Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
an-http vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2001-0202
Picserver web server allows remote malicious users to read arbitrary files via a .. (dot dot) attack in an HTTP GET request.
Informs Picserver 1.0
1 EDB exploit
NA
CVE-2024-4772
An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vulnerability affects Firefox < 126.
6.1
CVSSv3
CVE-2019-16532
An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections.
Yzmcms Yzmcms 5.3
NA
CVE-2001-1090
nss_postgresql 0.6.1 and before allows a remote malicious user to execute arbitrary SQL queries by inserting SQL code into an HTTP request.
Alessandro Gardich Nss Postgresql 0.6.1
8.1
CVSSv3
CVE-2019-10101
JetBrains Kotlin versions prior to 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.
Jetbrains Kotlin
NA
CVE-2002-1541
BadBlue 1.7 allows remote malicious users to bypass password protections for directories and files via an HTTP request containing an extra / (slash).
Working Resources Inc. Badblue 1.7.0
6.1
CVSSv3
CVE-2010-5336
IceWarp Webclient prior to 10.2.1 has XSS via an HTTP POST request: admin/login.html with the parameter username is persistent in 10.2.0.
Icewarp Webclient
6.1
CVSSv3
CVE-2010-5340
IceWarp Webclient prior to 10.2.1 has XSS via an HTTP POST request: webmail/ with the parameter password is non-persistent in 10.2.0.
Icewarp Webclient
NA
CVE-2003-1181
Advanced Poll 2.0.2 allows remote malicious users to obtain sensitive information via an HTTP request to info.php, which invokes the phpinfo() function.
Advanced Poll Advanced Poll 2.0.2
1 EDB exploit
NA
CVE-2004-1813
VocalTec VGW4/8 Gateway 8.0 allows remote malicious users to bypass authentication via an HTTP request to home.asp with a trailing slash (/).
Vocaltec Vgw4 8 Telephony Gateway 8.0
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »