Show filters
39 Total Results
Displaying 31-39 of 39
Sort by:
Attacker Value
Unknown

CVE-2006-2311

Disclosure Date: June 26, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to inject arbitrary web script or HTML via the filename in a request to a (1) .cfm or (2) .cfml file, which reflects the result in the default error page.
0
Attacker Value
Unknown

CVE-2006-2310

Disclosure Date: June 26, 2006 (last updated October 04, 2023)
BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to cause a denial of service (hang) via a request for a .cfm file whose name contains an MS-DOS device name such as (1) con, (2) aux, (3) com1, and (4) com2.
0
Attacker Value
Unknown

CVE-2005-4298

Disclosure Date: December 16, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in atl.cgi in AtlantForum 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) sch_allsubct, (2) before, and (3) ct parameters.
0
Attacker Value
Unknown

CVE-2005-4299

Disclosure Date: December 16, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in atl.cgi in Atlant Pro 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) before and (2) ct parameters.
0
Attacker Value
Unknown

CVE-2005-4275

Disclosure Date: December 16, 2005 (last updated February 22, 2025)
Scientific Atlanta DPX2100 Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD), as demonstrated using hping2. NOTE: the provenance of this issue is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2004-0650

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
UploadServlet in Cisco Collaboration Server (CCS) running ServletExec before 3.0E allows remote attackers to upload and execute arbitrary files via a direct call to the UploadServlet URL.
0
Attacker Value
Unknown

CVE-2002-0893

Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Directory traversal vulnerability in NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to read arbitrary files via a URL-encoded request to com.newatlanta.servletexec.JSP10Servlet containing "..%5c" (modified dot-dot) sequences.
0
Attacker Value
Unknown

CVE-2002-0894

Disclosure Date: October 04, 2002 (last updated February 22, 2025)
NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to cause a denial of service (crash) via (1) a request for a long .jsp file, or (2) a long URL sent directly to com.newatlanta.servletexec.JSP10Servlet.
0
Attacker Value
Unknown

CVE-2002-0892

Disclosure Date: October 04, 2002 (last updated February 22, 2025)
The default configuration of NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to determine the path of the web root via a direct request to com.newatlanta.servletexec.JSP10Servlet without a filename, which leaks the pathname in an error message.
0