Show filters
486 Total Results
Displaying 271-280 of 486
Sort by:
Attacker Value
Unknown
CVE-2008-0405
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) files and (2) directories via a .. (dot dot) in an account name, when requesting the / URI; and (3) append arbitrary data to a file via a .. (dot dot) in an account name, when requesting a URI composed of a "/?%0a" sequence followed by the data.
0
Attacker Value
Unknown
CVE-2008-0406
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a denial of service (daemon crash) via a long account name.
0
Attacker Value
Unknown
CVE-2008-0408
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
HTTP File Server (HFS) before 2.2c allows remote attackers to append arbitrary text to the log file by using the base64 representation of this text during HTTP Basic Authentication.
0
Attacker Value
Unknown
CVE-2008-0409
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in HTTP File Server (HFS) before 2.2c allows remote attackers to inject arbitrary web script or HTML via the userinfo subcomponent of a URL.
0
Attacker Value
Unknown
CVE-2008-0407
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more difficult for an administrator to determine who made a remote request.
0
Attacker Value
Unknown
CVE-2008-0410
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
HTTP File Server (HFS) before 2.2c allows remote attackers to obtain configuration and usage details by using an id element such as <id>%version%</id> in HTTP Basic Authentication instead of a username and password, as demonstrated by placing this id element in the userinfo subcomponent of a URL.
0
Attacker Value
Unknown
CVE-2008-0455
Disclosure Date: January 25, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
0
Attacker Value
Unknown
CVE-2008-0456
Disclosure Date: January 25, 2008 (last updated October 04, 2023)
CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
0
Attacker Value
Unknown
CVE-2008-0338
Disclosure Date: January 17, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary files and list arbitrary directories via a (1) .%2e (partially encoded dot dot) or (2) %2e%2e (encoded dot dot) in the URI.
0
Attacker Value
Unknown
CVE-2008-0337
Disclosure Date: January 17, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to execute arbitrary code via a long URI.
0