This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Sawmill First view 2002-05-29
Product Sawmill Last view 2013-07-29
Version 6.2.5 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:sawmill:sawmill

Activity : Overall

Related : CVE

  Date Alert Description
7.5 2013-07-29 CVE-2013-4947

Unspecified vulnerability in the update and build database page in Sawmill before 8.6.3 allows remote attackers to have unknown impact and attack vectors.

4.3 2010-03-23 CVE-2010-1079

Cross-site scripting (XSS) vulnerability in Sawmill before 7.2.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

4.3 2005-06-09 CVE-2005-1901

Multiple cross-site scripting (XSS) vulnerabilities in Sawmill before 7.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) the username in the Add User window or (2) the license key in the Licensing page.

7.5 2005-06-09 CVE-2005-1900

Sawmill before 7.1.6 allows remote attackers to bypass authentication and (1) gain administrative privileges or (2) add a license.

4.6 2002-05-29 CVE-2002-0265

Sawmill for Solaris 6.2.14 and earlier creates the AdminPassword file with world-writable permissions, which allows local users to gain privileges by modifying the file.

CWE : Common Weakness Enumeration

%idName
100% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')

CAPEC : Common Attack Pattern Enumeration & Classification

id Name
CAPEC-19 Embedding Scripts within Scripts
CAPEC-81 Web Logs Tampering

Open Source Vulnerability Database (OSVDB)

id Description
62537 Sawmill Unspecified XSS
17103 Sawmill Licensing Page license key Field XSS
17102 Sawmill Add User Window username Field XSS
17101 Sawmill Unauthorized License Addition
17100 Sawmill Unspecified Remote Administrative Privilege Escalation
2044 Sawmill AdminPassword Insecure Default Permissions

OpenVAS Exploits

id Description
2010-02-24 Name : Sawmill Unspecified Cross Site Scripting Vulnerability
File : nvt/sawmill_38387.nasl

Nessus® Vulnerability Scanner

id Description
2005-06-17 Name: An application running on the remote web server is affected by multiple vulne...
File: sawmill_priv_escalation.nasl - Type: ACT_GATHER_INFO