
CVE-2009-0271
https://notcve.org/view.php?id=CVE-2009-0271
26 Jan 2009 — Directory traversal vulnerability in the TFTP service in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors. Una vulnerabilidad de salto de directorio en el servicio TFTP de Fujitsu SystemcastWizard Lite 2.0a, 2.0, 1.9, y anteriores permite a atacantes remotos leer ficheros arbitrarios a través de secuencias de salto de directorio en vectores no especificados. • http://osvdb.org/51487 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2009-0264
https://notcve.org/view.php?id=CVE-2009-0264
26 Jan 2009 — Buffer overflow in the Registry Setting Tool in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier has unknown impact and attack vectors. Desbordamiento de búfer en Registry Setting Tool en Fujitsu SystemcastWizard Lite v2.0A, v2.0, v1.9, y anteriores tienen, tanto vectores de ataque como impactos no determinados. • http://www.fujitsu.com/global/services/computing/server/primequest/products/os/windows-server-2008-2.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2008-5842
https://notcve.org/view.php?id=CVE-2008-5842
05 Jan 2009 — Multiple cross-site scripting (XSS) vulnerabilities in Fujitsu-Siemens WebTransactions 7.0, 7.1, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via vectors associated with (1) a demo application shipped with WebTransactions and possibly (2) an unspecified "dynamic application." Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Fujitsu-Siemens WebTransactions v7.0, v7.1, y posiblemente otras versiones permiten a atacantes remotos inyec... • http://bs2www.fujitsu-siemens.de/update/securitypatch.htm#english • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2008-5810
https://notcve.org/view.php?id=CVE-2008-5810
02 Jan 2009 — WBPublish (aka WBPublish.exe) in Fujitsu-Siemens WebTransactions 7.0, 7.1, and possibly other versions allows remote attackers to execute arbitrary commands via shell metacharacters in input that is sent through HTTP and improperly used during temporary session data cleanup, possibly related to (1) directory names, (2) template names, and (3) session IDs. WBpublish (también conocido como WBpublish.exe) en Fujitsu-Siemens WebTransactions v7.0 y v7.1, y posiblemente otras versiones, permite a atacantes remoto... • http://bs2www.fujitsu-siemens.de/update/securitypatch.htm#english • CWE-20: Improper Input Validation •

CVE-2008-3776 – Fujitsu Web-Based Admin View 2.1.2 - Directory Traversal
https://notcve.org/view.php?id=CVE-2008-3776
25 Aug 2008 — Directory traversal vulnerability in Fujitsu Web-Based Admin View 2.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. Vulnerabilidad de Salto de Directorio en Fujitsu Web-Based Admin View 2.1.2, permite a atacantes leer archivos arbitrariamente mediante un .. (punto punto) en la URI. • https://www.exploit-db.com/exploits/32286 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2008-3126
https://notcve.org/view.php?id=CVE-2008-3126
10 Jul 2008 — Multiple stack-based buffer overflows in the ServerView web interface (SnmpGetMibValues.exe) in Fujitsu Siemens Computers ServerView 04.60.07 and earlier allow remote authenticated users to execute arbitrary code via a crafted URL. Múltiples desbordamientos de búfer basados en pila del interfaz web ServerView (SnmpGetMibValues.exe) en Fujitsu Siemens Computers ServerView 04.60.07 y anteriores permiten a usuarios remotos autenticados ejecutar código arbitrariamente a través de una URL manipulada. • http://lists.grok.org.uk/pipermail/full-disclosure/2008-July/063043.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2008-2674
https://notcve.org/view.php?id=CVE-2008-2674
12 Jun 2008 — Unspecified vulnerability in the Interstage Management Console, as used in Fujitsu Interstage Application Server 6.0 through 9.0.0A, Apworks Modelers-J 6.0 through 7.0, and Studio 8.0.1 and 9.0.0, allows remote attackers to read or delete arbitrary files via unspecified vectors. Vulnerabilidad no especificada en la Interstage Management Console, tal como se utiliza en Fujitsu Interstage Application Server 6.0 a 9.0.0A, Apworks Modelers-J 6.0 a 7.0, y Studio 8.0.1 y 9.0.0, permite a atacantes remotos leer o ... • http://secunia.com/advisories/30589 •

CVE-2008-1207
https://notcve.org/view.php?id=CVE-2008-1207
08 Mar 2008 — Multiple unspecified vulnerabilities in Fujitsu Interstage Smart Repository, as used in multiple Fujitsu Interstage products, allow remote attackers to cause a denial of service (daemon crash) via (1) an invalid request or (2) a large amount of data sent to the registered attribute value. Múltiples vulnerabilidades sin especificar en Fujitsu Interstage Smart Repository, como se utiliza en múltiples productos Fujitsu Interstage, permite a atacantes remotos provocar una denegación de servicio (caída del demon... • http://secunia.com/advisories/29250 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2008-1040
https://notcve.org/view.php?id=CVE-2008-1040
27 Feb 2008 — Buffer overflow in the Single Sign-On function in Fujitsu Interstage Application Server 8.0.0 through 8.0.3 and 9.0.0, Interstage Studio 8.0.1 and 9.0.0, and Interstage Apworks 8.0.0 allows remote attackers to execute arbitrary code via a long URI. Desbordamiento de búfer en la función Single Sign-On de Fujitsu Interstage Application Server 8.0.0 hasta 8.0.3 y 9.0.0, Interstage Studio 8.0.1 y 9.0.0, y Interstage Apworks 8.0.0 permite a atacantes remotos ejecutar código de su elección a través de una URI lar... • http://secunia.com/advisories/29088 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-5366
https://notcve.org/view.php?id=CVE-2007-5366
11 Oct 2007 — The Tomcat 4.1-based Servlet Service in Fujitsu Interstage Application Server 7.0 through 9.0.0 and Interstage Apworks/Studio 7.0 through 9.0.0 allows remote attackers to obtain sensitive information (web root path) via unspecified vectors that trigger an error message, probably related to enabling the useCanonCaches Java Virtual Machine (JVM) option. El Tomcat 4.1-based Servlet Service en Fujitsu Interstage Application Server 7.0 hasta la 9.0.0 y Interstage Apworks/Studio 7.0 hasta la 9.0.0 permite a ataca... • http://osvdb.org/41318 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •