Vulnerabilities
Vulnerable Software
Cvstrac:  Security Vulnerabilities
The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a ' character in certain messages, tickets, or Wiki entries.
CVSS Score
4.3
EPSS Score
0.036
Published
2007-01-29
Multiple cross-site scripting (XSS) vulnerabilities in (1) main.c and (2) login.c for CVSTrac before 1.1.5 allow remote attackers to inject arbitrary HTML and web script.
CVSS Score
4.3
EPSS Score
0.014
Published
2004-12-31
filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.
CVSS Score
7.5
EPSS Score
0.14
Published
2004-12-31


Contact Us

Shodan ® - All rights reserved