Vulnerabilities (CVE)

Filtered by vendor Andrey Cherezov Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-2421 1 Andrey Cherezov 1 Acweb 2024-02-28 7.8 HIGH N/A
acWEB 1.14 allows remote attackers to cause a denial of service (crash) via an HTTP request for a MS-DOS device name such as COM2.
CVE-2002-2171 1 Andrey Cherezov 1 Acweb 2024-02-28 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in acWEB 1.8 and 1.14 allows remote attackers to insert arbitrary HTML and web script via a URL, possibly via a "%db" request in a URL.