Webweaver
Vendor:
First CVE: Jun 27, 2001 · Active for 25 years
7
Total CVEs
More Total CVEs than 83% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Webweaver over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2001
25 years ago
Most Recent CVE
Dec 31, 2004
7,875 days ago
CVE Severity & Scoring
Webweaver7 CVEs
71%
29%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown7 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown7 (100.0%)
User Interaction
None0 (0.0%)
Unknown7 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown7 (100.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0409HIGH Buffer overflow in BRS WebWeaver 1.04 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP (1) POST or (2) H | Jun 30, 2003 | 10.0 | 45 | NO | YES |
CVE-2004-2128MEDIUM Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as other users via the query string to ISAPISkeleton.dll. | Dec 31, 2004 | 6.8 | 27 | NO | YES |
CVE-2003-1165MEDIUM Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with a long U | Dec 31, 2003 | 5.0 | 24 | NO | YES |
CVE-2001-0452MEDIUM BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls command. | Jun 27, 2001 | 5.0 | 23 | NO | YES |
CVE-2002-1546HIGH BRS WebWeaver Web Server 1.01 allows remote attackers to bypass password protections for files and directories via an HTTP request containing a "/./" sequence. | Mar 31, 2003 | 7.5 | 20 | NO | NO |
CVE-2003-1235MEDIUM BRW WebWeaver 1.03 allows remote attackers to obtain sensitive server environment information via a URL request for testcgi.exe, which lists the values of environment variables and | Dec 31, 2003 | 5.0 | 15 | NO | NO |
CVE-2001-0453MEDIUM Directory traversal vulnerability in BRS WebWeaver HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the (1) syshelp, (2) sysimages, or (3) s | Jun 27, 2001 | 5.0 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
57.1% of CVEs· 93rd percentile
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Webweaver
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.0.6 | 1 | 5.0 | 5.6% | 0 | 1 |
| 1.0.5 | 1 | 5.0 | 5.6% | 0 | 1 |
| 1.0.4 | 2 | 7.5 | 6.8% | 0 | 2 |
| 1.0.3 | 1 | 5.0 | 5.6% | 0 | 1 |
| 1.0.2 | 1 | 5.0 | 5.6% | 0 | 1 |
| 1.0.1 | 2 | 6.3 | 3.7% | 0 | 1 |
| 0.63_beta | 1 | 5.0 | 5.6% | 0 | 1 |
| 0.62_beta | 3 | 5.0 | 3.6% | 0 | 2 |
| 0.61_beta | 3 | 5.0 | 3.6% | 0 | 2 |
| 0.60_beta | 3 | 5.0 | 3.6% | 0 | 2 |
| 0.52_beta | 3 | 5.0 | 3.6% | 0 | 2 |
| 0.51_beta | 3 | 5.0 | 3.6% | 0 | 2 |
| 0.50_beta | 3 | 5.0 | 3.6% | 0 | 2 |
| 0.49_beta | 3 | 5.0 | 3.6% | 0 | 2 |