CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4800 | CVE-2002-0408 | Candidate | htcgibin.exe in Lotus Domino server 5.0.9a and earlier, when configured with the NoBanner setting, allows remote attackers to determine the version number of the server via a request that generates an HTTP 500 error code, which leaks the version in a hard-coded error message. | Proposed (20020611) | ACCEPT(1) Alderson | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:lotus-domino-reveal-information(8160) | View |
4801 | CVE-2002-0409 | Candidate | orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter. | Proposed (20020611) | ACCEPT(2) Alderson, Wall | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Frech | Alderson> This is a whole new breed of exposure... vulnerable example code | leading to cross industry and application exposure. This to a point made by | Gene Kim recently "they keep deploying problems faster than we can deploy | solutions". | View |
4802 | CVE-2002-0410 | Candidate | send_message.php in AeroMail before 1.45 allows remote attackers to read arbitrary files on the server, instead of just uploaded files, via an attachment that modifies the filename to be uploaded. | Proposed (20020611) | ACCEPT(4) Alderson, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall | View | |
4803 | CVE-2002-0411 | Candidate | Cross-site scripting vulnerability in message.php for AeroMail before 1.45 allows remote attackers to execute Javascript as an AeroMail user via an email message with the script in the Subject line. | Proposed (20020611) | ACCEPT(4) Alderson, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall | View | |
4805 | CVE-2002-0413 | Candidate | Cross-site scripting vulnerability in ReBB allows remote attackers to execute arbitrary Javascript and steal cookies via an IMG tag whose URL includes the malicious script. | Proposed (20020611) | ACCEPT(2) Alderson, Frech | NOOP(4) Cole, Cox, Foat, Wall | View |
Page 110 of 20943, showing 5 records out of 104715 total, starting on record 546, ending on 550