BRS operates a narrowly scoped product portfolio centered on WebWeaver, a web application platform where its vulnerability disclosures cluster in areas classified as general or miscellaneous by formal taxonomies. While the vendor's exposure remains modestly represented in absolute terms, its documented vulnerabilities have frequently acquired public exploit code, reflecting the appeal of web application targets to security researchers and tool developers. Current exploitation activity, severity distribution, and comprehensive CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Brs over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0409HIGH Buffer overflow in BRS WebWeaver 1.04 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP (1) POST or (2) H | Jun 30, 2003 | 10.0 | 45 | NO | YES |
CVE-2004-2128MEDIUM Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as other users via the query string to ISAPISkeleton.dll. | Dec 31, 2004 | 6.8 | 27 | NO | YES |
CVE-2003-1165MEDIUM Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with a long U | Dec 31, 2003 | 5.0 | 24 | NO | YES |
CVE-2001-0452MEDIUM BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls command. | Jun 27, 2001 | 5.0 | 23 | NO | YES |
CVE-2002-1546HIGH BRS WebWeaver Web Server 1.01 allows remote attackers to bypass password protections for files and directories via an HTTP request containing a "/./" sequence. | Mar 31, 2003 | 7.5 | 20 | NO | NO |
CVE-2003-1235MEDIUM BRW WebWeaver 1.03 allows remote attackers to obtain sensitive server environment information via a URL request for testcgi.exe, which lists the values of environment variables and | Dec 31, 2003 | 5.0 | 15 | NO | NO |
CVE-2001-0453MEDIUM Directory traversal vulnerability in BRS WebWeaver HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the (1) syshelp, (2) sysimages, or (3) s | Jun 27, 2001 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Brs.
Media articles that mention a CVE ID that affects a product developed by Brs — matched by CVE ID, not by vendor name.