Lucene search

K
cveMitreCVE-2004-2547
HistoryNov 21, 2005 - 11:00 a.m.

CVE-2004-2547

2005-11-2111:00:00
mitre
web.nvd.nist.gov
25
netwin
surgemail
webmail
sensitive information disclosure
cve-2004-2547
nvd
http requests
security vulnerability

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0.01

Percentile

84.0%

NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or © specify a non-existent file, which reveal the path in an error message.

Affected configurations

Nvd
Node
netwinsurgemailMatch1.0c
OR
netwinsurgemailMatch1.0d
OR
netwinsurgemailMatch1.1a
OR
netwinsurgemailMatch1.1b
OR
netwinsurgemailMatch1.1c
OR
netwinsurgemailMatch1.1d
OR
netwinsurgemailMatch1.2a
OR
netwinsurgemailMatch1.2b
OR
netwinsurgemailMatch1.2c
OR
netwinsurgemailMatch1.3a
OR
netwinsurgemailMatch1.3a_rc1
OR
netwinsurgemailMatch1.3b
OR
netwinsurgemailMatch1.3c
OR
netwinsurgemailMatch1.3d
OR
netwinsurgemailMatch1.3e
OR
netwinsurgemailMatch1.3f
OR
netwinsurgemailMatch1.3g
OR
netwinsurgemailMatch1.3h
OR
netwinsurgemailMatch1.3i
OR
netwinsurgemailMatch1.3j
OR
netwinsurgemailMatch1.3k
OR
netwinsurgemailMatch1.3l
OR
netwinsurgemailMatch1.4a
OR
netwinsurgemailMatch1.4b
OR
netwinsurgemailMatch1.4c
OR
netwinsurgemailMatch1.5a
OR
netwinsurgemailMatch1.5b
OR
netwinsurgemailMatch1.5c
OR
netwinsurgemailMatch1.5d
OR
netwinsurgemailMatch1.5d2
OR
netwinsurgemailMatch1.5f
OR
netwinsurgemailMatch1.6a
OR
netwinsurgemailMatch1.6b
OR
netwinsurgemailMatch1.6d
OR
netwinsurgemailMatch1.6e
OR
netwinsurgemailMatch1.6e2
OR
netwinsurgemailMatch1.7a
OR
netwinsurgemailMatch1.7b3
OR
netwinsurgemailMatch1.8a
OR
netwinsurgemailMatch1.8b3
OR
netwinsurgemailMatch1.8d
OR
netwinsurgemailMatch1.8e
OR
netwinsurgemailMatch1.8g3
OR
netwinsurgemailMatch1.9b2
OR
netwinsurgemailMatch2.0a2
OR
netwinwebmailMatch3.1d
VendorProductVersionCPE
netwinsurgemail1.0ccpe:2.3:a:netwin:surgemail:1.0c:*:*:*:*:*:*:*
netwinsurgemail1.0dcpe:2.3:a:netwin:surgemail:1.0d:*:*:*:*:*:*:*
netwinsurgemail1.1acpe:2.3:a:netwin:surgemail:1.1a:*:*:*:*:*:*:*
netwinsurgemail1.1bcpe:2.3:a:netwin:surgemail:1.1b:*:*:*:*:*:*:*
netwinsurgemail1.1ccpe:2.3:a:netwin:surgemail:1.1c:*:*:*:*:*:*:*
netwinsurgemail1.1dcpe:2.3:a:netwin:surgemail:1.1d:*:*:*:*:*:*:*
netwinsurgemail1.2acpe:2.3:a:netwin:surgemail:1.2a:*:*:*:*:*:*:*
netwinsurgemail1.2bcpe:2.3:a:netwin:surgemail:1.2b:*:*:*:*:*:*:*
netwinsurgemail1.2ccpe:2.3:a:netwin:surgemail:1.2c:*:*:*:*:*:*:*
netwinsurgemail1.3acpe:2.3:a:netwin:surgemail:1.3a:*:*:*:*:*:*:*
Rows per page:
1-10 of 461

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0.01

Percentile

84.0%

Related for CVE-2004-2547