RSS   Vulnerabilities for 'Webmail'   RSS

2008-02-27
 
CVE-2008-1055

CWE-134
 

 
Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in the page parameter.

 
2007-05-14
 
CVE-2007-2655

CWE-noinfo
 

 
Unspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a format string vulnerability that allows remote code execution.

 
2004-12-31
 
CVE-2004-2548

 

 
Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547).

 
 
CVE-2004-2547

 

 
NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message.

 

 >>> Vendor: Netwin 12 Products
Dmail
Dnews
Cwmail
Dmailweb
Netauth
Surgeftp
Webnews
Surgeldap
Surgemail
Webmail
Dnewsweb
Smsgate


Copyright 2022, cxsecurity.com

 

Back to Top