SibsoftCVEs & Vulnerabilities
3 CVEs affecting Sibsoft products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
3 CVEs→ All vendors
Most Affected Products
xfilesharing 2communimail 1
CVE-2019-18952CRITICAL
SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP.
14 Nov 2019
9.8
CVSS
CVE-2019-18951HIGHpoc
SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.
14 Nov 2019
7.5
CVSS
CVE-2006-1944LOWpoc
Multiple cross-site scripting (XSS) vulnerabilities in SibSoft CommuniMail 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the list_id parameter in mailadmin.cgi and (2) the form_id parameter in templates.cgi.
21 Apr 2006
2.6
CVSS
← PrevPage 1 / 1Next →