CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4699  CVE-2002-0307  Candidate  Directory traversal vulnerability in ans.pl in Avenger"s News System (ANS) 2.11 and earlier allows remote attackers to determine the existence of arbitrary files or execute any Perl program on the system via a .. (dot dot) in the p parameter, which reads the target file and attempts to execute the line using Perl"s eval function.  Proposed (20020502)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:ans-plugin-execute-commands(8256)  View
4703  CVE-2002-0311  Candidate  Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi or (2) service_action.cgi.  Proposed (20020502)  ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4704  CVE-2002-0312  Candidate  Directory traversal vulnerability in Essentia Web Server 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.  Proposed (20020502)  ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4706  CVE-2002-0314  Candidate  fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message.  Proposed (20020502)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
4707  CVE-2002-0315  Candidate  fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header.  Proposed (20020502)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View

Page 136 of 20943, showing 5 records out of 104715 total, starting on record 676, ending on 680

Actions