VendorsWoppowarepostmasterall versions
Vulnerabilities

Woppoware Postmaster

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2005-1652
message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to bypass authentication by modifying the email parameter.
Published 2005-05-18 · Modified
7.5EPSS 0.015
CVE-2005-1651
Directory traversal vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in the wmm parameter.
Published 2005-05-18 · Modified
7.5EPSS 0.015
CVE-2005-1653
Cross-site scripting (XSS) vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to inject arbitrary web script or HTML via the email parameter.
Published 2005-05-18 · Modified
6.8EPSS 0.011
CVE-2005-1650
The web mail service in Woppoware PostMaster 4.2.2 (build 3.2.5) generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.
Published 2005-05-18 · Modified
5.0EPSS 0.017