← Vulnerability feed

Vulnerability record · CVE-2004-2547 · published 31 December 2004

CVE-2004-2547: Netwin surgemail vulnerability

Netwin · Surgemail

NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message.

2.6 CVSS 2.0 Low EPSS 3.1% · top 12.7%
2.6CVSS 2.0 base score
3.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
14References, 8 tagged exploit
16 Jun 2026Last modified by NVD

Description

NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message.

AV:N/AC:H/Au:N/C:P/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-2547 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-4372Netwin surgemail vulnerabilityUnspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors. NOTE: this information is base…EPSS 1.2%10.0CVE-2004-2537Netwin surgemail vulnerabilityUnspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."EPSS 1.7%9.0CVE-2008-1497Netwin surgemail memory buffer overflow vulnerabilityStack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrary code vi…EPSS 6.3%9.0CVE-2008-1498Netwin surgemail memory buffer overflow vulnerabilityStack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitrary code v…EPSS 7.6%7.5CVE-2008-1055Netwin surgemail vulnerabilityFormat string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers t…EPSS 7.9%7.5CVE-2007-2655Netwin surgemail vulnerabilityUnspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a format string v…EPSS 3.9%6.4CVE-2008-1054Netwin surgemail memory buffer overflow vulnerabilityStack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlier, and …EPSS 7.4%6.0CVE-2007-4377Netwin surgemail vulnerabilityStack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argument to t…EPSS 5.0%

Source: NIST National Vulnerability Database (record CVE-2004-2547), CISA KEV, FIRST EPSS (scores of 2026-09-30). This page is refreshed as NVD updates the record.