SolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product's web server.
Multiple directory traversal vulnerabilities in (1) modevhost and (2) modsimplevhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to requestcheckhostname.