Filtered by vendor Netwin
Subscriptions
Total
50 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2002-0290 | 1 Netwin | 1 Webnews | 2025-04-03 | N/A |
Buffer overflow in Netwin WebNews CGI program 1.1, Webnews.exe, allows remote attackers to execute arbitrary code via a long group argument. | ||||
CVE-2002-0310 | 1 Netwin | 1 Webnews | 2025-04-03 | N/A |
Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the username/password combinations (1) testweb/newstest, (2) alwn3845/imaptest, (3) alwi3845/wtest3452, or (4) testweb2/wtest4879. | ||||
CVE-2004-2253 | 1 Netwin | 1 Surgeldap | 2025-04-03 | N/A |
Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in the page parameter of the show command. | ||||
CVE-2004-2254 | 1 Netwin | 1 Surgeldap | 2025-04-03 | N/A |
SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified utoken parameter. | ||||
CVE-2004-2318 | 1 Netwin | 1 Surgeftp | 2025-04-03 | N/A |
The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a temporary denial of service (crash) via requests with two percent (%) signs in the CMD parameter. | ||||
CVE-2004-2537 | 1 Netwin | 1 Surgemail | 2025-04-03 | N/A |
Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug." | ||||
CVE-2004-2547 | 1 Netwin | 2 Surgemail, Webmail | 2025-04-03 | N/A |
NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message. | ||||
CVE-2004-2548 | 1 Netwin | 2 Surgemail, Webmail | 2025-04-03 | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547). | ||||
CVE-2005-0845 | 1 Netwin | 1 Surgemail | 2025-04-03 | N/A |
Directory traversal vulnerability in the Webmail interface in SurgeMail 2.2g3 allows remote authenticated users to write arbitrary files or directories via a .. (dot dot) in the attach_id parameter. | ||||
CVE-2005-1034 | 1 Netwin | 1 Surgeftp | 2025-04-03 | N/A |
SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command. |