CVE-2004-2548
SurgeMail < 2.0c and WebMail - Cross-Site Scripting via URI or Login Username Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-2548. PoCs published by Donnie Werner.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in SurgeMail/WebMail versions 1.9 and prior, and WebMail 3.1d. The vulnerability arises from insufficient sanitization of user-supplied data, allowing an attacker to inject malicious scripts.
Description
Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547).
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in SurgeMail/WebMail versions 1.9 and prior, and WebMail 3.1d. The vulnerability arises from insufficient sanitization of user-supplied data, allowing an attacker to inject malicious scripts.