MidnightBSD

Advisories for asksam_systems

CVE-2002-1727 MEDIUM

Cross-site scripting vulnerability (XSS) in (1) as_web.exe and (2) as_web4.exe in askSam Web Publisher 1 and 4 allows remote attackers to execute arbitrary script as other users via a URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
asksam_systems asksam_web_publisher 1.0
asksam_systems asksam_web_publisher 4.0
CVE-2002-1728 MEDIUM

askSam Web Publisher 1.0 and 4.0 allows remote attackers to determine the full path to the web root directory via a request for a file that does not exist, which generates an error message that reveals the full path.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
asksam_systems asksam_web_publisher 1.0
asksam_systems asksam_web_publisher 4.0