4 results (0.002 seconds)

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 1

20 Dec 2006 — Inktomi Search 4.1.4 allows remote attackers to obtain sensitive information via direct requests with missing parameters to (1) help/header.html, (2) thesaurus.html, and (3) topics.html, which leak the installation path in the resulting error message, a related issue to CVE-2006-5970. Inktomi Search 4.1.4 permite a atacantes remotos obtener información sensible mediante peticiones directas con la ausencia de algún parámetro a (1) help/header.html, (2) thesaurus.html, y (3) topics.html, lo cual deja ver la r... • http://securitytracker.com/id?1017242 •

CVSS: 6.8EPSS: 0%CPEs: 1EXPL: 0

15 May 2003 — Cross-site scripting (XSS) vulnerability in Inktomi Traffic-Server 5.5.1 allows remote attackers to insert arbitrary web script or HTML into an error page that appears to come from the domain that the client is visiting, aka "Man-in-the-Middle" XSS. Vulnerabilidad de secuencias de comandos en sitios cruzados en Inktomi Traffic-Server 5.5.1 permite que atacantes remotos inserten script web arbitrario o HTML dentro de una página de error que parece provenir de el dominio que está visitando el cliente (también... • http://marc.info/?l=bugtraq&m=105292750807005&w=2 •

CVSS: 7.8EPSS: 0%CPEs: 9EXPL: 1

04 Oct 2002 — Buffer overflow in traffic_manager for Inktomi Traffic Server 4.0.18 through 5.2.2, Traffic Edge 1.1.2 and 1.5.0, and Media-IXT 3.0.4 allows local users to gain root privileges via a long -path argument. • https://www.exploit-db.com/exploits/21580 •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

11 Dec 2000 — Search engine in Ultraseek 3.1 and 3.1.10 (aka Inktomi Search) allows remote attackers to cause a denial of service via a malformed URL. • http://marc.info/?l=bugtraq&m=97301487015664&w=2 •