Filtered by vendor Surfcontrol Subscriptions
Filtered by product Web Filter Subscriptions
Total 5 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2002-0706 1 Surfcontrol 2 Superscout Web Filter, Web Filter 2024-08-08 N/A
UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the administrative password using a hard-coded key in a Javascript function.
CVE-2002-0708 1 Surfcontrol 2 Superscout Web Filter, Web Filter 2024-08-08 N/A
Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary files via an HTTP request containing ... (triple dot) sequences.
CVE-2002-0705 1 Surfcontrol 2 Superscout Web Filter, Web Filter 2024-08-08 N/A
The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory, which allows remote attackers to obtain valid usernames and crack the passwords.
CVE-2002-0707 1 Surfcontrol 2 Superscout Web Filter, Web Filter 2024-08-08 N/A
The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large GET requests, possibly due to a buffer overflow.
CVE-2002-0709 1 Surfcontrol 2 Superscout Web Filter, Web Filter 2024-08-08 N/A
SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary SQL queries via the RunReport option to SimpleBar.dll, and possibly other DLLs.