CVE List

Id CVE No. Status Description Phase Votes Comments Actions
285  CVE-1999-0286  Candidate  In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.  Proposed (19990714)  ACCEPT(3) Armstrong, Cole, Shostack | MODIFY(3) Blake, Levy, Wall | NOOP(5) Baker, Bishop, Landfield, Northcutt, Ozancin | REJECT(1) Frech | REVIEWING(1) Christey  Wall> In some NT web servers, appending a dot at the end of a URL may | allows attackers to read source code for active pages. | Source: MS Knowledge Base Article Q163485 - "Active Server Pages Script Appears | in Browser" | Frech> In the meantime, reword description as "Windows NT" (trademark issue) | Christey> Q163485 does not refer to a space, it refers to a dot. | However, I don"t have other references. | | Reading source code with a dot appended is in CVE-1999-0154, | which will be proposed. A subsequent bug similar to the | dot bug is CVE-1999-0253. | Levy> NTBUGTRAQ: http://www.securityfocus.com/archive/2/22014 | NTBUGTRAQ: http://www.securityfocus.com/archive/2/22019 | BID 273 | Blake> Reference: http://www.allaire.com/handlers/index.cfm?ID=10967 | CHANGE> [Christey changed vote from NOOP to REVIEWING] | CHANGE> [Frech changed vote from REVIEWING to REJECT] | Frech> BID articles)  View
475  CVE-1999-0477  Candidate  The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.  Modified (19991210-01)  ACCEPT(4) Baker, Christey, Frech, Ozancin | REJECT(1) Wall  Wall> Duplicate of 0455 | Christey> CVE-1999-0477 and CVE-1999-0455 were discovered at different | times. Also, the attack was different. So "Same Attack" and | "Same Time of Discovery" dictate that these should remain | separate.  View
539  CVE-1999-0549  Candidate  Windows NT automatically logs in an administrator upon rebooting.  Proposed (19990630)  ACCEPT(1) Hill | MODIFY(3) Blake, Frech, Ozancin | NOOP(1) Wall | REJECT(1) Baker  Wall> Don"t know what this is. Don"t think it is a vulnerability and would | initially reject. This is different than just renaming the | administrator account. | Frech> Would appreciate more information on this one, as in a reference. | Blake> Reference: XF:nt-autologin | Ozancin> Needs more detail | Baker> I tried to find the XF:nt-autologin reference, and got no matching records from their search engine. | No refs, no details, should reject | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:nt-autologon(5)  View
641  CVE-1999-0659  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A Windows NT Primary Domain Controller (PDC) or Backup Domain Controller (BDC) is present."  Modified (20080731)  REJECT(3) Baker, Northcutt, Wall  Wall> Don"t consider this a service or a problem. | Baker> concur with wall on this  View
228  CVE-1999-0229  Candidate  Denial of service in Windows NT IIS server using ....  Modified (19991228-02)  ACCEPT(2) Baker, Shostack | MODIFY(2) Frech, Wall | NOOP(1) Northcutt | REJECT(1) Christey | REVIEWING(1) Levy  Wall> Denial of service in Windows NT IIS Server 1.0 using ..... | Source: Microsoft Knowledge Base Article Q115052 - IIS Server. | Frech> XF:http-dotdot (not necessarily IIS?) | Christey> DELREF XF:http-dotdot - it deals with a read/access dot dot | problem. | Christey> This actually looks like XF:iis-dot-dot-crash(1638) | http://xforce.iss.net/static/1638.php | If so, include the version number (2.0) | | CHANGE> [Christey changed vote from REVOTE to REJECT] | Christey> Bill Wall intended to suggest Q155052, but the affected | IIS version there is 1.0; the effect is to read files, | so this sounds like a directory traversal problem, | instead of an inability to process certain strings. | | As a result, this candidate is too general, since it could | apply to 2 different problems, so it should be REJECTed. | Christey> Consider adding BID:2218  View

Page 10 of 20943, showing 5 records out of 104715 total, starting on record 46, ending on 50

<<first 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 last>>

Actions