VYPR
Vendor

Fraunhofer Fit

Products
2
CVEs
6
Across products
6
Status
Private

Products

2

Recent CVEs

6
  • CVE-2021-36359HigAug 30, 2021
    risk 0.58cvss 8.8epss 0.04

    OrbiTeam BSCW Classic before 7.4.3 allows exportpdf authenticated remote code execution (RCE) via XML tag injection because reportlab\platypus\paraparser.py (reached via bscw.cgi op=_editfolder.EditFolder) calls eval on attacker-supplied Python code. This is fixed in 5.0.12,…

  • CVE-2021-39271HigAug 30, 2021
    risk 0.57cvss 8.8epss 0.04

    OrbiTeam BSCW Classic before 7.4.3 allows authenticated remote code execution (RCE) during archive extraction via attacker-supplied Python code in the class attribute of a .bscw file. This is fixed in 5.0.12, 5.1.10, 5.2.4, 7.3.3, and 7.4.3.

  • CVE-2002-0095Mar 25, 2002
    risk 0.03cvss epss 0.03

    The default configuration of BSCW (Basic Support for Cooperative Work) 3.x and possibly version 4 enables user self registration, which could allow remote attackers to upload files and possibly join a user community that was intended to be closed.

  • CVE-2014-2301May 12, 2014
    risk 0.00cvss epss 0.02

    OrbiTeam BSCW before 5.0.8 allows remote attackers to obtain sensitive metadata via the inf operations (op=inf) to an object in pub/bscw.cgi/.

  • CVE-2002-0094Mar 25, 2002
    risk 0.00cvss epss 0.03

    config_converters.py in BSCW (Basic Support for Cooperative Work) 3.x and versions before 4.06 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name during filename conversion.

  • CVE-2001-0973Aug 31, 2001
    risk 0.00cvss epss 0.02

    BSCW groupware system 3.3 through 4.0.2 beta allows remote attackers to read or modify arbitrary files by uploading and extracting a tar file with a symlink into the data-bag space.