VendorsGeeos Teamgattaca_server_2003all versions
Vulnerabilities

Geeos Team Gattaca Server 2003

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2004-2519
Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specifiers in the LANGUAGE parameter to (1) index.tmpl and (2) web.tmpl, such as (a) slash "/", (b) backslash "\", (c) dot ".",, (d) dot dot "..", and (e) internal slash "lang//en".
Published 2005-10-25 · Modified
5.01 PoCEPSS 0.080
CVE-2004-2518
Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00") to a URL or (2) an invalid LANGUAGE parameter to web.tmpl, which reveals the full installation path in an error message.
Published 2005-10-25 · Modified
5.02 PoCEPSS 0.045
CVE-2004-2521
Mail server in Gattaca Server 2003 1.1.10.0 allows remote attackers to perform a denial of service (application crash) via a large number of connections to TCP port (1) 25 (SMTP) or (2) 110 (POP).
Published 2005-10-25 · Modified
5.0EPSS 0.018
CVE-2004-2522
Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject arbitrary web script or HTML via the (1) template or (2) language parameter.
Published 2005-10-25 · Modified
4.31 PoCEPSS 0.040
CVE-2004-2520
POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (application crash) via a large numeric value in the (1) LIST, (2) RETR, or (3) UIDL commands.
Published 2005-10-25 · Modified
4.01 PoCEPSS 0.033