VendorsNetWinsurgemail1.5b
Vulnerabilities

NetWin Surgemail 1.5b

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2010-3201
Cross-site scripting (XSS) vulnerability in NetWin Surgemail before 4.3g allows remote attackers to inject arbitrary web script or HTML via the username_ex parameter to the surgeweb program.
Published 2011-01-07 · Modified
4.31 PoCEPSS 0.031
CVE-2004-2547
NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message.
Published 2005-11-21 · Modified
2.61 PoCEPSS 0.031