Signedness error in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to execute arbitrary code via long (1) Username, (2) Password, or (3) Hostname entries.
2002-10-04T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | t._hauck | jana_web_server | 1.0 | Yes |
Application | t._hauck | jana_web_server | 1.45 | Yes |
Application | t._hauck | jana_web_server | 1.46 | Yes |
Application | t._hauck | jana_web_server | 2.0 | Yes |
Application | t._hauck | jana_web_server | 2.0_beta1 | Yes |
Application | t._hauck | jana_web_server | 2.0_beta2 | Yes |
Application | t._hauck | jana_web_server | 2.2.1 | Yes |