Neosys
6 CVEs tracked since 2006. Since Sep 2006, none of them reached CISA KEV.
Neosys CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2006-09 | 6 | 0 |
Products
The products that kept showing up in Neosys's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 6 most recently published vulnerabilities affecting Neosys.
- CVE-2006-4956Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote attackers to inject arbitrary web script or HTML via the in_name parameter, as ...6.8
- CVE-2006-4953Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary SQL commands via the (1) adr_sortkey and (2) adr_sortkey_desc parameters in t...7.5
- CVE-2006-4955Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the (1) savefolder ...5.0
- CVE-2006-4954The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifyi...7.5
- CVE-2006-4951Neon WebMail for Java before 5.08 allows remote attackers to execute arbitrary Java (JSP) code by sending an e-mail message with a JSP file attachment, which is stored under the web root with a pre...7.5
- CVE-2006-4952The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail folders, specified by the folderid and tofolder...7.5
The record
- Peak rank
- #13 in Sep 2006
- Busiest month shown
- Sep 2006, 6 CVEs
- Months with a KEV entry
- 0 since Sep 2006
- Monthly snapshots
- 1 since 2006