webtrends records
6 published records for vendor webtrends.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
33Monitor | CVE-2002-0595Proof of concept | Buffer overflow in WTRS_UI.EXE (WTX_REMOTE.DLL) for WebTrends Reporting Center 4.0d allows remote attackers to execute arbitrary code via a webtrends · reporting center | High7.5 | — | 10.7% | Jun 18, 2002 |
21Monitor | CVE-2001-0693Proof of concept | WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20).webtrends · webtrends enterprise reporting server | Medium5.0 | — | 3.1% | Sep 20, 2001 |
20Monitor | CVE-2002-0596No exploit | WebTrends Reporting Center 4.0d allows remote attackers to determine the real path of the web server via a GET request to get_od_toc.pl withwebtrends · reporting center · CWE-200 | Medium5.0 | — | 1.5% | Jun 18, 2002 |
18Monitor | CVE-2004-2748Proof of concept | viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an webtrends · reporting center · CWE-200 | Medium4.3 | — | 4.8% | Dec 31, 2004 |
17Monitor | CVE-2003-1583No exploit | Cross-site scripting (XSS) vulnerability in WebTrends allows remote attackers to inject arbitrary web script or HTML via a crafted client dowebtrends · webtrends log analyzer · CWE-79 | Medium4.3 | — | 0.9% | Feb 5, 2010 |
8Monitor | CVE-1999-0916No exploit | WebTrends software stores account names and passwords in a file which does not have restricted access permissions.webtrends · webtrends enterprise suite | Low2.1 | — | 0.4% | Jun 29, 1999 |
- CVE-2002-059533Monitor
Buffer overflow in WTRS_UI.EXE (WTX_REMOTE.DLL) for WebTrends Reporting Center 4.0d allows remote attackers to execute arbitrary code via a
HighCVSS 7.5Proof of conceptEPSS 11%webtrends · reporting centerJun 18, 2002
- CVE-2001-069321Monitor
WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20).
MediumCVSS 5.0Proof of conceptEPSS 3%webtrends · webtrends enterprise reporting serverSep 20, 2001
- CVE-2002-059620Monitor
WebTrends Reporting Center 4.0d allows remote attackers to determine the real path of the web server via a GET request to get_od_toc.pl with
MediumCVSS 5.0No exploitEPSS 2%webtrends · reporting centerJun 18, 2002
- CVE-2004-274818Monitor
viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an
MediumCVSS 4.3Proof of conceptEPSS 5%webtrends · reporting centerDec 31, 2004
- CVE-2003-158317Monitor
Cross-site scripting (XSS) vulnerability in WebTrends allows remote attackers to inject arbitrary web script or HTML via a crafted client do
MediumCVSS 4.3No exploitEPSS 1%webtrends · webtrends log analyzerFeb 5, 2010
- CVE-1999-09168Monitor
WebTrends software stores account names and passwords in a file which does not have restricted access permissions.
LowCVSS 2.1No exploitEPSS 0%webtrends · webtrends enterprise suiteJun 29, 1999