Vulnerabilities
19 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-35658 | SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted. SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2020-11698 | An issue was discovered in Titan SpamTitan 7.07. An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.conf that would allow executing commands on the target server. NVD description · AI analysis pending | 9.8 group max | 73% | PoC ×3 |
| — | |
| CVE-2019-19015 | An issue was discovered in TitanHQ WebTitan before 5.18. An issue was discovered in TitanHQ WebTitan before 5.18. The proxy service (which is typically exposed to all users) allows connections to the internal PostgreSQL database of the appliance. By connecting to the database through the proxy (without password authentication), an attacker is able to fully control the appliance database. Through this, several different paths exist to gain further access, or execute code. NVD description · AI analysis pending | 9.8 group max | 3% | PoC |
| — | |
| CVE-2019-6800 | In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP, including scripts which are subsequently executed with root permissions. An attacker with a privileged network position is trivially able to inject arbitrary commands. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2018-15136 | TitanHQ SpamTitan before 7.01 has Improper input validation. TitanHQ SpamTitan before 7.01 has Improper input validation. This allows internal attackers to bypass the anti-spam filter to send malicious emails to an entire organization by modifying the URL requests sent to the application. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2017-18227 | TitanHQ WebTitan Gateway has incorrect certificate validation for the TLS interception feature. TitanHQ WebTitan Gateway has incorrect certificate validation for the TLS interception feature. NVD description · AI analysis pending | 7.5 | <1% |
| — |