Sploitus

CVE-2004-2548

1 known exploit for CVE-2004-2548

Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547).

Affected products
Surgemail, Webmail
Netwin Surgemail
≤ 2.0a2, 1.8a, 1.8b3, 1.8d, 1.8f, 1.8g3, 1.9, 1.9b2
Netwin Webmail
= 3.1d
CVSS 2.0
4.3 MEDIUM
EPSS
2.0% (79th percentile)
NVD status
Modified
Published
2005-11-21
CVE-2004-2548 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2004-2548

Proof-of-concept code and exploit modules indexed by Sploitus