CVE-2010-3201
07.01.2011, 23:00
Cross-site scripting (XSS) vulnerability in NetWin Surgemail before 4.3g allows remote attackers to inject arbitrary web script or HTML via the username_ex parameter to the surgeweb program.
Vendor | Product | Version |
---|---|---|
netwin | surgemail | 𝑥 ≤ 4.2d4-4 |
netwin | surgemail | 1.0c:c |
netwin | surgemail | 1.0d:d |
netwin | surgemail | 1.1a:a |
netwin | surgemail | 1.1b:b |
netwin | surgemail | 1.1c:c |
netwin | surgemail | 1.1d:d |
netwin | surgemail | 1.2a:a |
netwin | surgemail | 1.2b:b |
netwin | surgemail | 1.2c:c |
netwin | surgemail | 1.3a:a |
netwin | surgemail | 1.3a_rc1:a_rc1 |
netwin | surgemail | 1.3b:b |
netwin | surgemail | 1.3c:c |
netwin | surgemail | 1.3d:d |
netwin | surgemail | 1.3e:e |
netwin | surgemail | 1.3f:f |
netwin | surgemail | 1.3g:g |
netwin | surgemail | 1.3h:h |
netwin | surgemail | 1.3i:i |
netwin | surgemail | 1.3j:j |
netwin | surgemail | 1.3k:k |
netwin | surgemail | 1.3l:l |
netwin | surgemail | 1.4a:a |
netwin | surgemail | 1.4b:b |
netwin | surgemail | 1.4c:c |
netwin | surgemail | 1.5a:a |
netwin | surgemail | 1.5b:b |
netwin | surgemail | 1.5c:c |
netwin | surgemail | 1.5d:d |
netwin | surgemail | 1.5d2:d2 |
netwin | surgemail | 1.5f:f |
netwin | surgemail | 1.6a:a |
netwin | surgemail | 1.6b:b |
netwin | surgemail | 1.6d:d |
netwin | surgemail | 1.6e:e |
netwin | surgemail | 1.6e2:e2 |
netwin | surgemail | 1.7a:a |
netwin | surgemail | 1.7b3:b3 |
netwin | surgemail | 1.8a:a |
netwin | surgemail | 1.8b3:b3 |
netwin | surgemail | 1.8d:d |
netwin | surgemail | 1.8e:e |
netwin | surgemail | 1.8f:f |
netwin | surgemail | 1.8g3:g3 |
netwin | surgemail | 1.9 |
netwin | surgemail | 1.9b2:b2 |
netwin | surgemail | 2.0a2:a2 |
netwin | surgemail | 2.0c:c |
netwin | surgemail | 2.0e:e |
netwin | surgemail | 2.0g2:g2 |
netwin | surgemail | 2.1a:a |
netwin | surgemail | 2.1c7:c7 |
netwin | surgemail | 2.2a6:a6 |
netwin | surgemail | 2.2c9:c9 |
netwin | surgemail | 2.2c10:c10 |
netwin | surgemail | 2.2g2:g2 |
netwin | surgemail | 2.2g3:g3 |
netwin | surgemail | 3.0a:a |
netwin | surgemail | 3.0c2:c2 |
netwin | surgemail | 3.1s:s |
netwin | surgemail | 3.2e:e |
netwin | surgemail | 3.5a:a |
netwin | surgemail | 3.5b3:b3 |
netwin | surgemail | 3.6d:d |
netwin | surgemail | 3.6f3:f3 |
netwin | surgemail | 3.6f5:f5 |
netwin | surgemail | 3.6f7:f7 |
netwin | surgemail | 3.7b:b |
netwin | surgemail | 3.7b3:b3 |
netwin | surgemail | 3.7b5:b5 |
netwin | surgemail | 3.7b6:b6 |
netwin | surgemail | 3.7b7:b7 |
netwin | surgemail | 3.7b8:b8 |
netwin | surgemail | 3.8a:a |
netwin | surgemail | 3.8b:b |
netwin | surgemail | 3.8d:d |
netwin | surgemail | 3.8f:f |
netwin | surgemail | 3.8f2:f2 |
netwin | surgemail | 3.8f3:f3 |
netwin | surgemail | 3.8i:i |
netwin | surgemail | 3.8i2:i2 |
netwin | surgemail | 3.8i3:i3 |
netwin | surgemail | 3.8k:k |
netwin | surgemail | 3.8k2:k2 |
netwin | surgemail | 3.8k3:k3 |
netwin | surgemail | 3.8k4:k4 |
netwin | surgemail | 3.8m:m |
netwin | surgemail | 3.8o:o |
netwin | surgemail | 3.8q:q |
netwin | surgemail | 3.8s:s |
netwin | surgemail | 3.8u:u |
netwin | surgemail | 3.9a:a |
netwin | surgemail | 3.9c:c |
netwin | surgemail | 3.9e:e |
netwin | surgemail | 3.9g:g |
netwin | surgemail | 3.9g2:g2 |
netwin | surgemail | 4.0a:a |
netwin | surgemail | 4.0k:k |
netwin | surgemail | 4.0u3:u3 |
netwin | surgemail | 4.0u4:u4 |
netwin | surgemail | 4.0v-8:v |
netwin | surgemail | 4.2a2-2:a2 |
netwin | surgemail | 4.2a2-3:a2 |
netwin | surgemail | 4.2a3-3:a3 |
netwin | surgemail | 4.2d-1:d |
netwin | surgemail | 4.2d2-2:d2 |
netwin | surgemail | 4.2d3-3:d3 |
𝑥
= Vulnerable software versions
References