CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6126 | CVE-2002-1744 | Candidate | Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and determine the existence of arbitrary files via a hex-encoded "%c0%ae%c0%ae" string, which is the Unicode representation for ".." (dot dot). | Assigned (20050621) | None (candidate not yet proposed) | View | |
6127 | CVE-2002-1745 | Candidate | Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code for files with extensions containing with one additional character after .html, .htm, .asp, or .inc, such as .aspx files. | Assigned (20050621) | None (candidate not yet proposed) | View | |
6128 | CVE-2002-1746 | Candidate | Vtun 2.5b1 allows remote attackers to inject data into user sessions by sniffing and replaying packets. | Assigned (20050621) | None (candidate not yet proposed) | View | |
6129 | CVE-2002-1747 | Candidate | Vtun 2.5b1 does not authenticate forwarded packets, which allows remote attackers to inject data into user sessions without detection, and possibly control the data contents via cut-and-paste attacks on ECB. | Assigned (20050621) | None (candidate not yet proposed) | View | |
6130 | CVE-2002-1748 | Candidate | Unknown vulnerability in Slash 2.1.x and 2.2 through 2.2.2, as used in Slashcode, allows remote authenticated users to gain access to arbitrary accounts. | Assigned (20050621) | None (candidate not yet proposed) | View |
Page 1226 of 20943, showing 5 records out of 104715 total, starting on record 6126, ending on 6130