Security Advisory

CVE-2004-2547

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2005-11-21 11:00:00
Last updated 2024-08-08 01:29:14
Assigner mitre
State PUBLISHED

Description

NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message.