VYPR

Samba Web Administration Tool (SWAT)

by Samba (software)

CVEs (6)

  • CVE-2023-0922MedApr 3, 2023
    risk 0.38cvss 5.9epss 0.00

    The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only connection.

  • CVE-2000-0937Dec 19, 2000
    risk 0.04cvss —epss 0.08

    Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which allows remote attackers to conduct brute force password guessing attacks.

  • CVE-2000-0935Dec 19, 2000
    risk 0.03cvss —epss 0.01

    Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file.

  • CVE-2011-2694Jul 29, 2011
    risk 0.01cvss —epss 0.06

    Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd…

  • CVE-2000-0939Dec 19, 2000
    risk 0.00cvss —epss 0.02

    Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and forcing it to restart.

  • CVE-2000-0938Dec 19, 2000
    risk 0.00cvss —epss 0.02

    Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided versus an invalid name, which allows remote attackers to identify valid users on the server.