VYPR

Net.data

by IBM

CVEs (4)

  • CVE-2004-1442Dec 31, 2004
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web script or HTML via a macro filename, which is not properly handled by error messages such as "DTWP001E."

  • CVE-2000-1110Jan 9, 2001
    risk 0.03cvss epss 0.03

    document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program.

  • CVE-2003-1282Dec 31, 2003
    risk 0.00cvss epss 0.01

    IBM Net.Data allows remote attackers to obtain sensitive information such as path names, server names and possibly user names and passwords by causing the (1) $(DTW_CURRENT_FILENAME), (2) $(DATABASE), (3) $(LOGIN), (4) $(PASSWORD), and possibly other predefined variables that…

  • CVE-2000-0677Oct 20, 2000
    risk 0.00cvss epss 0.03

    Buffer overflow in IBM Net.Data db2www CGI program allows remote attackers to execute arbitrary commands via a long PATH_INFO environmental variable.