CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted. | 5.3 |
Medium |
||
In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP, including scripts which are subsequently executed with root permissions. An attacker with a privileged network position is trivially able to inject arbitrary commands. | 7.5 |
High |