Known Vulnerabilities for products from Titanhq
Listed below are 19 of the newest known vulnerabilities associated with the vendor "Titanhq".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-35658 json | SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted. | 5.3 - MEDIUM | 2020-12-23 | 2021-07-21 |
| CVE-2020-24046 json | A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allo... | 7.2 - HIGH | 2020-09-17 | 2020-09-24 |
| CVE-2020-24045 json | A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allo... | 7.2 - HIGH | 2020-09-17 | 2021-07-21 |
| CVE-2020-11804 json | An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page mailque... | 8.8 - HIGH | 2020-09-17 | 2021-07-21 |
| CVE-2020-11803 json | An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the pag... | 8.8 - HIGH | 2020-09-17 | 2021-07-21 |
| CVE-2020-11700 json | An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.php, ... | 6.5 - MEDIUM | 2020-09-17 | 2021-07-21 |
| CVE-2020-11699 json | An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would all... | 8.8 - HIGH | 2020-09-17 | 2021-07-21 |
| CVE-2020-11698 json | An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.ph... | 9.8 - CRITICAL | 2020-09-17 | 2022-04-28 |
| CVE-2019-19021 json | An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the ... | 9.8 - CRITICAL | 2019-12-02 | 2019-12-09 |
| CVE-2019-19020 json | An issue was discovered in TitanHQ WebTitan before 5.18. In the administration web interface it is possible to upload a craft... | 7.2 - HIGH | 2019-12-02 | 2019-12-09 |
| CVE-2019-19019 json | An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an attacker ... | 7.5 - HIGH | 2019-12-02 | 2020-08-24 |
| CVE-2019-19018 json | An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfig.ini... | 2.7 - LOW | 2019-12-02 | 2021-07-21 |
| CVE-2019-19017 json | An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during installation... | 8.1 - HIGH | 2019-12-02 | 2019-12-09 |
| CVE-2019-19016 json | An issue was discovered in TitanHQ WebTitan before 5.18. Some functions, such as /history-x.php, of the administration interf... | 7.5 - HIGH | 2019-12-02 | 2019-12-04 |
| CVE-2019-19015 json | An issue was discovered in TitanHQ WebTitan before 5.18. The proxy service (which is typically exposed to all users) allows c... | 9.8 - CRITICAL | 2019-12-02 | 2019-12-06 |
| CVE-2019-19014 json | An issue was discovered in TitanHQ WebTitan before 5.18. It has a sudoers file that enables low-privilege users to execute a ... | 7.8 - HIGH | 2019-12-02 | 2019-12-06 |
| CVE-2019-6800 json | In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP,... | 7.5 - HIGH | 2019-06-05 | 2019-06-06 |
| CVE-2018-15136 json | TitanHQ SpamTitan before 7.01 has Improper input validation. This allows internal attackers to bypass the anti-spam filter to... | 5.3 - MEDIUM | 2019-01-30 | 2019-02-22 |
| CVE-2017-18227 json | TitanHQ WebTitan Gateway has incorrect certificate validation for the TLS interception feature. | 7.5 - HIGH | 2018-03-12 | 2018-04-12 |
Known software with vulnerabilities from Titanhq
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Titanhq | Spamtitan | 5.05 |
| Application | Titanhq | Webtitan | 5.12 |
| Application | Titanhq | Webtitan Cloud | 4.05 |
| Application | Titanhq | Webtitan Gateway | - |