Skip to main content

Vendor/product archive

verity / ultraseek CVEs

Beta · best-effort

4 CVEs tagged to verity / ultraseek1 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2006-5819

Published Nov 18, 2006

Verity Ultraseek before 5.7 allows remote attackers to use the server as a proxy for web attacks and host scanning via a direct request to the highlight/index.html script.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-5970

Published Nov 18, 2006

Verity Ultraseek before 5.7 allows remote attackers to obtain sensitive information via direct requests with (1) a null ("%00") terminated url parameter to help/urlstatusgo.html;…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5971

Published Nov 18, 2006

Absolute path traversal vulnerability in admin/logfile.txt in Verity Ultraseek before 5.6.2 allows remote attackers to read arbitrary files via the name variable.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0050

Published Jun 14, 2004

Verity Ultraseek before 5.2.2 allows remote attackers to obtain the full pathname of the document root via an MS-DOS device name in the web search option, such as (1) NUL, (2) CON…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1