ZeroHour

Vulnerabilities

9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-5670
The web services of Softnext's products, Mail SQR Expert and Mail Archiving Expert do not properly validate user input, allowing unauthenticated remote attacker

The web services of Softnext's products, Mail SQR Expert and Mail Archiving Expert do not properly validate user input, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the remote server.

NVD description · AI analysis pending
9.8<1%
  • softnext sn os
CVE-2023-48380
+4 in the same advisory: …48378 …48381 …48382 …48379
Softnext Mail SQR Expert is an email management platform, it has insufficient filtering for a special character within a spcific function.

Softnext Mail SQR Expert is an email management platform, it has insufficient filtering for a special character within a spcific function. A remote attacker authenticated as a localhost can exploit this vulnerability to perform command injection attacks, to execute arbitrary system command, manipulate system or disrupt service.

NVD description · AI analysis pending
8.0
group max
<1%
  • softnext mail sqr expert
CVE-2023-24835
Softnext Technologies Corp.’s SPAM SQR has a vulnerability of Code Injection within its specific function.

Softnext Technologies Corp.’s SPAM SQR has a vulnerability of Code Injection within its specific function. An authenticated remote attacker with administrator privilege can exploit this vulnerability to execute arbitrary system command to perform arbitrary system operation or disrupt service.

NVD description · AI analysis pending
7.2<1%
  • softnext spam sqr
CVE-2022-40741
+1 in the same advisory: …40742
Mail SQR Expert’s specific function has insufficient filtering for special characters.

Mail SQR Expert’s specific function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to perform arbitrary system command and disrupt service.

NVD description · AI analysis pending
9.8
group max
1%
  • softnext mail sqr expert