CVE ID | Publié | Description | Score | Gravité |
---|---|---|---|---|
SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted. | 5.3 |
Moyen |
||
In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP, including scripts which are subsequently executed with root permissions. An attacker with a privileged network position is trivially able to inject arbitrary commands. | 7.5 |
Haute |
||
TitanHQ SpamTitan before 7.01 has Improper input validation. This allows internal attackers to bypass the anti-spam filter to send malicious emails to an entire organization by modifying the URL requests sent to the application. | 5.3 |
Moyen |