Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
orionserver orion application server vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2005-2981
Cross-site scripting (XSS) vulnerability in Orion 1.3.8 and 1.4.5 allows remote malicious users to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.
Orionserver Orion Application Server 1.3.8
Orionserver Orion Application Server 1.4.5
NA
CVE-2006-0816
Orion Application Server prior to 2.0.7, when running on Windows, allows remote malicious users to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the extension of a URL.
Orionserver Orion Application Server
NA
CVE-2002-1859
Orion Application Server 1.5.3, when running on Windows, allows remote malicious users to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
Orionserver Orion Application Server 1.5.3
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started