CVE-2008-1040
https://notcve.org/view.php?id=CVE-2008-1040
Buffer overflow in the Single Sign-On function in Fujitsu Interstage Application Server 8.0.0 through 8.0.3 and 9.0.0, Interstage Studio 8.0.1 and 9.0.0, and Interstage Apworks 8.0.0 allows remote attackers to execute arbitrary code via a long URI. Desbordamiento de búfer en la función Single Sign-On de Fujitsu Interstage Application Server 8.0.0 hasta 8.0.3 y 9.0.0, Interstage Studio 8.0.1 y 9.0.0, y Interstage Apworks 8.0.0 permite a atacantes remotos ejecutar código de su elección a través de una URI larga. • http://secunia.com/advisories/29088 http://www.fujitsu.com/global/support/software/security/products-f/interstage-200804e.html http://www.securityfocus.com/bid/27966 http://www.vupen.com/english/advisories/2008/0662 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2007-5366
https://notcve.org/view.php?id=CVE-2007-5366
The Tomcat 4.1-based Servlet Service in Fujitsu Interstage Application Server 7.0 through 9.0.0 and Interstage Apworks/Studio 7.0 through 9.0.0 allows remote attackers to obtain sensitive information (web root path) via unspecified vectors that trigger an error message, probably related to enabling the useCanonCaches Java Virtual Machine (JVM) option. El Tomcat 4.1-based Servlet Service en Fujitsu Interstage Application Server 7.0 hasta la 9.0.0 y Interstage Apworks/Studio 7.0 hasta la 9.0.0 permite a atacantes remotos obtener información sensible (ruta del raíz web) a través de vectores no especificados que disparan un mensaje de error, probablemente relacionado con el permiso de la opción useCanonCaches Java Virtual Machine (JVM). • http://osvdb.org/41318 http://secunia.com/advisories/27136 http://www.fujitsu.com/global/support/software/security/products-f/interstage-200705e.html http://www.securityfocus.com/bid/25988 https://exchange.xforce.ibmcloud.com/vulnerabilities/37026 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2007-1504
https://notcve.org/view.php?id=CVE-2007-1504
Cross-site scripting (XSS) vulnerability in the Servlet Service in Fujitsu Interstage Application Server (IJServer) 8.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving web.xml and HTTP 404 and 500 status codes. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el Servicio Servlet de Fujitsu interstage Application Server (IJServer) 8.0.2 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de vectores no especificados, posiblemente relacionados con web.xml y códigos de estado HTTP 404 y 500. • http://jvn.jp/jp/JVN%2383832818/index.html http://osvdb.org/34276 http://secunia.com/advisories/24508 http://software.fujitsu.com/jp/security/vulnerabilities/jvn-83832818.html http://www.fujitsu.com/global/support/software/security/products-f/interstage-200701e.html http://www.securityfocus.com/bid/23020 http://www.vupen.com/english/advisories/2007/0996 https://exchange.xforce.ibmcloud.com/vulnerabilities/33099 •