ZeroHour

Vulnerabilities

19 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-35658
SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.

SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.

NVD description · AI analysis pending
5.3<1% PoC
  • titanhq spamtitan
CVE-2020-11698
An issue was discovered in Titan SpamTitan 7.07.

An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.conf that would allow executing commands on the target server.

NVD description · AI analysis pending
9.8
group max
73% PoC ×3
  • titanhq spamtitan
CVE-2019-19015
An issue was discovered in TitanHQ WebTitan before 5.18.

An issue was discovered in TitanHQ WebTitan before 5.18. The proxy service (which is typically exposed to all users) allows connections to the internal PostgreSQL database of the appliance. By connecting to the database through the proxy (without password authentication), an attacker is able to fully control the appliance database. Through this, several different paths exist to gain further access, or execute code.

NVD description · AI analysis pending
9.8
group max
3% PoC
  • titanhq webtitan
CVE-2019-6800
In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function.

In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP, including scripts which are subsequently executed with root permissions. An attacker with a privileged network position is trivially able to inject arbitrary commands.

NVD description · AI analysis pending
7.51% PoC
  • titanhq spamtitan
CVE-2018-15136
TitanHQ SpamTitan before 7.01 has Improper input validation.

TitanHQ SpamTitan before 7.01 has Improper input validation. This allows internal attackers to bypass the anti-spam filter to send malicious emails to an entire organization by modifying the URL requests sent to the application.

NVD description · AI analysis pending
5.3<1% PoC
  • titanhq spamtitan
CVE-2017-18227
TitanHQ WebTitan Gateway has incorrect certificate validation for the TLS interception feature.

TitanHQ WebTitan Gateway has incorrect certificate validation for the TLS interception feature.

NVD description · AI analysis pending
7.5<1%
  • titanhq webtitan gateway