CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1704 | CVE-2000-0126 | Candidate | Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack. | Proposed (20000208) | ACCEPT(4) Baker, Cole, LeBlanc, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF:iis-dir-traversal-read | Christey> This may be a variant of CVE-2000-0097 or CVE-2000-0098. | MS:MS00-006 says that a new variant was announced on February 4, | but that it only revealed the physical path. The post related | to this CAN is dated February 2, but it describes the impact | as being able to read files. | | See http://marc.theaimsgroup.com/?l=bugtraq&m=94972759912790&w=2 | Christey> According to Mark Burnett: "CISADV000202 [described] idq.dll | and involving .idq files... IDQ files are vulnerable to a | double-dot bug that allows files on the same partition as the | web root to be viewed.... [This candidate] refers to the same | MS00-006" | | ADDREF MS:MS00-006 | ADDREF BID:968 ? | Frech> Change iis-dir-traversal-read(4014) to http-indexserver-view-files(4232) | View |
2671 | CVE-2000-1104 | Candidate | Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site. | Proposed (20001219) | ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech | Frech> XF:iis-cross-site-scripting(5156) | View |
5364 | CVE-2002-0976 | Candidate | Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the applet. | Modified (20050610) | ACCEPT(1) Foat | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Cox | REVIEWING(1) Wall | Frech> XF:ie-xml-read-files(9885) | View |
488 | CVE-1999-0490 | Candidate | MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user"s files via an IMG SRC tag. | Modified (19991205-01) | ACCEPT(2) Landfield, Wall | MODIFY(1) Frech | NOOP(2) Baker, Ozancin | REVIEWING(1) Christey | Frech> XF:ie-scriplet-fileread | Christey> Duplicate of CVE-1999-0347? | View |
3710 | CVE-2001-0904 | Candidate | Internet Explorer 5.5 and 6 with the Q312461 (MS01-055) patch modifies the HTTP_USER_AGENT (UserAgent) information that indicates that the patch has been installed, which could allow remote malicious web sites to more easily identify and exploit vulnerable clients. | Modified (20050703) | ACCEPT(3) Armstrong, Cole, Foat | MODIFY(1) Frech | REVIEWING(1) Wall | Frech> XF:ie-q312461-patch-existence(7581) | View |
Page 155 of 20943, showing 5 records out of 104715 total, starting on record 771, ending on 775