Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2004-2548

Опубликовано: 31 дек. 2004
Источник: nvd
CVSS2: 4.3
EPSS Средний

Описание

Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547).

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:netwin:surgemail:*:*:*:*:*:*:*:*
Версия до 2.0a2 (включая)
cpe:2.3:a:netwin:surgemail:1.8a:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.8b3:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.8d:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.8f:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.8g3:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.9:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.9b2:*:*:*:*:*:*:*
cpe:2.3:a:netwin:webmail:3.1d:*:*:*:*:*:*:*

EPSS

Процентиль: 94%
0.1282
Средний

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547).

EPSS

Процентиль: 94%
0.1282
Средний

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other