CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5096  CVE-2002-0706  Candidate  UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the administrative password using a hard-coded key in a Javascript function.  Modified (20050610)  ACCEPT(1) Baker | NOOP(4) Cole, Cox, Green, Wall    View
5097  CVE-2002-0707  Candidate  The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large GET requests, possibly due to a buffer overflow.  Modified (20071016)  ACCEPT(1) Baker | NOOP(5) Christey, Cole, Cox, Green, Wall  Christey> BID:5854 | URL:http://www.securityfocus.com/bid/5854 | XF:superscout-webfilter-get-dos(10242) | URL:http://www.iss.net/security_center/static/10242.php  View
5098  CVE-2002-0708  Candidate  Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary files via an HTTP request containing ... (triple dot) sequences.  Modified (20050610)  ACCEPT(1) Baker | NOOP(4) Cole, Cox, Green, Wall    View
5099  CVE-2002-0709  Candidate  SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary SQL queries via the RunReport option to SimpleBar.dll, and possibly other DLLs.  Modified (20050610)  ACCEPT(1) Baker | NOOP(4) Cole, Cox, Green, Wall    View
5100  CVE-2002-0710  Entry  Directory traversal vulnerability in sendform.cgi 1.44 and earlier allows remote attackers to read arbitrary files by specifying the desired files in the BlurbFilePath parameter.        View

Page 1020 of 20943, showing 5 records out of 104715 total, starting on record 5096, ending on 5100

Actions