3 results (0.008 seconds)

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 1

MDaemon SecurityGateway through 9.0.3 allows XSS via a crafted Message Content Filtering rule. This might allow domain administrators to conduct attacks against global administrators. MDaemon SecurityGateway hasta 9.0.3 permite XSS a través de una regla de filtrado de contenido de mensajes manipulada. Esto podría permitir a los administradores de dominio realizar ataques contra administradores globales. • https://github.com/vipercalling/XSSsecurityGateway/blob/main/finding https://mdaemon.com/pages/security-gateway • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 1

Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection. Alt-N MDaemon Security Gateway a través de 8.5.0 permite la inyección XML de SecurityGateway.dll?view=login • https://www.altn.com/Products/SecurityGateway-Email-Firewall https://www.swascan.com/security-advisory-alt-n-security-gateway https://www.swascan.com/security-blog • CWE-91: XML Injection (aka Blind XPath Injection) •

CVSS: 10.0EPSS: 85%CPEs: 1EXPL: 3

Stack-based buffer overflow in SecurityGateway.dll in Alt-N Technologies SecurityGateway 1.0.1 allows remote attackers to execute arbitrary code via a long username parameter. Desbordamiento de búfer basado en pila en SecurityGateway.dll de Alt-N Technologies SecurityGateway 1.0.1 permite a atacantes remotos ejecutar código de su elección mediante un parámetro username largo. • https://www.exploit-db.com/exploits/5718 https://www.exploit-db.com/exploits/16803 https://www.exploit-db.com/exploits/5827 http://files.altn.com/securitygateway/release/relnotes_en.htm http://secunia.com/advisories/30497 http://securityreason.com/securityalert/4302 http://www.securityfocus.com/bid/29457 http://www.securitytracker.com/id?1020156 http://www.vupen.com/english/advisories/2008/1717/references https://exchange.xforce.ibmcloud.com/vulnerabilities/42769 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •