Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2001-1106

Disclosure Date: July 25, 2001 (last updated February 22, 2025)
The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the sambar program to call the decryption procedure.
0
Attacker Value
Unknown

CVE-2001-1010

Disclosure Date: July 22, 2001 (last updated February 22, 2025)
Directory traversal vulnerability in pagecount CGI script in Sambar Server before 5.0 beta 5 allows remote attackers to overwrite arbitrary files via a .. (dot dot) attack on the page parameter.
0
Attacker Value
Unknown

CVE-2000-0835

Disclosure Date: November 14, 2000 (last updated February 22, 2025)
search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter.
0