Vulnerabilities > Microworld Technologies

DATE CVE VULNERABILITY TITLE RISK
2008-08-20 CVE-2008-3729 Improper Authentication vulnerability in Microworld Technologies Mailscan 5.6.A
Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to bypass authentication and obtain administrative access via a direct request with (1) an IsAdmin=true cookie value or (2) no cookie.
network
low complexity
microworld-technologies CWE-287
7.5
2008-08-20 CVE-2008-3728 Permissions, Privileges, and Access Controls vulnerability in Microworld Technologies Mailscan 5.6.A
Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to determine the installation path, IP addresses, and error messages via direct requests to files under LOG/.
network
low complexity
microworld-technologies CWE-264
5.0
2008-08-20 CVE-2008-3727 Path Traversal vulnerability in Microworld Technologies Mailscan 5.6.A
Directory traversal vulnerability in Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to read arbitrary files via a ..
network
low complexity
microworld-technologies CWE-22
5.0
2008-08-20 CVE-2008-3726 Cross-Site Scripting vulnerability in Microworld Technologies Mailscan 5.6.A
Cross-site scripting (XSS) vulnerability in Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to inject arbitrary web script or HTML via the URI.
4.3
2008-03-10 CVE-2008-1221 Path Traversal vulnerability in Microworld Technologies Escan, Escan Management Console and Escan Server
Absolute path traversal vulnerability in the FTP server in MicroWorld eScan Corporate Edition 9.0.742.98 and eScan Management Console (aka eScan Server) 9.0.742.1 allows remote attackers to read arbitrary files via an absolute pathname in the RETR (get) command.
network
low complexity
microworld-technologies CWE-22
5.0
2007-08-31 CVE-2007-4649 Permissions, Privileges, and Access Controls vulnerability in Microworld Technologies products
MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Everyone:Full Control) for their installation directory trees, which allows local users to gain privileges by replacing application files, as demonstrated by traysser.exe.
local
low complexity
microworld-technologies CWE-264
7.2
2007-05-24 CVE-2007-2687 Remote Buffer Overflow vulnerability in Microworld Technologies Escan 9.0.715.1
Stack-based buffer overflow in the MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan before 9.0.718.1 allows remote attackers to execute arbitrary code via a long command.
network
low complexity
microworld-technologies
critical
10.0
2007-05-02 CVE-2007-0655 Unspecified vulnerability in Microworld Technologies Escan
The MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan 8.0.671.1, and possibly other versions, allows remote or local attackers to gain privileges and execute arbitrary commands by connecting directly to TCP port 2222.
network
low complexity
microworld-technologies
critical
10.0