Vendorspi3pi3weball versions
Vulnerabilities

pi3 pi3web

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2002-0142
CGI handler in John Roy Pi3Web for Windows 2.0 beta 1 and 2 allows remote attackers to cause a denial of service (crash) via a series of requests whose physical path is exactly 260 characters long and ends in a series of . (dot) characters.
Published 2002-03-15 · Modified
7.51 PoCEPSS 0.031
CVE-2003-0276
Buffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GET request with a large number of / characters.
Published 2003-05-14 · Modified
5.02 PoCEPSS 0.114
CVE-2001-0302
Buffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL.
Published 2001-04-04 · Modified
5.01 PoCEPSS 0.070
CVE-2003-1032
Pi3Web web server 2.0.2 Beta 1, when the Directory Index is configured to use the "Name" column and sort using the column title as a hyperlink, allows remote attackers to cause a denial of service (crash) via a malformed URL to the web server, possibly involving a buffer overflow.
Published 2004-01-26 · Modified
5.01 PoCEPSS 0.036
CVE-2002-0433
Pi3Web 2.0.0 allows remote attackers to view restricted files via an HTTP request containing a "*" (wildcard or asterisk) character.
Published 2002-06-11 · Modified
5.0EPSS 0.023
CVE-2001-0303
tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to determine the physical path of the server via a URL that requests a non-existent file.
Published 2001-04-04 · Modified
5.0EPSS 0.015