CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4144  CVE-2001-1340  Candidate  Beck GmbH IPC@Chip TelnetD service supports only one connection and does not disconnect a user who does not complete the login process, which allows remote attackers to lock out the administrator account by connecting to the service.  Proposed (20020502)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall    View
4145  CVE-2001-1341  Candidate  The Beck GmbH IPC@Chip embedded web server installs the chipcfg.cgi program by default, which allows remote attackers to obtain sensitive network information via a request to the program.  Proposed (20020502)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall    View
4658  CVE-2002-0266  Candidate  Thunderstone Texis CGI script allows remote attackers to obtain the full path of the web root via a request for a nonexistent file, which generates an error message that includes the full pathname.  Proposed (20020502)  ACCEPT(3) Armstrong, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4147  CVE-2001-1343  Candidate  ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter.  Proposed (20020502)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall  Green> As this vulnerability requires the exploiter to have an authenticated administrative login, is it an oxymoron?  View
4148  CVE-2001-1344  Candidate  WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot).  Proposed (20020502)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall    View

Page 131 of 20943, showing 5 records out of 104715 total, starting on record 651, ending on 655

Actions