📦

602lan_suite

Vendor: software602

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 0 Remote Access
Total CVEs 10 Total Indexed
Avg. EPSS 1.77% Exploit Prob.
Latest CVE CVE-2005-1909 Jun 09

Security Vulnerability Index

Page 1 / 1
4.3 CVSS

The web server control panel in 602LAN SUITE 2004 allows remote attackers to make it more difficult for the administrator to read portions of log files via a "</pre><!-" sequence in an HTTP GET request in the logon, possibly due to a cross-site scripting (XSS) vulnerability.

EPSS: 0.99%
6.4 CVSS
CVE-2005-1423
Exploit Found

Directory traversal vulnerability in the mail program in 602LAN SUITE 2004.0.05.0413 allows remote attackers to cause a denial of service and determine the presence of arbitrary files via .. sequences in the A parameter.

EPSS: 2.80%
5.0 CVSS
CVE-2005-0344
Exploit Found

Directory traversal vulnerability in 602LAN SUITE 2004.0.04.1221 allows remote authenticated users to upload and execute arbitrary files via a .. (dot dot) in the filename parameter.

EPSS: 2.55%
5.0 CVSS

The webmail service in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) by sending a POST request with a large Content-Length value, then disconnecting without sending that amount of data.

EPSS: 1.26%
5.0 CVSS

The Telnet proxy in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (socket exhaustion) via a Telnet request to an IP address of the proxy's network interface, which causes a loop.

EPSS: 1.26%