Page 6 of 51 results (0.005 seconds)

CVSS: 5.0EPSS: 1%CPEs: 2EXPL: 0

SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command. • http://marc.info/?l=bugtraq&m=111289226204780&w=2 http://secunia.com/advisories/14888 http://securitytracker.com/id?1013664 http://www.security.org.sg/vuln/surgeftp22m1.html http://www.securityfocus.com/bid/13054 https://exchange.xforce.ibmcloud.com/vulnerabilities/20011 •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in the email auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject arbitrary web script or HTML via the (1) message subject or (2) message header field. • http://marc.info/?l=bugtraq&m=111159967417903&w=2 http://netwinsite.com/cgi/dnewsweb.cgi?cmd=article&group=netwin.surgemail&item=8814&utag= http://secunia.com/advisories/14658 http://www.security.org.sg/vuln/surgemail22g3.html •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

Directory traversal vulnerability in the Webmail interface in SurgeMail 2.2g3 allows remote authenticated users to write arbitrary files or directories via a .. (dot dot) in the attach_id parameter. • http://marc.info/?l=bugtraq&m=111159967417903&w=2 http://netwinsite.com/cgi/dnewsweb.cgi?cmd=article&group=netwin.surgemail&item=8814&utag= http://secunia.com/advisories/14658 http://www.security.org.sg/vuln/surgemail22g3.html •

CVSS: 2.6EPSS: 1%CPEs: 46EXPL: 5

NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message. • https://www.exploit-db.com/exploits/24176 http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0056.html http://secunia.com/advisories/11772 http://www.exploitlabs.com/files/advisories/EXPL-A-2004-002-surgmail.txt http://www.netwinsite.com/surgemail/help/updates.htm http://www.osvdb.org/6745 http://www.securityfocus.com/bid/10483 https://exchange.xforce.ibmcloud.com/vulnerabilities/16319 •

CVSS: 5.0EPSS: 1%CPEs: 3EXPL: 4

Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in the page parameter of the show command. • https://www.exploit-db.com/exploits/23987 http://members.lycos.co.uk/r34ct/main/SurgeLDAP%201.0g.txt http://secunia.com/advisories/11343 http://www.securityfocus.com/bid/10103 https://exchange.xforce.ibmcloud.com/vulnerabilities/15851 •