Vulnerabilities
Vulnerable Software
Apple:  >> Quicktime Streaming Server  Security Vulnerabilities
Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter.
CVSS Score
4.3
EPSS Score
0.027
Published
2003-12-31
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.
CVSS Score
7.5
EPSS Score
0.878
Published
2003-03-07
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.
CVSS Score
5.0
EPSS Score
0.005
Published
2003-03-07
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.
CVSS Score
5.0
EPSS Score
0.008
Published
2003-03-07
Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.
CVSS Score
4.3
EPSS Score
0.004
Published
2003-03-07
Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.
CVSS Score
7.5
EPSS Score
0.009
Published
2003-03-07


Contact Us

Shodan ® - All rights reserved