VYPR

Awffull

by Awffull

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2007-32990.000.01Jun 20, 2007Cross-site scripting (XSS) vulnerability in AWFFull before 3.7.4, when AllSearchStr (aka the All Search Terms report) is enabled, allows remote attackers to inject arbitrary web script or HTML via a search string.
CVE-2007-05100.000.01Jan 26, 2007Multiple buffer overflows in (1) graphs.c, (2) output.c, and (3) preserve.c in AWFFull 3.7.1 and earlier have unknown impact and attack vectors. NOTE: some of these details are obtained from third party information. NOTE: There may not be any attack vector that crosses privilege boundaries.