VYPR

Omnihttpd

by Omnicron

CVEs (9)

  • CVE-2001-0113Mar 12, 2001
    risk 0.04cvss epss 0.08

    statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to execute arbitrary commands via the mostbrowsers parameter, whose value is used as part of a generated Perl script.

  • CVE-1999-0970Jun 5, 1999
    risk 0.04cvss epss 0.06

    The OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number of temporary files to be created.

  • CVE-2002-1455Jun 9, 2003
    risk 0.03cvss epss 0.00

    Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.

  • CVE-2001-0778Oct 18, 2001
    risk 0.03cvss epss 0.03

    OmniHTTPd 2.0.8 and earlier allow remote attackers to obtain source code via a GET request with the URL-encoded symbol for a space (%20).

  • CVE-2001-0114Mar 12, 2001
    risk 0.03cvss epss 0.03

    statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter.

  • CVE-1999-0951Oct 22, 1999
    risk 0.03cvss epss 0.05

    Buffer overflow in OmniHTTPd CGI program imagemap.exe allows remote attackers to execute commands.

  • CVE-2002-1035Oct 4, 2002
    risk 0.00cvss epss 0.01

    Omnicron OmniHTTPd 2.09 allows remote attackers to cause a denial of service (crash) via an HTTP request with a long, malformed HTTP 1version number.

  • CVE-2001-0777Oct 18, 2001
    risk 0.00cvss epss 0.01

    Omnicron OmniHTTPd 2.0.8 allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests for PHP scripts.

  • CVE-2001-0613Aug 22, 2001
    risk 0.00cvss epss 0.01

    Omnicron Technologies OmniHTTPD Professional 2.08 and earlier allows a remote attacker to create a denial of service via a long POST URL request.