Filtered by vendor Netwin Subscriptions
Total 52 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2008-2859 1 Netwin 1 Surgemail 2025-04-09 N/A
Unspecified vulnerability in the IMAP service in NetWin SurgeMail before 3.9g2 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors related to an "imap command."
CVE-2008-1498 1 Netwin 1 Surgemail 2025-04-09 N/A
Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitrary code via a long first argument to the LIST command.
CVE-2006-5100 1 Netwin 1 Webnews 2025-04-09 N/A
PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the WN_BASEDIR parameter.
CVE-2004-2254 1 Netwin 1 Surgeldap 2025-04-03 N/A
SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified utoken parameter.
CVE-2001-0696 1 Netwin 1 Surgeftp 2025-04-03 N/A
NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con.
CVE-2001-1354 1 Netwin 2 Dmail, Surgeftp 2025-04-03 N/A
NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.
CVE-2001-0698 1 Netwin 1 Surgeftp 2025-04-03 N/A
Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and directories via the 'nlist ...' command.
CVE-2002-0310 1 Netwin 1 Webnews 2025-04-03 N/A
Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the username/password combinations (1) testweb/newstest, (2) alwn3845/imaptest, (3) alwi3845/wtest3452, or (4) testweb2/wtest4879.
CVE-2001-0697 1 Netwin 1 Surgeftp 2025-04-03 N/A
NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.
CVE-2000-0609 1 Netwin 2 Cwmail, Dmailweb 2025-04-03 N/A
NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to cause a denial of service via a long username parameter.
CVE-2000-0610 1 Netwin 2 Cwmail, Dmailweb 2025-04-03 N/A
NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to bypass authentication and use the server for mail relay via a username that contains a carriage return.
CVE-2000-0611 1 Netwin 2 Cwmail, Dmailweb 2025-04-03 N/A
The default configuration of NetWin dMailWeb and cwMail trusts all POP servers, which allows attackers to bypass normal authentication and cause a denial of service.
CVE-2000-0782 1 Netwin 1 Netauth 2025-04-03 N/A
netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-2000-0608 1 Netwin 2 Cwmail, Dmailweb 2025-04-03 N/A
NetWin dMailWeb and cwMail 2.6i and earlier allows remote attackers to cause a denial of service via a long POP parameter (pophost).
CVE-2004-2253 1 Netwin 1 Surgeldap 2025-04-03 N/A
Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in the page parameter of the show command.
CVE-2004-2547 1 Netwin 2 Surgemail, Webmail 2025-04-03 N/A
NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message.
CVE-2002-0290 1 Netwin 1 Webnews 2025-04-03 N/A
Buffer overflow in Netwin WebNews CGI program 1.1, Webnews.exe, allows remote attackers to execute arbitrary code via a long group argument.
CVE-2002-0273 1 Netwin 1 Cwmail 2025-04-03 N/A
Buffer overflow in CWMail.exe in NetWin before 2.8a allows remote authenticated users to execute arbitrary code via a long item parameter.
CVE-2004-2318 1 Netwin 1 Surgeftp 2025-04-03 N/A
The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a temporary denial of service (crash) via requests with two percent (%) signs in the CMD parameter.
CVE-2004-2537 1 Netwin 1 Surgemail 2025-04-03 N/A
Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."