method, or (2) modify files via the AddS…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0333

Published Jan 17, 2008

Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read arbitrary files via a .. (dot…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5290

Published Oct 9, 2007

Multiple cross-site scripting (XSS) vulnerabilities in MailBee WebMail Pro 3.4 and earlier; and possibly MailBee WebMail Pro ASP before 3.4.64, WebMail Lite ASP before 4.0.11, and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2061

Published Apr 18, 2007

Cross-site scripting (XSS) vulnerability in check_login.asp in AfterLogic MailBee WebMail Pro 3.4 allows remote attackers to inject arbitrary web script or HTML via the username p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1