CVE List

Id CVE No. Status Description Phase Votes Comments Actions
716  CVE-1999-0736  Candidate  The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.  Modified (20061101)  ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(2) Cole, Frech | NOOP(1) Baker | REVIEWING(1) Christey  Frech> XF:iis-samples-showcode | Cole> There are several sample files that allow this. I would quote | showcode.asp but make it more generic. | Prosser> (Modify) | Have a question on this and on the following three candidates as well. All | of these are part of the file viewers utilities that allow unauthorized | files reading, but MSKB Q231368 also mentioned the diagnostics | program,Winmsdp.exe, as another vulnerable viewer in this same set of | viewers. If we are going to split out the seperate viewer tools then | shouldn"t there should be a seperate CAN for Winmsdp.exe also. | Christey> Mike"s question basically touches on the CD:SF-EXEC | content decision - what do you do when you have the same bug | in multiple executables? CD:SF-EXEC needs to be reviewed | and approved by the Editorial Board before we can decide | what to do with this candidate. | Christey> Mark Burnett says that Microsoft"s mention of winmsdp.exe in | MSKB:Q231368 may be an error, and that winmsdp.exe is a | Microsoft Diagnostics Report Generator which may not even | be installed as part of IIS. | | Also see http://www.securityfocus.com/focus/microsoft/iis/showcode.html | Christey> ADDREF BID:167 | URL:http://www.securityfocus.com/vdb/bottom.html?vid=167 | Christey> MISC:http://p.ulh.as/xploitsdb/NT/iis38.html covers a showcode.asp | directory traversal vulnerability and refers to the L0pht advisory. | | Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317  View
717  CVE-1999-0737  Candidate  The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.  Proposed (19991208)  ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Cole  Frech> XF:iis-samples-viewcode | Cole> I would combine this with the previous. | Prosser> (modify) | See comments in 0736 above | Christey> See http://www.securityfocus.com/focus/microsoft/iis/showcode.html | for additional details. | Christey> Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317  View
718  CVE-1999-0738  Candidate  The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.  Proposed (19991208)  ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Cole  Frech> XF:iis-samples-code | Cole> Same as above | Prosser> (modify) | See comments in 0736 above | Christey> See http://www.securityfocus.com/focus/microsoft/iis/showcode.html | for additional details. | Christey> Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317  View
719  CVE-1999-0739  Candidate  The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.  Proposed (19991208)  ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Cole  Frech> XF:iis-samples-codebrws | Cole> Same as above. | Prosser> (modify) | See comments in 0736 above | Christey> codebrw2.asp and Codebrw1.asp also need to be included | somewhere. | | Also see http://www.securityfocus.com/focus/microsoft/iis/showcode.html | Christey> Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317  View
720  CVE-1999-0740  Entry  Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable.        View

Page 144 of 20943, showing 5 records out of 104715 total, starting on record 716, ending on 720

Actions