NetWin SurgeMail Multiple Unspecified Input Validation Vulnerabilities
BID:13689
Info
NetWin SurgeMail Multiple Unspecified Input Validation Vulnerabilities
| Bugtraq ID: | 13689 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2005 12:00AM |
| Updated: | May 19 2005 12:00AM |
| Credit: | These issues were reported by the vendor. |
| Vulnerable: |
NetWin SurgeMail 3.0 c2 |
| Not Vulnerable: | |
Discussion
NetWin SurgeMail Multiple Unspecified Input Validation Vulnerabilities
Multiple unspecified vulnerabilities affect SurgeMail. Reportedly, these issues are due to a failure of the application to properly sanitize user-supplied input prior to employing it in critical locations including dynamic content. A successful attack may allow attackers to execute arbitrary HTML and script code in a user's browser.
SurgeMail 3.0c2 is reported to be affected by these issues. Other versions may be vulnerable as well.
Due to a lack of details, further information cannot be provided at the moment. This BID will be updated when more details are available.
Multiple unspecified vulnerabilities affect SurgeMail. Reportedly, these issues are due to a failure of the application to properly sanitize user-supplied input prior to employing it in critical locations including dynamic content. A successful attack may allow attackers to execute arbitrary HTML and script code in a user's browser.
SurgeMail 3.0c2 is reported to be affected by these issues. Other versions may be vulnerable as well.
Due to a lack of details, further information cannot be provided at the moment. This BID will be updated when more details are available.
Exploit / POC
NetWin SurgeMail Multiple Unspecified Input Validation Vulnerabilities
An exploit is likely not required.
An exploit is likely not required.
Solution / Fix
NetWin SurgeMail Multiple Unspecified Input Validation Vulnerabilities
Solution:
A CVS fix is available from the vendor.
Solution:
A CVS fix is available from the vendor.
References
NetWin SurgeMail Multiple Unspecified Input Validation Vulnerabilities
References:
References:
- SurgeMail Home Page (NetWin)