Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
orionserver orion application server vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2005-2981
Cross-site scripting (XSS) vulnerability in Orion 1.3.8 and 1.4.5 allows remote malicious users to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.
Orionserver Orion Application Server 1.3.8
Orionserver Orion Application Server 1.4.5
5
CVSSv2
CVE-2006-0816
Orion Application Server prior to 2.0.7, when running on Windows, allows remote malicious users to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the extension of a URL.
Orionserver Orion Application Server
5
CVSSv2
CVE-2002-1859
Orion Application Server 1.5.3, when running on Windows, allows remote malicious users to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
Orionserver Orion Application Server 1.5.3
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started