Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-2548
CVE-2004-2548
Description
Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547).
Affected products
9cpe:2.3:a:netwin:surgemail:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:netwin:surgemail:*:*:*:*:*:*:*:*range: <=2.0a2
- cpe:2.3:a:netwin:surgemail:1.8a:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:1.8b3:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:1.8d:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:1.8f:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:1.8g3:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:1.9:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:1.9b2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- secunia.com/advisories/11772nvdPatchVendor Advisory
- archives.neohapsis.com/archives/fulldisclosure/2004-06/0056.htmlnvdExploitPatch
- www.exploitlabs.com/files/advisories/EXPL-A-2004-002-surgmail.txtnvdExploit
- www.osvdb.org/6746nvdExploit
- www.securityfocus.com/bid/10483nvdExploitPatch
- www.netwinsite.com/surgemail/help/updates.htmnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/16320nvd
News mentions
0No linked articles in our index yet.