CVE-2024-56085

CVSS v3 Score
5.9
Medium

Vulnerability Description

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.

CVSS:5.9(Medium)

In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail. This allows e-mail messages and user credentials...

CWE-772020
CVSS:5.9(Medium)

An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cleartext commands int...

CWE-772020
CVSS:5.9(Medium)

IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability. IBM X-Force ID: 186700.

CWE-772020
CVSS:5.9(Medium)

In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.

CWE-772021
CVSS:5.9(Medium)

Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks, leading potentially...

CWE-772021
CVSS:5.9(Medium)

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.

CWE-772024