Vulnerabilities
Vulnerable Software
Netwin:  >> Surgemail  >> 1.0d  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in NetWin Surgemail before 4.3g allows remote attackers to inject arbitrary web script or HTML via the username_ex parameter to the surgeweb program.
CVSS Score
4.3
EPSS Score
0.021
Published
2011-01-07
NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message.
CVSS Score
2.6
EPSS Score
0.16
Published
2004-12-31


Contact Us

Shodan ® - All rights reserved