Skip to main content

Vendor archive

oreilly CVEs

Beta · best-effort

8 CVEs tagged to vendor oreilly2 Critical, 2 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2001-0743

Published Oct 18, 2001

Paging function in O'Reilly WebBoard Pager 4.10 allows remote attackers to cause a denial of service via a message with an escaped ' character followed by JavaScript commands.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0394

Published Aug 22, 2001

Remote manager service in Website Pro 3.0.37 allows remote attackers to cause a denial of service via a series of malformed HTTP requests to the /dyn directory.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0626

Published Aug 22, 2001

O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request containing a ":" character.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0769

Published Oct 20, 2000

O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0622

Published Jul 19, 2000

Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL containing a long "keywords"…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0623

Published Jul 17, 2000

Buffer overflow in O'Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0066

Published Jan 13, 2000

WebSite Pro allows remote attackers to determine the real pathname of webdirectories via a malformed URL request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-1180

Published Feb 16, 1999

O'Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cmd or (2) args.bat.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1