WebSVN 2.3.2

CPE Details

WebSVN 2.3.2
2.3.2
2012-10-26
12h51 +00:00
2012-10-26
16h20 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:websvn:websvn:2.3.2:*:*:*:*:*:*:*

Informations

Vendor

websvn

Product

websvn

Version

2.3.2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2011-2195 2021-10-26 10h10 +00:00 A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operating system.
9.8
Critical
CVE-2021-32305 2021-05-18 14h11 +00:00 WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.
9.8
Critical
CVE-2016-1236 2016-05-11 19h00 +00:00 Multiple cross-site scripting (XSS) vulnerabilities in (1) revision.php, (2) log.php, (3) listing.php, and (4) comp.php in WebSVN allow context-dependent attackers to inject arbitrary web script or HTML via the name of a (a) file or (b) directory in a repository.
6.1
Medium
CVE-2016-2511 2016-04-07 19h00 +00:00 Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the path parameter to log.php.
6.1
Medium