Sambar
Sambar Server: vulnerabilidades y CVE
Sambar Server tiene 19 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE19
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2006-6624 | Media (4) | 6.2% | — | 18 dic 2006 | The FTP Server in Sambar Server 6.4 allows remote authenticated users to cause a denial of service (application crash) via a long series of "./" sequences in the SIZE command. |
| CVE-2005-3506 | Media (4.3) | 1.2% | — | 5 nov 2005 | Cross-site scripting (XSS) vulnerability in proxy.asp in Sambar Server 6.3 BETA 2 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the (1) Remote Proxy Server or (2) Proxy… |
| CVE-2004-2565 | Media (5) | 9.4% | — | 31 dic 2004 | Multiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, when the administrative IP address restrictions have been modified from the default, allow… |
| CVE-2004-2564 | Media (4.3) | 4.7% | — | 31 dic 2004 | Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter… |
| CVE-2004-2086 | Media (5) | 75% | — | 6 feb 2004 | Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request… |
| CVE-2003-1284 | Media (5) | 1.4% | — | 31 dic 2003 | Sambar Server before 6.0 beta 6 allows remote attackers to obtain sensitive information via direct requests to the default scripts (1) environ.pl and (2) testcgi.exe. |
| CVE-2003-1285 | Media (4.3) | 1.9% | — | 31 dic 2003 | Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server before 6.0 beta 6 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) isapi/testisa.dll, (2) testcgi.exe, (3)… |
| CVE-2003-1286 | Alta (7.5) | 3.4% | — | 31 dic 2003 | HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attackers to send proxy HTTP requests to the Sambar Server's administrative interface and external web… |
| CVE-2003-1287 | Media (4.6) | 0.42% | — | 31 dic 2003 | Sambar Server before 6.0 beta 3 allows attackers with physical access to execute arbitrary code via a request with an MS-DOS device name such as com1.pl, con.pl, or aux.pl, which causes Perl to read the code from the… |
| CVE-2002-0737 | Media (6.4) | 8.9% | — | 12 ago 2002 | Sambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scripts, or cause a denial of service (resource exhaustion) via DOS devices, using a URL that ends with a space and a null… |
| CVE-2002-0128 | Alta (7.5) | 10% | — | 25 mar 2002 | cgitest.exe in Sambar Server 5.1 before Beta 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long argument. |
| CVE-2001-1292 | Alta (7.5) | 2.9% | — | 13 ago 2001 | Sambar Telnet Proxy/Server allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long password. |
| CVE-2001-1106 | Alta (7.5) | 2.4% | — | 25 jul 2001 | The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the… |
| CVE-2001-1010 | Media (5) | 7.0% | — | 22 jul 2001 | Directory traversal vulnerability in pagecount CGI script in Sambar Server before 5.0 beta 5 allows remote attackers to overwrite arbitrary files via a .. (dot dot) attack on the page parameter. |
| CVE-2000-0835 | Media (5) | 2.8% | — | 14 nov 2000 | search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter. |
| CVE-2000-0509 | Alta (10) | 4.3% | — | 1 jun 2000 | Buffer overflows in the finger and whois demonstration scripts in Sambar Server 4.3 allow remote attackers to execute arbitrary commands via a long hostname. |
| CVE-2000-0213 | Media (5) | 10.0% | — | 23 feb 2000 | The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacharacters. |
| CVE-1999-1523 | Alta (7.5) | 2.3% | — | 4 oct 1999 | Buffer overflow in Sambar Web Server 4.2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request. |
| CVE-1999-1178 | Media (5) | 1.5% | — | 10 jun 1998 | Sambar Server 4.1 beta allows remote attackers to obtain sensitive information about the server via an HTTP request for the dumpenv.pl script. |