Vulnerabilities > Bajie

DATE CVE VULNERABILITY TITLE RISK
2003-12-31 CVE-2003-1543 Cross-Site Scripting vulnerability in Bajie Java Http Server 0.95
Cross-site scripting (XSS) vulnerability in Bajie Http Web Server 0.95zxe, 0.95zxc, and possibly others, allows remote attackers to inject arbitrary web script or HTML via the query string, which is reflected in an error message.
network
bajie CWE-79
4.3
2003-12-31 CVE-2003-1511 Cross-Site Scripting vulnerability in Bajie Java Http Server 0.95
Cross-site scripting (XSS) vulnerability in Bajie Java HTTP Server 0.95 through 0.95zxv4 allows remote attackers to inject arbitrary web script or HTML via (1) the query string to test.txt, (2) the guestName parameter to the custMsg servlet, or (3) the cookiename parameter to the CookieExample servlet.
network
bajie CWE-79
4.3
2001-05-03 CVE-2001-0308 Code Injection vulnerability in Bajie Java Http Server
UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ...
network
low complexity
bajie CWE-94
7.5
2001-05-03 CVE-2001-0307 Code Injection vulnerability in Bajie Java Http Server
Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist.
network
low complexity
bajie CWE-94
7.5
2000-10-20 CVE-2000-0774 Path Disclosure vulnerability in Bajie Java Http Server 1.0
The sample Java servlet "test" in Bajie HTTP web server 0.30a reveals the real pathname of the web document root.
network
low complexity
bajie
5.0
2000-10-20 CVE-2000-0773 Unspecified vulnerability in Bajie Java Http Server 1.0
Bajie HTTP web server 0.30a allows remote attackers to read arbitrary files via a URL that contains a "....", a variant of the dot dot directory traversal attack.
network
low complexity
bajie
5.0