vendor:
SurgeMail
by:
loneferret of Offensive Security
7,5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: SurgeMail
Affected Version From: 6.0a4
Affected Version To: 6.0a4
Patch Exists: YES
Related CWE: N/A
CPE: a:netwinsite:surge_mail:6.0a4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Server 2003 SP2, Windows XP Pro SP3 (x86), Windows 7 Pro SP1 (x86)
2012
SurgeMail 6.0a4 XSS Vulnerability
A Cross-Site Scripting (XSS) vulnerability was discovered in SurgeMail 6.0a4. The vulnerability exists due to insufficient sanitization of user-supplied input in the body of an email. An attacker can exploit this vulnerability by sending a malicious email with a specially crafted payload to a victim. The payload will be executed in the victim's browser when the email is viewed.
Mitigation:
Upgrade to the latest version of SurgeMail 6.0a4 or later.