4.3
CVSSv2

CVE-2012-2575

Published: 17/09/2012 Updated: 18/09/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 6.0a4 allows remote malicious users to inject arbitrary web script or HTML via the SRC attribute of an IFRAME element in the body of an HTML e-mail message.

Vulnerable Product Search on Vulmon Subscribe to Product

netwin surgemail 6.0

Exploits

#!/usr/bin/python ''' Author: loneferret of Offensive Security Product: SurgeMail Version: 60a4 Vendor Site: wwwnetwinsitecom Software Download: netwinsitecom/downloadhtm Timeline: 29 May 2012: Vulnerability reported to CERT 30 May 2012: Response received from CERT with disclosure date set to 20 Jul 2012 23 Jul 2012: Update fr ...