Filtered by vendor Netwin
Subscribe
Total
50 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-5100 | 1 Netwin | 1 Webnews | 2024-02-28 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the WN_BASEDIR parameter. | |||||
CVE-2005-1714 | 1 Netwin | 1 Surgemail | 2024-02-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |||||
CVE-2005-0845 | 1 Netwin | 1 Surgemail | 2024-02-28 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in the Webmail interface in SurgeMail 2.2g3 allows remote authenticated users to write arbitrary files or directories via a .. (dot dot) in the attach_id parameter. | |||||
CVE-2004-2318 | 1 Netwin | 1 Surgeftp | 2024-02-28 | 5.0 MEDIUM | N/A |
The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a temporary denial of service (crash) via requests with two percent (%) signs in the CMD parameter. | |||||
CVE-2005-1478 | 1 Netwin | 1 Dmail | 2024-02-28 | 7.5 HIGH | N/A |
Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifiers in the xtellmail command. | |||||
CVE-2004-2537 | 1 Netwin | 1 Surgemail | 2024-02-28 | 10.0 HIGH | N/A |
Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug." | |||||
CVE-2005-1516 | 1 Netwin | 1 Dmail | 2024-02-28 | 7.5 HIGH | N/A |
DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog command with an incorrect password hash, which is not properly handled by the _cmd_sendlog function. | |||||
CVE-2004-2547 | 1 Netwin | 2 Surgemail, Webmail | 2024-02-28 | 2.6 LOW | N/A |
NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message. | |||||
CVE-2005-0846 | 1 Netwin | 1 Surgemail | 2024-02-28 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in the email auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject arbitrary web script or HTML via the (1) message subject or (2) message header field. | |||||
CVE-2004-2548 | 1 Netwin | 2 Surgemail, Webmail | 2024-02-28 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547). | |||||
CVE-2005-1034 | 1 Netwin | 1 Surgeftp | 2024-02-28 | 5.0 MEDIUM | N/A |
SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command. | |||||
CVE-2000-0423 | 1 Netwin | 1 Dnews | 2024-02-28 | 5.0 MEDIUM | N/A |
Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd, and utag. | |||||
CVE-2000-0782 | 1 Netwin | 1 Netauth | 2024-02-28 | 5.0 MEDIUM | N/A |
netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |||||
CVE-2000-0610 | 1 Netwin | 2 Cwmail, Dmailweb | 2024-02-28 | 5.0 MEDIUM | N/A |
NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to bypass authentication and use the server for mail relay via a username that contains a carriage return. | |||||
CVE-2002-0273 | 1 Netwin | 1 Cwmail | 2024-02-28 | 4.6 MEDIUM | N/A |
Buffer overflow in CWMail.exe in NetWin before 2.8a allows remote authenticated users to execute arbitrary code via a long item parameter. | |||||
CVE-2000-0611 | 1 Netwin | 2 Cwmail, Dmailweb | 2024-02-28 | 5.0 MEDIUM | N/A |
The default configuration of NetWin dMailWeb and cwMail trusts all POP servers, which allows attackers to bypass normal authentication and cause a denial of service. | |||||
CVE-2000-0490 | 1 Netwin | 1 Dmail | 2024-02-28 | 10.0 HIGH | N/A |
Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN request. | |||||
CVE-2000-0608 | 1 Netwin | 2 Cwmail, Dmailweb | 2024-02-28 | 5.0 MEDIUM | N/A |
NetWin dMailWeb and cwMail 2.6i and earlier allows remote attackers to cause a denial of service via a long POP parameter (pophost). | |||||
CVE-2001-0697 | 1 Netwin | 1 Surgeftp | 2024-02-28 | 5.0 MEDIUM | N/A |
NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command. | |||||
CVE-2001-0698 | 1 Netwin | 1 Surgeftp | 2024-02-28 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and directories via the 'nlist ...' command. |