Vulnerabilities > Webtrends

DATE CVE VULNERABILITY TITLE RISK
2010-02-05 CVE-2003-1583 Cross-Site Scripting vulnerability in Webtrends LOG Analyzer
Cross-site scripting (XSS) vulnerability in WebTrends allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
network
webtrends CWE-79
4.3
2004-12-31 CVE-2004-2748 Information Exposure vulnerability in Webtrends Reporting Center 6.1A
viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid profileid parameter, which leaks the pathname in an error message.
network
webtrends CWE-200
4.3
2002-06-18 CVE-2002-0596 Information Exposure vulnerability in Webtrends Reporting Center 4.0D
WebTrends Reporting Center 4.0d allows remote attackers to determine the real path of the web server via a GET request to get_od_toc.pl with an empty Profile parameter, which leaks the pathname in an error message.
network
low complexity
webtrends CWE-200
5.0
2002-06-18 CVE-2002-0595 Buffer Overflow vulnerability in Webtrends Reporting Center 4.0D
Buffer overflow in WTRS_UI.EXE (WTX_REMOTE.DLL) for WebTrends Reporting Center 4.0d allows remote attackers to execute arbitrary code via a long HTTP GET request to the /reports/ directory.
network
low complexity
webtrends
7.5
2001-09-20 CVE-2001-0693 Unspecified vulnerability in Webtrends products
WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20).
network
low complexity
webtrends
5.0
1999-06-29 CVE-1999-0916 Unspecified vulnerability in Webtrends products
WebTrends software stores account names and passwords in a file which does not have restricted access permissions.
local
low complexity
webtrends
2.1