This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Namazu First view 2001-11-25
Product Namazu Last view 2011-12-08
Version 1.3.0.11 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:namazu:namazu

Activity : Overall

Related : CVE

  Date Alert Description
5 2011-12-08 CVE-2011-4711

Multiple directory traversal vulnerabilities in namazu.cgi in Namazu before 2.0.16 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) lang or (2) result parameter.

2.6 2011-11-29 CVE-2011-4345

Cross-site scripting (XSS) vulnerability in Namazu before 2.0.21, when Internet Explorer 6 or 7 is used, allows remote attackers to inject arbitrary web script or HTML via a cookie.

7.5 2011-11-29 CVE-2009-5028

Stack-based buffer overflow in Namazu before 2.0.20 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted request containing an empty uri field.

4.3 2008-03-24 CVE-2008-1468

Cross-site scripting (XSS) vulnerability in namazu.cgi in Namazu before 2.0.18 allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded input, related to failure to set the charset, a different vector than CVE-2004-1318 and CVE-2001-1350. NOTE: some of these details are obtained from third party information.

7.5 2001-12-27 CVE-2001-1352

Cross-site scripting vulnerability in Namazu 2.0.9 and earlier allows remote attackers to execute arbitrary Javascript as other web users via an error message that is returned when an invalid index file is specified in the idxname parameter.

7.5 2001-12-25 CVE-2001-1351

Cross-site scripting vulnerability in Namazu 2.0.8 and earlier allows remote attackers to execute arbitrary Javascript as other web users via the index file name that is displayed when displaying hit numbers.

7.5 2001-11-25 CVE-2001-1350

Cross-site scripting vulnerability in namazu.cgi for Namazu 2.0.7 and earlier allows remote attackers to execute arbitrary Javascript as other web users via the lang parameter.

CWE : Common Weakness Enumeration

%idName
50% (2) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
25% (1) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
25% (1) CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path ...

Open Source Vulnerability Database (OSVDB)

id Description
77348 Namazu result.c replace_field() Function uri Field Query Parsing Remote Overflow
77267 Namazu Unspecified XSS
43409 Namazu namazu.cgi UTF-7 XSS
22992 HP Systems Insight Manager Namazu lang Parameter Traversal Arbitrary File Access
5691 Namazu Error Message XSS
5690 Namazu Hit Number File Name XSS
5689 Namazu namazu.cgi lang Parameter XSS

OpenVAS Exploits

id Description
2009-02-16 Name : Fedora Update for namazu FEDORA-2008-2678
File : nvt/gb_fedora_2008_2678_namazu_fc7.nasl
2009-02-16 Name : Fedora Update for namazu FEDORA-2008-2767
File : nvt/gb_fedora_2008_2767_namazu_fc8.nasl

Nessus® Vulnerability Scanner

id Description
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2011-79.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: suse_11_3_namazu-111208.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: suse_11_4_namazu-111208.nasl - Type: ACT_GATHER_INFO
2013-11-29 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-201311-22.nasl - Type: ACT_GATHER_INFO
2010-04-27 Name: The remote web server has multiple vulnerabilities.
File: hpsmh_6_0_0_95.nasl - Type: ACT_GATHER_INFO
2008-08-22 Name: The remote openSUSE host is missing a security update.
File: suse_namazu-5523.nasl - Type: ACT_GATHER_INFO
2008-03-28 Name: The remote Fedora host is missing a security update.
File: fedora_2008-2678.nasl - Type: ACT_GATHER_INFO
2008-03-28 Name: The remote Fedora host is missing a security update.
File: fedora_2008-2767.nasl - Type: ACT_GATHER_INFO