CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5002 | CVE-2002-0611 | Candidate | Directory traversal vulnerability in FileSeek.cgi allows remote attackers to read arbitrary files via a ....// (modified dot dot) in the (1) head or (2) foot parameters, which are not properly filtered. | Proposed (20020611) | ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | View | |
5003 | CVE-2002-0612 | Candidate | FileSeek.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) head or (2) foot parameters. | Proposed (20020611) | ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | View | |
5005 | CVE-2002-0614 | Candidate | PHP-Survey 20000615 and earlier stores the global.inc file under the web root, which allows remote attackers to obtain sensitive information, including database credentials, if .inc files are not preprocessed by the server. | Proposed (20020611) | ACCEPT(2) Cole, Frech | NOOP(3) Cox, Foat, Wall | View | |
4797 | CVE-2002-0405 | Candidate | Buffer overflow in Transsoft Broker FTP Server 5.0 evaluation allows remote attackers to cause a denial of service and possibly execute arbitrary code via a CWD command with a large number of . (dot) characters. | Proposed (20020611) | ACCEPT(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | View | |
4799 | CVE-2002-0407 | Candidate | htcgibin.exe in Lotus Domino server 5.0.9a and earlier allows remote attackers to determine the physical pathname for the server via requests that contain certain MS-DOS device names such as com5, such as (1) a request with a .pl or .java extension, or (2) a request containing a large number of periods, which causes htcgibin.exe to leak the pathname in an error message. | Proposed (20020611) | ACCEPT(4) Alderson, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall | View |
Page 109 of 20943, showing 5 records out of 104715 total, starting on record 541, ending on 545