VendorsSurfControlsuperscout_web_filter3.0.3
Vulnerabilities

SurfControl SuperScout Web Filter 3.0.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2002-0705
The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory, which allows remote attackers to obtain valid usernames and crack the passwords.
Published 2002-10-03 · Modified
7.5EPSS 0.025
CVE-2002-0709
SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary SQL queries via the RunReport option to SimpleBar.dll, and possibly other DLLs.
Published 2002-10-03 · Modified
7.51 PoCEPSS 0.011
CVE-2002-0706
UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the administrative password using a hard-coded key in a Javascript function.
Published 2002-10-03 · Modified
7.5EPSS 0.010
CVE-2002-0708
Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary files via an HTTP request containing ... (triple dot) sequences.
Published 2002-10-03 · Modified
5.01 PoCEPSS 0.035
CVE-2002-0707
The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large GET requests, possibly due to a buffer overflow.
Published 2002-10-03 · Modified
5.0EPSS 0.018