CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5002  CVE-2002-0611  Candidate  Directory traversal vulnerability in FileSeek.cgi allows remote attackers to read arbitrary files via a ....// (modified dot dot) in the (1) head or (2) foot parameters, which are not properly filtered.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
5003  CVE-2002-0612  Candidate  FileSeek.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) head or (2) foot parameters.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
5005  CVE-2002-0614  Candidate  PHP-Survey 20000615 and earlier stores the global.inc file under the web root, which allows remote attackers to obtain sensitive information, including database credentials, if .inc files are not preprocessed by the server.  Proposed (20020611)  ACCEPT(2) Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4797  CVE-2002-0405  Candidate  Buffer overflow in Transsoft Broker FTP Server 5.0 evaluation allows remote attackers to cause a denial of service and possibly execute arbitrary code via a CWD command with a large number of . (dot) characters.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
4799  CVE-2002-0407  Candidate  htcgibin.exe in Lotus Domino server 5.0.9a and earlier allows remote attackers to determine the physical pathname for the server via requests that contain certain MS-DOS device names such as com5, such as (1) a request with a .pl or .java extension, or (2) a request containing a large number of periods, which causes htcgibin.exe to leak the pathname in an error message.  Proposed (20020611)  ACCEPT(4) Alderson, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View

Page 109 of 20943, showing 5 records out of 104715 total, starting on record 541, ending on 545

Actions