4.3
CVSSv2

CVE-2010-3201

Published: 07/01/2011 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in NetWin Surgemail prior to 4.3g allows remote malicious users to inject arbitrary web script or HTML via the username_ex parameter to the surgeweb program.

Vulnerable Product Search on Vulmon Subscribe to Product

netwin surgemail 1.3a

netwin surgemail 1.3a_rc1

netwin surgemail 1.0d

netwin surgemail 1.1a

netwin surgemail 1.5a

netwin surgemail 1.6b

netwin surgemail 1.3h

netwin surgemail 1.4c

netwin surgemail 1.9

netwin surgemail 1.9b2

netwin surgemail 1.7b3

netwin surgemail 1.8a

netwin surgemail 2.1c7

netwin surgemail 3.0c2

netwin surgemail 2.2g2

netwin surgemail 3.0a

netwin surgemail 3.9a

netwin surgemail 3.8u

netwin surgemail 3.1s

netwin surgemail 3.8a

netwin surgemail 1.3f

netwin surgemail 1.3g

netwin surgemail 1.2b

netwin surgemail 1.2c

netwin surgemail 1.1d

netwin surgemail 1.6a

netwin surgemail 1.5f

netwin surgemail 1.4b

netwin surgemail 1.4a

netwin surgemail 2.0a2

netwin surgemail 2.0c

netwin surgemail 2.0e

netwin surgemail 1.8b3

netwin surgemail 1.8d

netwin surgemail 2.2g3

netwin surgemail 3.8i

netwin surgemail 3.9c

netwin surgemail 3.9e

netwin surgemail 3.7b7

netwin surgemail 3.7b6

netwin surgemail 3.8k3

netwin surgemail 3.8k2

netwin surgemail 3.5a

netwin surgemail 3.6f7

netwin surgemail 4.0k

netwin surgemail 4.0u3

netwin surgemail 4.2d2-2

netwin surgemail

netwin surgemail 1.3b

netwin surgemail 1.3c

netwin surgemail 1.1b

netwin surgemail 1.1c

netwin surgemail 1.5c

netwin surgemail 1.5b

netwin surgemail 1.3j

netwin surgemail 1.3i

netwin surgemail 1.8f

netwin surgemail 1.8g3

netwin surgemail 1.6e2

netwin surgemail 1.7a

netwin surgemail 2.0g2

netwin surgemail 2.2a6

netwin surgemail 2.2c10

netwin surgemail 2.2c9

netwin surgemail 3.8q

netwin surgemail 3.8s

netwin surgemail 3.8d

netwin surgemail 3.8b

netwin surgemail 3.8m

netwin surgemail 3.8k

netwin surgemail 3.5b3

netwin surgemail 3.6f5

netwin surgemail beta_3.9a

netwin surgemail 4.2a2-2

netwin surgemail 4.2a2-3

netwin surgemail 3.7b8

netwin surgemail 3.6d

netwin surgemail 3.2e

netwin surgemail 3.9g2

netwin surgemail 4.0a

netwin surgemail 4.2d-1

netwin surgemail 4.2a3-3

netwin surgemail 3.8k4

netwin surgemail 1.0c

netwin surgemail 1.3d

netwin surgemail 1.3e

netwin surgemail 1.2a

netwin surgemail 1.5d

netwin surgemail 1.5d2

netwin surgemail 1.3k

netwin surgemail 1.3l

netwin surgemail 1.8e

netwin surgemail 1.6d

netwin surgemail 1.6e

netwin surgemail 3.8i2

netwin surgemail 2.1a

netwin surgemail 3.8f3

netwin surgemail 3.8i3

netwin surgemail 3.9g

netwin surgemail 3.8o

netwin surgemail 3.7b5

netwin surgemail 3.7b3

netwin surgemail 3.8f2

netwin surgemail 3.8f

netwin surgemail 3.7b

netwin surgemail 3.6f3

netwin surgemail 4.0u4

netwin surgemail 4.0v-8

netwin surgemail 4.2d3-3

Exploits

source: wwwsecurityfocuscom/bid/43679/info SurgeMail is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This can allow the attacker t ...
NetWin Surgemail version 43e suffers from a cross site scripting vulnerability ...