Vulnerabilities (CVE)

Filtered by vendor Mnscu Pals Subscribe
Filtered by product Webpals
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0216 1 Mnscu Pals 1 Webpals 2024-02-28 7.5 HIGH N/A
PALS Library System pals-cgi program allows remote attackers to execute arbitrary commands via shell metacharacters in the documentName parameter.
CVE-2001-0217 1 Mnscu Pals 1 Webpals 2024-02-28 5.0 MEDIUM N/A
Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter.