Hastymail

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 7
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2011-4542

    Hastymail2 2.1.1 before RC2 allows remote attackers to execute arbitrary commands via the (1) rs or (2) rsargs[] parameter in a mailbox Drafts action to the default URI.

    Last Modified: Apr 11, 2025
    Published: Nov 30, 2011

    CVE-2011-4541

    Cross-site scripting (XSS) vulnerability in index.php in Hastymail2 2.1.1 before RC2 allows remote attackers to inject arbitrary web script or HTML via the rs parameter in a mailbox Drafts action.

    Last Modified: Apr 11, 2025
    Published: Nov 29, 2011

    CVE-2010-4646

    Cross-site scripting (XSS) vulnerability in Hastymail2 before 1.01 allows remote attackers to inject arbitrary web script or HTML via a crafted background attribute within a cell in a TABLE element, related to improper use of the htmLawed filter.

    Last Modified: Apr 11, 2025
    Published: Jan 18, 2011

    CVE-2009-5051

    Hastymail2 before RC 8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

    Last Modified: Apr 11, 2025
    Published: Jan 18, 2011

    CVE-2006-5313

    Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary SMTP commands by placing them after a CRLF.CRLF sequence in the smtp_message parameter. NOTE: this crosses privilege boundaries if the SMTP server configuration prevents a user from establishing a direct SMTP session. NOTE: this is a different type of issue than CVE-2006-5262.

    Last Modified: Apr 23, 2026
    Published: Oct 17, 2006
    Items Per Page
    Hastymail Vulnerabilities & Security CVEs | CVE-DB