Vulnerabilities > KEY Focus

DATE CVE VULNERABILITY TITLE RISK
2007-06-26 CVE-2007-3396 Cross-Site Scripting vulnerability in KEY Focus KF web Server 3.1.0
Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the opsubmenu parameter.
network
key-focus
4.3
2002-12-31 CVE-2002-2403 Path Traversal vulnerability in KEY Focus KF web Server 1.0.8
Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences.
network
low complexity
key-focus CWE-22
5.0
2002-10-04 CVE-2002-1032 Denial-Of-Service vulnerability in KF Web Server
Buffer overflow in KeyFocus (KF) web server 1.0.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed HTTP header.
network
low complexity
key-focus
7.5
2002-10-04 CVE-2002-1031 Unspecified vulnerability in KEY Focus KF web Server 1.0.2
KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request containing a %00 (null) character.
network
low complexity
key-focus
5.0