Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
orionserver orion application server vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2005-2981
Cross-site scripting (XSS) vulnerability in Orion 1.3.8 and 1.4.5 allows remote malicious users to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.
Orionserver Orion Application Server 1.3.8
Orionserver Orion Application Server 1.4.5
445
VMScore
CVE-2006-0816
Orion Application Server prior to 2.0.7, when running on Windows, allows remote malicious users to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the extension of a URL.
Orionserver Orion Application Server
445
VMScore
CVE-2002-1859
Orion Application Server 1.5.3, when running on Windows, allows remote malicious users to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
Orionserver Orion Application Server 1.5.3
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started