Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NetWin SurgeMail/WebMail多个输入验证漏洞
Vulnerability Description
NetWin SurgeMail/WebMail是基于WEB的邮件服务程序。 NetWin SurgeMail/WebMail多处不正确处理用户提供数据,远程攻击者可以利用这个漏洞获得敏感路径信息和进行跨站脚本攻击。 提交不存在的文件请求会导致敏感信息泄露,而对程序监听的7080端口,对恶意HTML字符缺少充分过滤,可导致跨站脚本攻击,泄露敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A