CVE-2008-3776 – Fujitsu Web-Based Admin View 2.1.2 - Directory Traversal
https://notcve.org/view.php?id=CVE-2008-3776
Directory traversal vulnerability in Fujitsu Web-Based Admin View 2.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. Vulnerabilidad de Salto de Directorio en Fujitsu Web-Based Admin View 2.1.2, permite a atacantes leer archivos arbitrariamente mediante un .. (punto punto) en la URI. • https://www.exploit-db.com/exploits/32286 http://seclists.org/fulldisclosure/2008/Aug/0411.html http://www.securityfocus.com/bid/30780 http://www.securitytracker.com/id?1020726 https://exchange.xforce.ibmcloud.com/vulnerabilities/44602 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2008-3126
https://notcve.org/view.php?id=CVE-2008-3126
Multiple stack-based buffer overflows in the ServerView web interface (SnmpGetMibValues.exe) in Fujitsu Siemens Computers ServerView 04.60.07 and earlier allow remote authenticated users to execute arbitrary code via a crafted URL. Múltiples desbordamientos de búfer basados en pila del interfaz web ServerView (SnmpGetMibValues.exe) en Fujitsu Siemens Computers ServerView 04.60.07 y anteriores permiten a usuarios remotos autenticados ejecutar código arbitrariamente a través de una URL manipulada. • http://lists.grok.org.uk/pipermail/full-disclosure/2008-July/063043.html http://secunia.com/advisories/30913 http://www.securityfocus.com/bid/30081 http://www.vupen.com/english/advisories/2008/2007/references https://exchange.xforce.ibmcloud.com/vulnerabilities/43611 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2008-2674
https://notcve.org/view.php?id=CVE-2008-2674
Unspecified vulnerability in the Interstage Management Console, as used in Fujitsu Interstage Application Server 6.0 through 9.0.0A, Apworks Modelers-J 6.0 through 7.0, and Studio 8.0.1 and 9.0.0, allows remote attackers to read or delete arbitrary files via unspecified vectors. Vulnerabilidad no especificada en la Interstage Management Console, tal como se utiliza en Fujitsu Interstage Application Server 6.0 a 9.0.0A, Apworks Modelers-J 6.0 a 7.0, y Studio 8.0.1 y 9.0.0, permite a atacantes remotos leer o borrar archivos de su elección a través de vectores no especificados. • http://secunia.com/advisories/30589 http://www.fujitsu.com/global/support/software/security/products-f/interstage-200805e.html http://www.securityfocus.com/bid/29624 http://www.securitytracker.com/id?1020235 http://www.vupen.com/english/advisories/2008/1771/references https://exchange.xforce.ibmcloud.com/vulnerabilities/42949 •
CVE-2008-1207
https://notcve.org/view.php?id=CVE-2008-1207
Multiple unspecified vulnerabilities in Fujitsu Interstage Smart Repository, as used in multiple Fujitsu Interstage products, allow remote attackers to cause a denial of service (daemon crash) via (1) an invalid request or (2) a large amount of data sent to the registered attribute value. Múltiples vulnerabilidades sin especificar en Fujitsu Interstage Smart Repository, como se utiliza en múltiples productos Fujitsu Interstage, permite a atacantes remotos provocar una denegación de servicio (caída del demonio) a través de (1) una petición no válida o (2) una cantidad grande de datos enviados al valor de atributo registrado. • http://secunia.com/advisories/29250 http://www.fujitsu.com/global/support/software/security/products-f/interstage-sr-200801e.html http://www.fujitsu.com/global/support/software/security/products-f/interstage-sr-200802e.html http://www.securityfocus.com/bid/28114 http://www.vupen.com/english/advisories/2008/0786 https://exchange.xforce.ibmcloud.com/vulnerabilities/41039 https://exchange.xforce.ibmcloud.com/vulnerabilities/41041 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2008-1040
https://notcve.org/view.php?id=CVE-2008-1040
Buffer overflow in the Single Sign-On function in Fujitsu Interstage Application Server 8.0.0 through 8.0.3 and 9.0.0, Interstage Studio 8.0.1 and 9.0.0, and Interstage Apworks 8.0.0 allows remote attackers to execute arbitrary code via a long URI. Desbordamiento de búfer en la función Single Sign-On de Fujitsu Interstage Application Server 8.0.0 hasta 8.0.3 y 9.0.0, Interstage Studio 8.0.1 y 9.0.0, y Interstage Apworks 8.0.0 permite a atacantes remotos ejecutar código de su elección a través de una URI larga. • http://secunia.com/advisories/29088 http://www.fujitsu.com/global/support/software/security/products-f/interstage-200804e.html http://www.securityfocus.com/bid/27966 http://www.vupen.com/english/advisories/2008/0662 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •