Page 48 of 289 results (0.013 seconds)

CVSS: 5.0EPSS: 94%CPEs: 5EXPL: 6

The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex. • https://www.exploit-db.com/exploits/20692 https://www.exploit-db.com/exploits/20693 https://www.exploit-db.com/exploits/20694 https://www.exploit-db.com/exploits/20695 http://www.apacheweek.com/features/security-13 http://www.debian.org/security/2001/dsa-067 http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-077.php3 http://www.linuxsecurity.com/advisories/other_advisory-1452.html http://www.securityfocus.com/archive/1/168497 http://www.securityfocus.com/archive • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 7.2EPSS: 0%CPEs: 7EXPL: 2

Format string vulnerability in splitvt before 1.6.5 allows local users to execute arbitrary commands via the -rcfile command line argument. • https://www.exploit-db.com/exploits/20556 http://marc.info/?l=bugtraq&m=97958269320974&w=2 http://www.debian.org/security/2001/dsa-014 http://www.securityfocus.com/bid/2210 https://exchange.xforce.ibmcloud.com/vulnerabilities/5948 •

CVSS: 1.2EPSS: 0%CPEs: 14EXPL: 0

privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack. • http://marc.info/?l=bugtraq&m=97916374410647&w=2 http://www.debian.org/security/2001/dsa-016 http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-001.php3 http://www.securityfocus.com/bid/2189 https://exchange.xforce.ibmcloud.com/vulnerabilities/5915 •

CVSS: 7.2EPSS: 0%CPEs: 7EXPL: 2

Multiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands. • https://www.exploit-db.com/exploits/260 http://marc.info/?l=bugtraq&m=97958269320974&w=2 http://www.debian.org/security/2001/dsa-014 http://www.securityfocus.com/bid/2210 •

CVSS: 3.3EPSS: 0%CPEs: 3EXPL: 0

htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack. • http://marc.info/?l=bugtraq&m=97916374410647&w=2 http://www.debian.org/security/2001/dsa-021 http://www.securityfocus.com/bid/2182 https://exchange.xforce.ibmcloud.com/vulnerabilities/5926 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •