Total
4 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-1999-1287 | 1 Stephen Turner | 1 Analog | 2017-12-18 | 5.0 MEDIUM | N/A |
Vulnerability in Analog 3.0 and earlier allows remote attackers to read arbitrary files via the forms interface. | |||||
CVE-2001-0301 | 1 Stephen Turner | 1 Analog | 2017-10-09 | 10.0 HIGH | N/A |
Buffer overflow in Analog before 4.16 allows remote attackers to execute arbitrary commands by using the ALIAS command to construct large strings. | |||||
CVE-2002-0166 | 1 Stephen Turner | 1 Analog | 2008-09-10 | 7.5 HIGH | N/A |
Cross-site scripting vulnerability in analog before 5.22 allows remote attackers to execute Javascript via an HTTP request containing the script, which is entered into a web logfile and not properly filtered by analog during display. | |||||
CVE-2002-1154 | 1 Stephen Turner | 1 Analog | 2008-09-05 | 5.0 MEDIUM | N/A |
anlgform.pl in Analog before 5.23 does not restrict access to the PROGRESSFREQ progress update command, which allows remote attackers to cause a denial of service (disk consumption) by using the command to report updates more frequently and fill the web server error log. |