CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4650  CVE-2002-0258  Candidate  Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access to the ID to gain privileges as that user, e.g. by extracting the ID from the user"s answer or forward URLs.  Proposed (20020502)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:icewarp-static-sessionid(9807)  View
4139  CVE-2001-1335  Candidate  Directory traversal vulnerability in CesarFTP 0.98b and earlier allows remote authenticated users (such as anonymous) to read arbitrary files via a GET with a filename that contains a ...%5c (modified dot dot).  Proposed (20020502)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall    View
4651  CVE-2002-0259  Candidate  InstantServers MiniPortal 1.1.5 and earlier stores sensitive login and account data in plaintext in (1) .pwd files in the miniportal/apache directory, or (2) mplog.txt, which could allow local users to gain privileges.  Proposed (20020502)  ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall    View
4140  CVE-2001-1336  Candidate  CesarFTP 0.98b and earlier stores usernames and passwords in plaintext in the settings.ini file, which allows attackers to gain privileges.  Proposed (20020502)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall    View
4652  CVE-2002-0260  Candidate  Buffer overflow in InstantServers MiniPortal 1.1.5 and earlier allows remote attackers to execute arbitrary code via a long login name, which is not properly handled by the logging utility.  Proposed (20020502)  ACCEPT(3) Armstrong, Cole, Frech | NOOP(3) Cox, Foat, Wall    View

Page 129 of 20943, showing 5 records out of 104715 total, starting on record 641, ending on 645

Actions