Show filters
39 Total Results
Displaying 31-39 of 39
Sort by:
Attacker Value
Unknown
CVE-2006-2311
Disclosure Date: June 26, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to inject arbitrary web script or HTML via the filename in a request to a (1) .cfm or (2) .cfml file, which reflects the result in the default error page.
0
Attacker Value
Unknown
CVE-2006-2310
Disclosure Date: June 26, 2006 (last updated October 04, 2023)
BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to cause a denial of service (hang) via a request for a .cfm file whose name contains an MS-DOS device name such as (1) con, (2) aux, (3) com1, and (4) com2.
0
Attacker Value
Unknown
CVE-2005-4298
Disclosure Date: December 16, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in atl.cgi in AtlantForum 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) sch_allsubct, (2) before, and (3) ct parameters.
0
Attacker Value
Unknown
CVE-2005-4299
Disclosure Date: December 16, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in atl.cgi in Atlant Pro 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) before and (2) ct parameters.
0
Attacker Value
Unknown
CVE-2005-4275
Disclosure Date: December 16, 2005 (last updated February 22, 2025)
Scientific Atlanta DPX2100 Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD), as demonstrated using hping2. NOTE: the provenance of this issue is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2004-0650
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
UploadServlet in Cisco Collaboration Server (CCS) running ServletExec before 3.0E allows remote attackers to upload and execute arbitrary files via a direct call to the UploadServlet URL.
0
Attacker Value
Unknown
CVE-2002-0893
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Directory traversal vulnerability in NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to read arbitrary files via a URL-encoded request to com.newatlanta.servletexec.JSP10Servlet containing "..%5c" (modified dot-dot) sequences.
0
Attacker Value
Unknown
CVE-2002-0894
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to cause a denial of service (crash) via (1) a request for a long .jsp file, or (2) a long URL sent directly to com.newatlanta.servletexec.JSP10Servlet.
0
Attacker Value
Unknown
CVE-2002-0892
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
The default configuration of NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to determine the path of the web root via a direct request to com.newatlanta.servletexec.JSP10Servlet without a filename, which leaks the pathname in an error message.
0