CVE-2004-2548: XSS
Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547).
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2548?
CVE-2004-2548 is classified as a moderate severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2004-2548?
To mitigate CVE-2004-2548, upgrade to NetWin SurgeMail version 2.0c or later and ensure that input is properly sanitized.
What are the affected versions in CVE-2004-2548?
CVE-2004-2548 affects NetWin SurgeMail versions prior to 2.0c and specific versions of WebMail.
Can CVE-2004-2548 be exploited remotely?
Yes, CVE-2004-2548 can be exploited remotely through crafted URIs or by manipulating the username field in the login form.
What type of attacks are associated with CVE-2004-2548?
CVE-2004-2548 is associated with cross-site scripting (XSS) attacks that allow for arbitrary script or HTML injection.