Vulnerabilities > Yngve Svendsen > Gnatsweb

DATE CVE VULNERABILITY TITLE RISK
2007-05-22 CVE-2007-2808 Cross-Site Scripting vulnerability in GNU GNATS Gnatsweb.PL
Cross-site scripting (XSS) vulnerability in gnatsweb.pl in Gnatsweb 4.00 and Gnats 4.1.99 allows remote attackers to inject arbitrary web script or HTML via the database parameter.
4.3
2001-12-06 CVE-2001-0808 Unspecified vulnerability in Yngve Svendsen Gnatsweb
gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter.
network
low complexity
yngve-svendsen
critical
10.0