Vulnerabilities > Ecartis

DATE CVE VULNERABILITY TITLE RISK
2006-01-21 CVE-2006-0332 Code Injection vulnerability in Ecartis 1.0.0Snapshot20050909
Pantomime in Ecartis 1.0.0 snapshot 20050909 stores e-mail attachments in a publicly accessible directory, which may allow remote attackers to upload arbitrary files.
network
low complexity
ecartis CWE-94
6.4
2004-12-31 CVE-2004-0913 Remote Undisclosed Privilege Escalation vulnerability in Ecartis
Unknown vulnerability in ecartis 0.x before 0.129a+1.0.0-snap20020514-1.3 and 1.x before 1.0.0+cvs.20030911-8 allows attackers in the same domain to gain administrator privileges and modify configuration.
local
low complexity
ecartis
4.6
2004-05-04 CVE-2003-0782 Unspecified vulnerability in Ecartis 1.0.0
Multiple buffer overflows in ecartis before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.
network
low complexity
ecartis
critical
10.0
2004-05-04 CVE-2003-0781 Unspecified vulnerability in Ecartis 1.0.0
Unknown vulnerability in ecartis before 1.0.0 does not properly validate user input, which allows attackers to obtain mailing list passwords.
network
low complexity
ecartis
critical
10.0
2003-04-02 CVE-2003-0162 Unspecified vulnerability in Ecartis 1.0.0Snapshot20021013
Ecartis 1.0.0 (formerly listar) before snapshot 20030227 allows remote attackers to reset passwords of other users and gain privileges by modifying hidden form fields in the HTML page.
network
low complexity
ecartis
7.5
2002-08-12 CVE-2002-0469 Ecartis (formerly Listar) 1.0.0 in snapshot 20020125 and earlier does not properly drop privileges when Ecartis is installed setuid-root, "lock-to-user" is not set, and ecartis is called by certain MTA's, which could allow local users to gain privileges.
local
low complexity
ecartis listar
7.2
2002-08-12 CVE-2002-0468 Local Buffer Overflow vulnerability in Ecartis/Listar
Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privileges via (1) a long command line argument, which is not properly handled in core.c, or possibly via bad uses of sprintf() in (2) moderate.c, (3) lcgi.c, (4) fileapi.c, (5) cookie.c, (6) codes.c, or other files.
local
low complexity
ecartis listar
4.6
2002-08-12 CVE-2002-0467 Buffer Overflow vulnerability in Ecartis/Listar
Buffer overflows in Ecartis (formerly Listar) 1.0.0 before snapshot 20020125 allows remote attackers to execute arbitrary code via (1) address_match() of mystring.c or (2) other functions in tolist.c.
network
low complexity
ecartis listar
critical
10.0