CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
716 | CVE-1999-0736 | Candidate | The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | Modified (20061101) | ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(2) Cole, Frech | NOOP(1) Baker | REVIEWING(1) Christey | Frech> XF:iis-samples-showcode | Cole> There are several sample files that allow this. I would quote | showcode.asp but make it more generic. | Prosser> (Modify) | Have a question on this and on the following three candidates as well. All | of these are part of the file viewers utilities that allow unauthorized | files reading, but MSKB Q231368 also mentioned the diagnostics | program,Winmsdp.exe, as another vulnerable viewer in this same set of | viewers. If we are going to split out the seperate viewer tools then | shouldn"t there should be a seperate CAN for Winmsdp.exe also. | Christey> Mike"s question basically touches on the CD:SF-EXEC | content decision - what do you do when you have the same bug | in multiple executables? CD:SF-EXEC needs to be reviewed | and approved by the Editorial Board before we can decide | what to do with this candidate. | Christey> Mark Burnett says that Microsoft"s mention of winmsdp.exe in | MSKB:Q231368 may be an error, and that winmsdp.exe is a | Microsoft Diagnostics Report Generator which may not even | be installed as part of IIS. | | Also see http://www.securityfocus.com/focus/microsoft/iis/showcode.html | Christey> ADDREF BID:167 | URL:http://www.securityfocus.com/vdb/bottom.html?vid=167 | Christey> MISC:http://p.ulh.as/xploitsdb/NT/iis38.html covers a showcode.asp | directory traversal vulnerability and refers to the L0pht advisory. | | Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317 | View |
717 | CVE-1999-0737 | Candidate | The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | Proposed (19991208) | ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Cole | Frech> XF:iis-samples-viewcode | Cole> I would combine this with the previous. | Prosser> (modify) | See comments in 0736 above | Christey> See http://www.securityfocus.com/focus/microsoft/iis/showcode.html | for additional details. | Christey> Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317 | View |
718 | CVE-1999-0738 | Candidate | The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | Proposed (19991208) | ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Cole | Frech> XF:iis-samples-code | Cole> Same as above | Prosser> (modify) | See comments in 0736 above | Christey> See http://www.securityfocus.com/focus/microsoft/iis/showcode.html | for additional details. | Christey> Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317 | View |
719 | CVE-1999-0739 | Candidate | The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | Proposed (19991208) | ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Cole | Frech> XF:iis-samples-codebrws | Cole> Same as above. | Prosser> (modify) | See comments in 0736 above | Christey> codebrw2.asp and Codebrw1.asp also need to be included | somewhere. | | Also see http://www.securityfocus.com/focus/microsoft/iis/showcode.html | Christey> Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317 | View |
720 | CVE-1999-0740 | Entry | Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable. | View |
Page 144 of 20943, showing 5 records out of 104715 total, starting on record 716, ending on 720