Page 24 of 120 results (0.006 seconds)

CVSS: 6.4EPSS: 3%CPEs: 7EXPL: 1

The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack. • https://www.exploit-db.com/exploits/20568 https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0174 •

CVSS: 7.5EPSS: 0%CPEs: 11EXPL: 1

List of arbitrary files on Web host via nph-test-cgi script. • https://www.exploit-db.com/exploits/19536 https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0045 •

CVSS: 10.0EPSS: 0%CPEs: 14EXPL: 0

Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0043 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 3.7EPSS: 0%CPEs: 1EXPL: 0

Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet. • http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/134 •

CVSS: 7.5EPSS: 3%CPEs: 2EXPL: 0

The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0142 •