Page 4 of 52 results (0.005 seconds)

CVSS: 7.5EPSS: 1%CPEs: 11EXPL: 2

31 Dec 2004 — The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a temporary denial of service (crash) via requests with two percent (%) signs in the CMD parameter. • http://members.lycos.co.uk/r34ct/main/surge_FTP/surge-ftp.txt •

CVSS: 5.3EPSS: 16%CPEs: 46EXPL: 5

31 Dec 2004 — NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message. • https://www.exploit-db.com/exploits/24176 •

CVSS: 10.0EPSS: 0%CPEs: 14EXPL: 0

31 Dec 2004 — Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug." • http://netwinsite.com/surgemail/help/updates.htm •

CVSS: 9.8EPSS: 13%CPEs: 6EXPL: 6

31 Dec 2004 — SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified utoken parameter. • https://www.exploit-db.com/exploits/24094 •

CVSS: 6.1EPSS: 11%CPEs: 9EXPL: 5

31 Dec 2004 — Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547). • https://www.exploit-db.com/exploits/24177 •

CVSS: 9.8EPSS: 3%CPEs: 3EXPL: 0

31 May 2002 — Buffer overflow in Netwin WebNews CGI program 1.1, Webnews.exe, allows remote attackers to execute arbitrary code via a long group argument. Desbordamiento de búfer en Netwin WebNews CGI program 1.1, Webnews.exe, permite a atacantes remotos ejecutar código arbitrarior mediante un argumento de grupo largo. • ftp://netwinsite.com/pub/webnews/beta/webnews11m_solaris.tar.Z •

CVSS: 8.8EPSS: 0%CPEs: 17EXPL: 0

03 May 2002 — Buffer overflow in CWMail.exe in NetWin before 2.8a allows remote authenticated users to execute arbitrary code via a long item parameter. Desbordamiento de búfer en CWMail.exe en NetWin anteriores a 2.8a permite a usuarios remotos remotos ejecutar código arbitrario mediante un parámetro largo. • http://marc.info/?l=bugtraq&m=101362100602008&w=2 •

CVSS: 9.8EPSS: 0%CPEs: 4EXPL: 0

03 May 2002 — Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the username/password combinations (1) testweb/newstest, (2) alwn3845/imaptest, (3) alwi3845/wtest3452, or (4) testweb2/wtest4879. El programa CGI Netwin WebNews 1.1k incluye por defecto ciertos nombres de usuarios y contraseñas en texto claro que no pueden ser borrados por el administrador, lo que permite a atacantes rem... • http://marc.info/?l=bugtraq&m=101432236729631&w=2 •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 2

20 Sep 2001 — NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con. • http://netwinsite.com/surgeftp/manual/updates.htm •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 2

20 Sep 2001 — Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and directories via the 'nlist ...' command. • http://www.netwinsite.com/surgeftp/manual/updates.htm •