Search

published date: December 31, 2004

CVE-2004-2547 : NetWin (1) SurgeMail before...

Description

NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message.

Product(s):

  • NetWin Surgemail 1.0c
  • NetWin Surgemail 1.0d
  • NetWin SurgeMail 1.1a
  • NetWin SurgeMail 1.1b
  • NetWin SurgeMail 1.1c
  • NetWin SurgeMail 1.1d

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2004-2547, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2004-2547 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?