4.3

CVE-2004-2548

Exploit
Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form.  NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NetwinSurgemail Version <= 2.0a2
NetwinSurgemail Version1.8a
NetwinSurgemail Version1.8b3
NetwinSurgemail Version1.8d
NetwinSurgemail Version1.8f
NetwinSurgemail Version1.8g3
NetwinSurgemail Version1.9
NetwinSurgemail Version1.9b2
NetwinWebmail Version3.1d
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.04% 0.786
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0056.html
Patch
Exploit
http://secunia.com/advisories/11772
Patch
Vendor Advisory
http://www.exploitlabs.com/files/advisories/EXPL-A-2004-002-surgmail.txt
Exploit
http://www.netwinsite.com/surgemail/help/updates.htm
http://www.securityfocus.com/bid/10483
Patch
Exploit
http://www.osvdb.org/6746
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/16320