CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1704  CVE-2000-0126  Candidate  Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack.  Proposed (20000208)  ACCEPT(4) Baker, Cole, LeBlanc, Wall | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:iis-dir-traversal-read | Christey> This may be a variant of CVE-2000-0097 or CVE-2000-0098. | MS:MS00-006 says that a new variant was announced on February 4, | but that it only revealed the physical path. The post related | to this CAN is dated February 2, but it describes the impact | as being able to read files. | | See http://marc.theaimsgroup.com/?l=bugtraq&m=94972759912790&w=2 | Christey> According to Mark Burnett: "CISADV000202 [described] idq.dll | and involving .idq files... IDQ files are vulnerable to a | double-dot bug that allows files on the same partition as the | web root to be viewed.... [This candidate] refers to the same | MS00-006" | | ADDREF MS:MS00-006 | ADDREF BID:968 ? | Frech> Change iis-dir-traversal-read(4014) to http-indexserver-view-files(4232)  View
2671  CVE-2000-1104  Candidate  Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site.  Proposed (20001219)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech  Frech> XF:iis-cross-site-scripting(5156)  View
5364  CVE-2002-0976  Candidate  Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the applet.  Modified (20050610)  ACCEPT(1) Foat | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Cox | REVIEWING(1) Wall  Frech> XF:ie-xml-read-files(9885)  View
488  CVE-1999-0490  Candidate  MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user"s files via an IMG SRC tag.  Modified (19991205-01)  ACCEPT(2) Landfield, Wall | MODIFY(1) Frech | NOOP(2) Baker, Ozancin | REVIEWING(1) Christey  Frech> XF:ie-scriplet-fileread | Christey> Duplicate of CVE-1999-0347?  View
3710  CVE-2001-0904  Candidate  Internet Explorer 5.5 and 6 with the Q312461 (MS01-055) patch modifies the HTTP_USER_AGENT (UserAgent) information that indicates that the patch has been installed, which could allow remote malicious web sites to more easily identify and exploit vulnerable clients.  Modified (20050703)  ACCEPT(3) Armstrong, Cole, Foat | MODIFY(1) Frech | REVIEWING(1) Wall  Frech> XF:ie-q312461-patch-existence(7581)  View

Page 155 of 20943, showing 5 records out of 104715 total, starting on record 771, ending on 775

Actions