Amax Information Technologies maintains a focused product portfolio centered around email server software, principally Magic WinMail Server and related mail-handling products, which occupy a specialized niche in messaging infrastructure. While the vendor's disclosures carry a notable tendency toward public exploit availability, the recurring weakness-class signals are sparse and largely categorized generically in public records, limiting structural insight into attack patterns. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Amax Information Technologies over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-0313HIGH Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) | Jan 27, 2005 | 7.5 | 35 | NO | YES |
CVE-2003-0391HIGH Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrar | Jul 2, 2003 | 7.5 | 29 | NO | YES |
CVE-2005-3811MEDIUM Directory traversal vulnerability in admin/main.php in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to overwrite arbitrary files with session info | Nov 25, 2005 | 5.0 | 27 | NO | YES |
CVE-2006-1250HIGH Unspecified vulnerability in the Webmail module in Winmail before 4.3 has unknown impact and unknown remote attack vectors. | Mar 19, 2006 | 10.0 | 25 | NO | NO |
CVE-2005-0315MEDIUM The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which all | Jan 27, 2005 | 4.6 | 18 | NO | NO |
CVE-2005-3692MEDIUM Cross-site scripting (XSS) vulnerability in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) retid | Nov 19, 2005 | 4.3 | 16 | NO | NO |
CVE-2004-2572MEDIUM AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) invalid characters such as "()" or (2) a large number of characters in the Loo | Dec 31, 2004 | 5.0 | 15 | NO | NO |
CVE-2005-0314MEDIUM Cross-site scripting (XSS) vulnerability in user.php in Magic Winmail Server 4.0 Build 1112 allows remote attackers to inject arbitrary web script or HTML via the personal informat | Jan 27, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Amax Information Technologies.
Media articles that mention a CVE ID that affects a product developed by Amax Information Technologies — matched by CVE ID, not by vendor name.