PoC Index

CVE-2004-2547

LOW 2.6EPSS 3.1%

NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message.

CVSS v2.0
2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
EPSS
3.09% chance of exploitation in the next 30 days, 87th percentile
Published
2005-11-21
Updated
2024-08-08

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related