NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message.
2004-12-31T05:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 2.6 (LOW)
AV:N/AC:H/Au:N/C:P/I:N/A:N
4.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | netwin | surgemail | 1.0c | Yes |
Application | netwin | surgemail | 1.0d | Yes |
Application | netwin | surgemail | 1.1a | Yes |
Application | netwin | surgemail | 1.1b | Yes |
Application | netwin | surgemail | 1.1c | Yes |
Application | netwin | surgemail | 1.1d | Yes |
Application | netwin | surgemail | 1.2a | Yes |
Application | netwin | surgemail | 1.2b | Yes |
Application | netwin | surgemail | 1.2c | Yes |
Application | netwin | surgemail | 1.3a | Yes |
Application | netwin | surgemail | 1.3a_rc1 | Yes |
Application | netwin | surgemail | 1.3b | Yes |
Application | netwin | surgemail | 1.3c | Yes |
Application | netwin | surgemail | 1.3d | Yes |
Application | netwin | surgemail | 1.3e | Yes |
Application | netwin | surgemail | 1.3f | Yes |
Application | netwin | surgemail | 1.3g | Yes |
Application | netwin | surgemail | 1.3h | Yes |
Application | netwin | surgemail | 1.3i | Yes |
Application | netwin | surgemail | 1.3j | Yes |
Application | netwin | surgemail | 1.3k | Yes |
Application | netwin | surgemail | 1.3l | Yes |
Application | netwin | surgemail | 1.4a | Yes |
Application | netwin | surgemail | 1.4b | Yes |
Application | netwin | surgemail | 1.4c | Yes |
Application | netwin | surgemail | 1.5a | Yes |
Application | netwin | surgemail | 1.5b | Yes |
Application | netwin | surgemail | 1.5c | Yes |
Application | netwin | surgemail | 1.5d | Yes |
Application | netwin | surgemail | 1.5d2 | Yes |
Application | netwin | surgemail | 1.5f | Yes |
Application | netwin | surgemail | 1.6a | Yes |
Application | netwin | surgemail | 1.6b | Yes |
Application | netwin | surgemail | 1.6d | Yes |
Application | netwin | surgemail | 1.6e | Yes |
Application | netwin | surgemail | 1.6e2 | Yes |
Application | netwin | surgemail | 1.7a | Yes |
Application | netwin | surgemail | 1.7b3 | Yes |
Application | netwin | surgemail | 1.8a | Yes |
Application | netwin | surgemail | 1.8b3 | Yes |
Application | netwin | surgemail | 1.8d | Yes |
Application | netwin | surgemail | 1.8e | Yes |
Application | netwin | surgemail | 1.8g3 | Yes |
Application | netwin | surgemail | 1.9b2 | Yes |
Application | netwin | surgemail | 2.0a2 | Yes |
Application | netwin | webmail | 3.1d | Yes |