← Back

Chilisoft

chilisoft

Vendor: Sun • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sun
1Chilisoft
Apr 16, 2026
Aug 22, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Sun Chili!Soft ASP has weak permissions on various configuration files, which allows a local attacker to gain additional privileges and create a denial of service.
1Sun
1Chilisoft
Apr 16, 2026
Aug 22, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Sun Chili!Soft ASP on multiple Unixes allows a remote attacker to read arbitrary files above the web root via a '..' (dot dot) attack in the sample script 'codebrws.asp'.
1Sun
1Chilisoft
Apr 16, 2026
Aug 22, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges.
1Sun
1Chilisoft
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Chili!Soft ASP for Linux before 3.6 does not properly set group privileges when running in inherited mode, which could allow attackers to gain privileges via malicious scripts.