Webtrends operates a modestly scoped portfolio of web analytics and enterprise reporting products, including its Reporting Center, Log Analyzer, and Enterprise Reporting Server platforms. The vendor's disclosures center on application-layer weaknesses typical of data-collection and reporting systems: sensitive-information exposure and cross-site scripting in web interfaces, alongside a tendency toward public exploit availability. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webtrends over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0595HIGH Buffer overflow in WTRS_UI.EXE (WTX_REMOTE.DLL) for WebTrends Reporting Center 4.0d allows remote attackers to execute arbitrary code via a long HTTP GET request to the /reports/ d | Jun 18, 2002 | 7.5 | 33 | NO | YES |
CVE-2004-2748MEDIUM viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid profileid parameter, which leaks | Dec 31, 2004 | 4.3 | 28 | NO | YES |
CVE-2001-0693MEDIUM WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20). | Sep 20, 2001 | 5.0 | 23 | NO | YES |
CVE-2002-0596MEDIUM WebTrends Reporting Center 4.0d allows remote attackers to determine the real path of the web server via a GET request to get_od_toc.pl with an empty Profile parameter, which leaks | Jun 18, 2002 | 5.0 | 15 | NO | NO |
CVE-2003-1583MEDIUM Cross-site scripting (XSS) vulnerability in WebTrends allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup | Feb 5, 2010 | 4.3 | 14 | NO | NO |
WebTrends software stores account names and passwords in a file which does not have restricted access permissions. | Jun 29, 1999 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webtrends.
Media articles that mention a CVE ID that affects a product developed by Webtrends — matched by CVE ID, not by vendor name.