CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6126  CVE-2002-1744  Candidate  Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and determine the existence of arbitrary files via a hex-encoded "%c0%ae%c0%ae" string, which is the Unicode representation for ".." (dot dot).  Assigned (20050621)  None (candidate not yet proposed)    View
6127  CVE-2002-1745  Candidate  Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code for files with extensions containing with one additional character after .html, .htm, .asp, or .inc, such as .aspx files.  Assigned (20050621)  None (candidate not yet proposed)    View
6128  CVE-2002-1746  Candidate  Vtun 2.5b1 allows remote attackers to inject data into user sessions by sniffing and replaying packets.  Assigned (20050621)  None (candidate not yet proposed)    View
6129  CVE-2002-1747  Candidate  Vtun 2.5b1 does not authenticate forwarded packets, which allows remote attackers to inject data into user sessions without detection, and possibly control the data contents via cut-and-paste attacks on ECB.  Assigned (20050621)  None (candidate not yet proposed)    View
6130  CVE-2002-1748  Candidate  Unknown vulnerability in Slash 2.1.x and 2.2 through 2.2.2, as used in Slashcode, allows remote authenticated users to gain access to arbitrary accounts.  Assigned (20050621)  None (candidate not yet proposed)    View

Page 1226 of 20943, showing 5 records out of 104715 total, starting on record 6126, ending on 6130

Actions