CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4650 | CVE-2002-0258 | Candidate | Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access to the ID to gain privileges as that user, e.g. by extracting the ID from the user"s answer or forward URLs. | Proposed (20020502) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:icewarp-static-sessionid(9807) | View |
4139 | CVE-2001-1335 | Candidate | Directory traversal vulnerability in CesarFTP 0.98b and earlier allows remote authenticated users (such as anonymous) to read arbitrary files via a GET with a filename that contains a ...%5c (modified dot dot). | Proposed (20020502) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | View | |
4651 | CVE-2002-0259 | Candidate | InstantServers MiniPortal 1.1.5 and earlier stores sensitive login and account data in plaintext in (1) .pwd files in the miniportal/apache directory, or (2) mplog.txt, which could allow local users to gain privileges. | Proposed (20020502) | ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall | View | |
4140 | CVE-2001-1336 | Candidate | CesarFTP 0.98b and earlier stores usernames and passwords in plaintext in the settings.ini file, which allows attackers to gain privileges. | Proposed (20020502) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | View | |
4652 | CVE-2002-0260 | Candidate | Buffer overflow in InstantServers MiniPortal 1.1.5 and earlier allows remote attackers to execute arbitrary code via a long login name, which is not properly handled by the logging utility. | Proposed (20020502) | ACCEPT(3) Armstrong, Cole, Frech | NOOP(3) Cox, Foat, Wall | View |
Page 129 of 20943, showing 5 records out of 104715 total, starting on record 641, ending on 645