2 results (0.005 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in RaidenHTTPD 2.0.19 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the ulang parameter. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS)en RaidenHTTPD 2.0.19 y versiones anteriores permite a atacantes remotos inyectar a su elección secuencias de comandos web o HTML mediante vectores no especificados relacionadas con el parámetro ulang. • http://jvn.jp/jp/JVN%2391868305/index.html http://secunia.com/advisories/28770 http://www.raidenhttpd.com/jp/security.html http://www.securityfocus.com/bid/27628 http://www.vupen.com/english/advisories/2008/0411 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 10.0EPSS: 2%CPEs: 1EXPL: 3

Directory traversal vulnerability in raidenhttpd-admin/workspace.php in RaidenHTTPD 2.0.19, when the WebAdmin function is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ulang parameter. Vulnerabilidad de salto de directorio en raidenhttpd-admin/workspace.php en RaidenHTTPD 2.0.19, cuando la función WebAdmin está activada, permite a atacantes remotos incluir y ejecutar archivos locales de su elección a través de la secuencia .. (punto punto) en el parámetro ulang. • https://www.exploit-db.com/exploits/4747 http://jvn.jp/jp/JVN%2390438169/index.html http://retrogod.altervista.org/rgod_raidenhttpdudo.html http://secunia.com/advisories/28143 http://securityreason.com/securityalert/3460 http://www.osvdb.org/39228 http://www.raidenhttpd.com/jp/security.html http://www.securityfocus.com/archive/1/485221/100/0/threaded http://www.securityfocus.com/bid/26903 http://www.vupen.com/english/advisories/2007/4244 https://exchange.xforce.ibmcloud.co • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •