First published: Thu Mar 18 2021(Updated: )
HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Hgiga Msr45 Isherlock-antispam | <4.5-133 | |
Hgiga Msr45 Isherlock-user | <4.5-120 | |
Hgiga Ssr45 Isherlock-antispam | <4.5-133 | |
Hgiga Ssr45 Isherlock-user | <4.5-120 |
MailSherlock MSR45/SSR45 Module: iSherlock-user-4.5-120.i386.rpm and iSherlock-antispam-4.5-133.i386.rpm
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.