Vulnerabilities
Vulnerable Software
Webtrends:  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in WebTrends allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
CVSS Score
4.3
EPSS Score
0.002
Published
2010-02-05
viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid profileid parameter, which leaks the pathname in an error message.
CVSS Score
4.3
EPSS Score
0.046
Published
2004-12-31
Buffer overflow in WTRS_UI.EXE (WTX_REMOTE.DLL) for WebTrends Reporting Center 4.0d allows remote attackers to execute arbitrary code via a long HTTP GET request to the /reports/ directory.
CVSS Score
7.5
EPSS Score
0.054
Published
2002-06-18
WebTrends Reporting Center 4.0d allows remote attackers to determine the real path of the web server via a GET request to get_od_toc.pl with an empty Profile parameter, which leaks the pathname in an error message.
CVSS Score
5.0
EPSS Score
0.007
Published
2002-06-18
WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20).
CVSS Score
5.0
EPSS Score
0.038
Published
2001-09-20
WebTrends software stores account names and passwords in a file which does not have restricted access permissions.
CVSS Score
2.1
EPSS Score
0.001
Published
1999-06-29


Contact Us

Shodan ® - All rights reserved