Show filters
49 Total Results
Displaying 21-30 of 49
Sort by:
Attacker Value
Unknown

CVE-2007-2655

Disclosure Date: May 14, 2007 (last updated October 04, 2023)
Unspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a format string vulnerability that allows remote code execution.
0
Attacker Value
Unknown

CVE-2006-5100

Disclosure Date: October 03, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the WN_BASEDIR parameter.
0
Attacker Value
Unknown

CVE-2005-1714

Disclosure Date: May 24, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
0
Attacker Value
Unknown

CVE-2005-1516

Disclosure Date: May 11, 2005 (last updated February 22, 2025)
DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog command with an incorrect password hash, which is not properly handled by the _cmd_sendlog function.
0
Attacker Value
Unknown

CVE-2005-1478

Disclosure Date: May 11, 2005 (last updated February 22, 2025)
Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifiers in the xtellmail command.
0
Attacker Value
Unknown

CVE-2005-1034

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command.
0
Attacker Value
Unknown

CVE-2005-0846

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in the email auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject arbitrary web script or HTML via the (1) message subject or (2) message header field.
0
Attacker Value
Unknown

CVE-2004-2548

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547).
0
Attacker Value
Unknown

CVE-2004-2537

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."
0
Attacker Value
Unknown

CVE-2004-2254

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified utoken parameter.
0