CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Surfcontrol 2Superscout Web Filter Web FilterApr 16, 2026 Oct 10, 2002 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary SQL queries via the RunReport option to SimpleBar.dll, and possibly other DLLs. |
1Surfcontrol 2Superscout Web Filter Web FilterApr 16, 2026 Oct 10, 2002 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary files via an HTTP request containing ... (triple dot) sequences. |
1Surfcontrol 2Superscout Web Filter Web FilterApr 16, 2026 Oct 10, 2002 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large GET requests, possibly due to a buffer overflow. |
1Surfcontrol 2Superscout Web Filter Web FilterApr 16, 2026 Oct 10, 2002 N/A· v4 N/A· v3 7.5 HIGH· v2 UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the administrative password using a hard-coded key...Show more |
1Surfcontrol 2Superscout Web Filter Web FilterApr 16, 2026 Oct 10, 2002 N/A· v4 N/A· v3 7.5 HIGH· v2 The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory, which allows remote attackers to obtain valid usernames and crack the password...Show more |