Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
monkey-project vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2002-1663
The Post_Method function in method.c for Monkey HTTP Daemon prior to 0.5.1 allows remote malicious users to cause a denial of service (crash) via a POST request with an invalid or missing Content-Length header value.
Monkey-project Monkey
1 EDB exploit
6.8
CVSSv2
CVE-2013-3843
Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) prior to 1.2.1 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP header.
Monkey-project Monkey
4.3
CVSSv2
CVE-2002-1852
Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote malicious users to inject arbitrary web script or HTML via (1) the URL or (2) a parameter to test2.pl.
Monkey-project Monkey 0.5.0
1 EDB exploit
5
CVSSv2
CVE-2002-2154
Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote malicious users to read arbitrary files via .. (dot dot) sequences.
Monkey-project Monkey 0.1.4
1 EDB exploit
6.9
CVSSv2
CVE-2012-5303
Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathname different from the default /var/run/monkey.pid pathname.
Monkey-project Monkey 0.9.3
6.9
CVSSv2
CVE-2012-4443
Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to gain privileges by leveraging cgi-bin write access.
Monkey-project Monkey 0.9.3
7.5
CVSSv2
CVE-2013-2159
Monkey HTTP Daemon: broken user name authentication
Monkey-project Monkey 1.2.1
4.3
CVSSv2
CVE-2013-2181
Cross-site scripting (XSS) vulnerability in the Directory Listing plugin in Monkey HTTP Daemon (monkeyd) 1.2.2 allows malicious users to inject arbitrary web script or HTML via a file name.
Monkey-project Monkey 1.2.2
4.7
CVSSv2
CVE-2012-4442
Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restrictions by leveraging a race condition in a file-permission check.
Monkey-project Monkey 0.9.3
5
CVSSv2
CVE-2013-3724
The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote malicious users to cause a denial of service (thread crash and service outage) via a '\0' character in an HTTP request.
Monkey-project Monkey 1.1.1
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27975
CVE-2024-2961
CVE-2024-20380
XML injection
HTML injection
CVE-2024-29204
CVE-2023-51795
memory leak
CVE-2024-3470
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2