VendorsOmnicronomnihttpdall versions
Vulnerabilities

Omnicron Omnihttpd

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2001-0113
statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to execute arbitrary commands via the mostbrowsers parameter, whose value is used as part of a generated Perl script.
Published 2001-02-14 · Modified
10.01 PoCEPSS 0.104
CVE-1999-0951
Buffer overflow in OmniHTTPd CGI program imagemap.exe allows remote attackers to execute commands.
Published 2000-01-04 · Modified
10.01 PoCEPSS 0.100
CVE-2004-2299
Buffer overflow in Omnicron OmniHTTPd 3.0a and earlier allows remote attackers to execute arbitrary code via an HTTP GET request with a long Range header.
Published 2005-08-05 · Modified
7.51 PoCEPSS 0.102
CVE-2001-0778
OmniHTTPd 2.0.8 and earlier allow remote attackers to obtain source code via a GET request with the URL-encoded symbol for a space (%20).
Published 2001-10-12 · Modified
5.01 PoCEPSS 0.063
CVE-1999-0970
The OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number of temporary files to be created.
Published 2000-02-04 · Modified
5.01 PoCEPSS 0.032
CVE-2001-0114
statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter.
Published 2001-02-14 · Modified
5.01 PoCEPSS 0.020
CVE-2001-0613
Omnicron Technologies OmniHTTPD Professional 2.08 and earlier allows a remote attacker to create a denial of service via a long POST URL request.
Published 2002-03-09 · Modified
5.0EPSS 0.017
CVE-2001-0777
Omnicron OmniHTTPd 2.0.8 allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests for PHP scripts.
Published 2001-10-12 · Modified
5.0EPSS 0.017
CVE-2002-1035
Omnicron OmniHTTPd 2.09 allows remote attackers to cause a denial of service (crash) via an HTTP request with a long, malformed HTTP 1version number.
Published 2003-04-02 · Modified
5.0EPSS 0.016
CVE-2002-1455
Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.
Published 2003-03-18 · Modified
4.32 PoCEPSS 0.039