verbose software vulnerabilities
vulnerabilities.aspcode.net
Searching verbose software vulnerabilities
DB4Web server, when configured to use verbose d
connections
|
configured
|
attackers
|
messages
|
verbose
|
systems
|
attempt
|
remote
|
DB4Web
|
server
|
allows
|
other
|
debug
|
proxy
|
use
|
TCP
|
DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message.
Buffer overflow in the WriteToLog function for
WriteToLog
|
connectors
|
function
|
overflow
|
through
|
server
|
Buffer
|
such
|
JRun
|
web
|
Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose logging enabled, allows remote attackers to execute arbitrary code via a long HTTP header Content-Type field or other fields.
The DecodeTCPOptions function in decode.c in Sn
DecodeTCPOptions
|
function
|
decodec
|
before
|
Snort
|
The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null dereference.
roundcube webmail Alpha, with a default high ve
roundcube
|
default
|
verbose
|
webmail
|
level
|
Alpha
|
high
|
roundcube webmail Alpha, with a default high verbose level ($rcmail_config['debug_level'] = 1), allows remote attackers to obtain the full path of the application via an invalid_task parameter, which leaks the path in an error message.
The save_log_local function in Fully Automatic
save_log_local
|
Installation
|
Automatic
|
function
|
Fully
|
The save_log_local function in Fully Automatic Installation (FAI) 2.10.1, and possibly 3.1.2, when verbose mode is enabled, stores the root password hash in /var/log/fai/current/fai.log, whose file permissions allow it to be copied to other hosts when fai-savelog is called and allows attackers to obtain the hash.
Software vulnerabilities results 1 to 6 of 6
Page:
1