Kf Web Server
by Key Focus
CVEs (4)
| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2007-3396 | 0.04 | — | 0.11 | Jun 26, 2007 | Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the opsubmenu parameter. | ||
| CVE-2002-2403 | 0.04 | — | 0.07 | Dec 31, 2002 | Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences. | ||
| CVE-2002-1031 | 0.04 | — | 0.07 | Oct 4, 2002 | KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request containing a %00 (null) character. | ||
| CVE-2002-1032 | 0.00 | — | 0.01 | Oct 4, 2002 | Buffer overflow in KeyFocus (KF) web server 1.0.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed HTTP header. |
- CVE-2007-3396Jun 26, 2007risk 0.04cvss —epss 0.11
Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the opsubmenu parameter.
- CVE-2002-2403Dec 31, 2002risk 0.04cvss —epss 0.07
Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences.
- CVE-2002-1031Oct 4, 2002risk 0.04cvss —epss 0.07
KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request containing a %00 (null) character.
- CVE-2002-1032Oct 4, 2002risk 0.00cvss —epss 0.01
Buffer overflow in KeyFocus (KF) web server 1.0.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed HTTP header.