Vulnerabilities > Redhat > Directory Server

DATE CVE VULNERABILITY TITLE RISK
2008-04-16 CVE-2008-0893 Permissions, Privileges, and Access Controls vulnerability in Redhat Directory Server 8.0
Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, does not properly restrict access to CGI scripts, which allows remote attackers to perform administrative actions.
network
low complexity
redhat CWE-264
7.5
2008-04-16 CVE-2008-0892 Improper Input Validation vulnerability in Redhat Directory Server and Fedora Directory Server
The replication monitor CGI script (repl-monitor-cgi.pl) in Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, allows remote attackers to execute arbitrary commands.
network
low complexity
redhat CWE-20
critical
9.0
2008-03-12 CVE-2008-0890 Permissions, Privileges, and Access Controls vulnerability in Redhat Directory Server
Red Hat Directory Server 7.1 before SP4 uses insecure permissions for certain directories, which allows local users to modify JAR files and execute arbitrary code via unknown vectors.
local
low complexity
redhat CWE-264
4.6