Show filters
58 Total Results
Displaying 51-58 of 58
Sort by:
Attacker Value
Unknown

CVE-2005-4834

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
IBM WebSphere Application Server (WAS) 5.0.2.5 through 5.1.1.3 allows remote attackers to obtain JSP source code and other sensitive information, related to incorrect request processing by the web container.
0
Attacker Value
Unknown

CVE-2005-3467

Disclosure Date: November 02, 2005 (last updated February 22, 2025)
Serv-U FTP Server before 6.1.0.4 allows attackers to cause a denial of service (crash) via (1) malformed packets and possibly other unspecified issues with unknown impact and attack vectors including (2) use of "~" in a pathname, and (3) memory consumption of the daemon. NOTE: it is not clear whether items (2) and above are vulnerabilities.
0
Attacker Value
Unknown

CVE-2005-2091

Disclosure Date: July 05, 2005 (last updated February 22, 2025)
IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebSphere to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
0
Attacker Value
Unknown

CVE-2005-0425

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL that causes the page to be processed by the file serving servlet instead of the JSP engine.
0
Attacker Value
Unknown

CVE-2005-1112

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine.
0
Attacker Value
Unknown

CVE-2004-1675

Disclosure Date: September 11, 2004 (last updated February 22, 2025)
Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as (1) COM1, (2) LPT1, (3) PRN, or (4) AUX.
0
Attacker Value
Unknown

CVE-2001-0389

Disclosure Date: July 02, 2001 (last updated February 22, 2025)
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.
0
Attacker Value
Unknown

CVE-2001-0390

Disclosure Date: July 02, 2001 (last updated February 22, 2025)
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.
0