VYPR

TIFF Server

by Aquaforest

CVEs (6)

  • CVE-2020-9325HigMar 18, 2020
    risk 0.49cvss 7.5epss 0.02

    Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download.

  • CVE-2020-9324HigMar 18, 2020
    risk 0.49cvss 7.5epss 0.01

    Aquaforest TIFF Server 4.0 allows Unauthenticated SMB Hash Capture via UNC.

  • CVE-2023-6352MedNov 30, 2023
    risk 0.35cvss 5.3epss 0.01

    The default configuration of Aquaforest TIFF Server allows access to arbitrary file paths, subject to any restrictions imposed by Internet Information Services (IIS) or Microsoft Windows. Depending on how a web application uses and configures TIFF Server, a remote attacker may…

  • CVE-2023-6344MedNov 30, 2023
    risk 0.35cvss 5.3epss 0.01

    Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate directories using the tiffserver/te003.aspx or te004.aspx 'ifolder' parameter. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server, possibly…

  • CVE-2023-6343MedNov 30, 2023
    risk 0.35cvss 5.3epss 0.01

    Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitive files using the tiffserver/tssp.aspx 'FN' and 'PN' parameters. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server,…

  • CVE-2020-9323MedMar 18, 2020
    risk 0.35cvss 5.3epss 0.02

    Aquaforest TIFF Server 4.0 allows Unauthenticated File and Directory Enumeration via tiffserver/tssp.aspx.