CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5161  CVE-2002-0771  Candidate  Cross-site scripting vulnerability in viewcvs.cgi for ViewCVS 0.9.2 allows remote attackers to inject script and steal cookies via the (1) cvsroot or (2) sortby parameters.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5162  CVE-2002-0772  Candidate  Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories via a .. (dot dot) in the RootName parameter.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5163  CVE-2002-0773  Candidate  imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imp_rootdir.asp and modifying parameters such as (1) ftp, (2) owwwPath, and (3) oftpPath.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5164  CVE-2002-0774  Candidate  Hosting Controller creates a default user AdvWebadmin with a default password, which could allow remote attackers to gain privileges if the password is not changed.  Proposed (20020726)  ACCEPT(1) Cole | NOOP(4) Armstrong, Cox, Foat, Wall    View
5165  CVE-2002-0775  Candidate  browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter.  Proposed (20020726)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(3) Cox, Foat, Wall    View

Page 1033 of 20943, showing 5 records out of 104715 total, starting on record 5161, ending on 5165

Actions