Vulnerabilities (CVE)

Filtered by vendor Snapstream Subscribe
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-1108 1 Snapstream 1 Pvs 2024-02-04 7.5 HIGH N/A
Directory traversal vulnerability in SnapStream PVS 1.2a allows remote attackers to read arbitrary files via a .. (dot dot) attack in the requested URL.
CVE-2004-0046 1 Snapstream 1 Snapstream Pvs 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script or HTML via a GET request containing a terminating '"' (double quote) character.
CVE-2001-1107 1 Snapstream 1 Pvs 2024-02-04 5.0 MEDIUM N/A
SnapStream PVS 1.2a stores its passwords in plaintext in the file SSD.ini, which could allow a remote attacker to gain privileges on the server.