CVE-2004-2548
Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547).
- Netwin Surgemail
- ≤ 2.0a2, 1.8a, 1.8b3, 1.8d, 1.8f, 1.8g3, 1.9, 1.9b2
- Netwin Webmail
- = 3.1d
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 2.0% (79th percentile)
- NVD status
- Modified
- Published
- 2005-11-21
CVE-2004-2548 at NVD
1 known exploit for CVE-2004-2548
Proof-of-concept code and exploit modules indexed by Sploitus