cbcvebase.

Sambar Server vulnerabilities

18 known vulnerabilities affecting sambar/sambar_server.

Total CVEs
18
CISA KEV
0
Public exploits
11
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH5MEDIUM12

Vulnerabilities

Page 1 of 1
CVE-2004-2086P3MEDIUMCVSS 5.0PoCv6.02004-02-06
CVE-2004-2086 [MEDIUM] CVE-2004-2086: Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allow Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a long query parameter.
nvd
CVE-2002-0128P4HIGHCVSS 7.5PoCv5.12002-03-25
CVE-2002-0128 [HIGH] CVE-2002-0128: cgitest.exe in Sambar Server 5.1 before Beta 4 allows remote attackers to cause a denial of service, cgitest.exe in Sambar Server 5.1 before Beta 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long argument.
nvd
CVE-2003-1286P3HIGHCVSS 7.5PoCv5.0v5.1+3 more2003-12-31
CVE-2003-1286 [HIGH] CVE-2003-1286: HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attackers to send proxy HTTP requests to the Sambar Server's administrative interface and external web servers, by making a "Connection: keep-alive" request before the proxy requests.
nvd
CVE-2004-2565P4MEDIUMCVSS 5.0PoCv6.12004-12-31
CVE-2004-2565 [MEDIUM] CVE-2004-2565: Multiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly ot Multiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, when the administrative IP address restrictions have been modified from the default, allow remote authenticated users to read arbitrary files via (1) a "..\" (dot dot backslash) in the file parameter to showini.asp, or (2) an absolute pat
nvd
CVE-2000-0213P4MEDIUMCVSS 5.0PoC≤ 4.22000-02-23
CVE-2000-0213 [MEDIUM] CVE-2000-0213: The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remo The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacharacters.
nvd
CVE-2001-1010P4MEDIUMCVSS 5.0PoCv4.4v5.02001-07-22
CVE-2001-1010 [MEDIUM] CVE-2001-1010: Directory traversal vulnerability in pagecount CGI script in Sambar Server before 5.0 beta 5 allows Directory traversal vulnerability in pagecount CGI script in Sambar Server before 5.0 beta 5 allows remote attackers to overwrite arbitrary files via a .. (dot dot) attack on the page parameter.
nvd
CVE-2001-1106P4HIGHCVSS 7.5PoCv4.1v4.2.1_production+3 more2001-07-25
CVE-2001-1106 [HIGH] CVE-2001-1106: The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the sambar program to call the decryption procedure.
nvd
CVE-2002-0737P4MEDIUMCVSS 6.4PoCv5.12002-08-12
CVE-2002-0737 [MEDIUM] CVE-2002-0737: Sambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scr Sambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scripts, or cause a denial of service (resource exhaustion) via DOS devices, using a URL that ends with a space and a null character.
nvd
CVE-2000-0835P4MEDIUMCVSS 5.0PoCv4.3v4.42000-11-14
CVE-2000-0835 [MEDIUM] CVE-2000-0835: search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read a search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter.
nvd
CVE-2004-2564P4MEDIUMCVSS 4.3PoCv6.12004-12-31
CVE-2004-2564 [MEDIUM] CVE-2004-2564: Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and poss Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in show.asp and (2) the title parameter in showperf.asp.
nvd
CVE-2000-0509P3CRITICALCVSS 10.0≤ 4.32000-06-01
CVE-2000-0509 [CRITICAL] CVE-2000-0509: Buffer overflows in the finger and whois demonstration scripts in Sambar Server 4.3 allow remote att Buffer overflows in the finger and whois demonstration scripts in Sambar Server 4.3 allow remote attackers to execute arbitrary commands via a long hostname.
nvd
CVE-2006-6624P4MEDIUMCVSS 4.0PoCv6.42006-12-18
CVE-2006-6624 [MEDIUM] CVE-2006-6624: The FTP Server in Sambar Server 6.4 allows remote authenticated users to cause a denial of service ( The FTP Server in Sambar Server 6.4 allows remote authenticated users to cause a denial of service (application crash) via a long series of "./" sequences in the SIZE command.
nvd
CVE-2001-1292P4HIGHCVSS 7.5v5.0v5.1+1 more2001-08-13
CVE-2001-1292 [HIGH] CVE-2001-1292: Sambar Telnet Proxy/Server allows remote attackers to cause a denial of service and possibly execute Sambar Telnet Proxy/Server allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long password.
nvd
CVE-1999-1523P4HIGHCVSS 7.5v4.2.11999-10-04
CVE-1999-1523 [HIGH] CVE-1999-1523: Buffer overflow in Sambar Web Server 4.2.1 allows remote attackers to cause a denial of service, and Buffer overflow in Sambar Web Server 4.2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request.
nvd
CVE-2003-1287P4MEDIUMCVSS 4.6v5.0v5.1+3 more2003-12-31
CVE-2003-1287 [MEDIUM] CVE-2003-1287: Sambar Server before 6.0 beta 3 allows attackers with physical access to execute arbitrary code via Sambar Server before 6.0 beta 3 allows attackers with physical access to execute arbitrary code via a request with an MS-DOS device name such as com1.pl, con.pl, or aux.pl, which causes Perl to read the code from the associated device.
nvd
CVE-2003-1285P4MEDIUMCVSS 4.3v5.0v5.1+3 more2003-12-31
CVE-2003-1285 [MEDIUM] CVE-2003-1285: Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server before 6.0 beta 6 allow remote Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server before 6.0 beta 6 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) isapi/testisa.dll, (2) testcgi.exe, (3) environ.pl, (4) the query parameter to samples/search.dll, (5) the price parameter to mortgage.pl, (6) the query string in dumpenv.pl, (7) the qu
nvd
CVE-2005-3506P4MEDIUMCVSS 4.3≤ 6.3v6.32005-11-05
CVE-2005-3506 [MEDIUM] CVE-2005-3506: Cross-site scripting (XSS) vulnerability in proxy.asp in Sambar Server 6.3 BETA 2 and possibly earli Cross-site scripting (XSS) vulnerability in proxy.asp in Sambar Server 6.3 BETA 2 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the (1) Remote Proxy Server or (2) Proxy Filter IPs field.
nvd
CVE-1999-1178P4MEDIUMCVSS 5.0v4.11998-06-10
CVE-1999-1178 [MEDIUM] CVE-1999-1178: Sambar Server 4.1 beta allows remote attackers to obtain sensitive information about the server via Sambar Server 4.1 beta allows remote attackers to obtain sensitive information about the server via an HTTP request for the dumpenv.pl script.
nvd
Sambar Server vulnerabilities | cvebase