VYPR

Wwwisis

by Wwwisis

CVEs (3)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2007-54840.030.01Oct 16, 2007Directory traversal vulnerability in wxis.exe in WWWISIS 7.1 allows local users to read arbitrary files via a .. (dot dot) in the IsisScript parameter to iah.
CVE-2007-54550.030.04Oct 14, 2007Cross-site scripting (XSS) vulnerability in wxis.exe in WWWISIS 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a call to the iah/iah.xis IsisScript code, possibly involving the lang or exprSearch parameter.
CVE-2002-05080.000.04Aug 12, 2002wwwisis 3.45 and earlier allows remote attackers to execute arbitrary commands and read files via the parameters (1) prolog or (2) epilog.