CVE

CVE-2004-2547

Severity:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/2004
Last modified:
11/07/2017

Description

NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netwin:surgemail:1.0c:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.0d:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.1a:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.1b:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.1c:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.1d:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.2a:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.2b:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.2c:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.3a:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.3a_rc1:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.3b:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.3c:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.3d:*:*:*:*:*:*:*
cpe:2.3:a:netwin:surgemail:1.3e:*:*:*:*:*:*:*