cvstrac records
3 published records for vendor cvstrac.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2004-1456Proof of concept | filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.cvstrac · cvstrac | High7.5 | — | 14.0% | Dec 31, 2004 |
18Monitor | CVE-2007-0347Proof of concept | The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticcvstrac · cvstrac | Medium4.3 | — | 3.7% | Jan 29, 2007 |
17Monitor | CVE-2004-1146No exploit | Multiple cross-site scripting (XSS) vulnerabilities in (1) main.c and (2) login.c for CVSTrac before 1.1.5 allow remote attackers to inject cvstrac · cvstrac | Medium4.3 | — | 1.4% | Dec 31, 2004 |
- CVE-2004-145634Monitor
filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.
HighCVSS 7.5Proof of conceptEPSS 14%cvstrac · cvstracDec 31, 2004
- CVE-2007-034718Monitor
The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authentic
MediumCVSS 4.3Proof of conceptEPSS 4%cvstrac · cvstracJan 29, 2007
- CVE-2004-114617Monitor
Multiple cross-site scripting (XSS) vulnerabilities in (1) main.c and (2) login.c for CVSTrac before 1.1.5 allow remote attackers to inject
MediumCVSS 4.3No exploitEPSS 1%cvstrac · cvstracDec 31, 2004