← Back

Webtrends

webtrends

6 CVEs • 8 products

Products (8)

Click to collapse
Toggle

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webtrends
1Webtrends Log Analyzer
Apr 29, 2026
Feb 5, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in WebTrends allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
1Webtrends
1Reporting Center
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
4.3 MEDIUM· v2
viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid profileid parameter, which leaks the pathname in an error message.
1Webtrends
1Reporting Center
Apr 16, 2026
Jun 18, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
WebTrends Reporting Center 4.0d allows remote attackers to determine the real path of the web server via a GET request to get_od_toc.pl with an empty Profile parameter, which leaks the pathname in an error message.
1Webtrends
1Reporting Center
Apr 16, 2026
Jun 18, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in WTRS_UI.EXE (WTX_REMOTE.DLL) for WebTrends Reporting Center 4.0d allows remote attackers to execute arbitrary code via a long HTTP GET request to the /reports/ directory.
1Webtrends
2Webtrends Enterprise Reporting Server
Webtrends Enterprise Reporting Server Nt
Apr 16, 2026
Sep 20, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20).
1Webtrends
5Webtrends Enterprise Suite
Webtrends For FirewallsWebtrends Log Analyzer+2 more
Apr 16, 2026
Jun 29, 1999
N/A· v4
N/A· v3
2.1 LOW· v2
WebTrends software stores account names and passwords in a file which does not have restricted access permissions.