Products: 1
    Vulnerabilities: 7
    Known Exploited: 0
    2
    Critical Level Threats
    0
    High Level Threats
    4
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2011-2195

    A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operating system.

    Last Modified: Nov 21, 2024
    Published: Oct 26, 2021

    CVE-2021-32305

    WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.

    Last Modified: Nov 21, 2024
    Published: May 18, 2021

    CVE-2016-1236

    Multiple cross-site scripting (XSS) vulnerabilities in (1) revision.php, (2) log.php, (3) listing.php, and (4) comp.php in WebSVN allow context-dependent attackers to inject arbitrary web script or HTML via the name of a (a) file or (b) directory in a repository.

    Last Modified: Apr 12, 2025
    Published: May 11, 2016

    CVE-2016-2511

    Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the path parameter to log.php.

    Last Modified: Apr 12, 2025
    Published: Apr 07, 2016

    CVE-2013-6892

    WebSVN 2.3.3 allows remote authenticated users to read arbitrary files via a symlink attack in a commit.

    Last Modified: Apr 12, 2025
    Published: Jan 21, 2015
    Items Per Page