CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3942 | CVE-2001-1138 | Candidate | Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the FILE parameter. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(5) Armstrong, Cole, Foat, Wall, Ziese | View | |
3943 | CVE-2001-1139 | Candidate | Directory traversal vulnerability in ASCII NT WinWrapper Professional allows remote attackers to read arbitrary files via a .. (dot dot) in the server request. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(5) Armstrong, Cole, Foat, Wall, Ziese | View | |
3944 | CVE-2001-1140 | Candidate | BadBlue Personal Edition v1.02 beta allows remote attackers to read source code for executable programs by appending a %00 (null byte) to the request. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(5) Armstrong, Cole, Foat, Wall, Ziese | View | |
3946 | CVE-2001-1142 | Candidate | ArGoSoft FTP Server 1.2.2.2 uses weak encryption for user passwords, which allows an attacker with access to the password file to gain privileges. | Proposed (20020315) | ACCEPT(2) Baker, Frech | NOOP(7) Armstrong, Christey, Cole, Foat, Green, Wall, Ziese | Christey> In an e-mail response, the vendor stated that they were | not a crypto expert and were using their own home-grown | crypto. | CHANGE> [Baker changed vote from REVIEWING to ACCEPT] | Baker> I received an email from Artchil Gogava, of Argosoft, author | of the program in question. I think this is sufficient verification | that the problem is probably as identified. He states he is not an | encryption expert, and that he invented his own encryption mechanism | for this. Need I say more? | | >>>EMAIL<<< | ///// | Subject: Re: Encryption in ArgoSoft FTP Server | Date: Thu, 9 May 2002 15:14:29 -0400 | From: "Artchil Gogava" <archie@argosoft.com> | To: "David Baker" <bakerd@mitre.org> | References: 1 | | Hello David, | | lnk problem, described in the document, has been fixed ages ago, and it does | not present in 1.2.2.2. As of password encryption. I am not an encryption | expert. I am using a method invented by myself, and I am sure that whatever | I do, someone, who has spare time to play around with it, will find the | method to decrypt it. | | Archie | View |
3947 | CVE-2001-1143 | Candidate | IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789. | Proposed (20020315) | ACCEPT(1) Frech | NOOP(5) Armstrong, Cole, Foat, Green, Wall | REVIEWING(1) Ziese | Ziese> HAS ANYONE BEEN ABLE TO REPRODUCE THIS? | View |
Page 161 of 20943, showing 5 records out of 104715 total, starting on record 801, ending on 805