CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4538  CVE-2002-0144  Candidate  Directory traversal vulnerability in chuid 1.2 and earlier allows remote attackers to change the ownership of files outside of the upload directory via a .. (dot dot) attack.  Proposed (20020315)  ACCEPT(4) Balinsky, Cole, Frech, Green | NOOP(2) Foat, Wall    View
4027  CVE-2001-1223  Candidate  The web administration server for ELSA Lancom 1100 Office does not require authentication, which allows arbitrary remote attackers to gain administrative privileges by connecting to the server.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese    View
4028  CVE-2001-1224  Candidate  get_input in adrotate.pm for Les VanBrunt AdRotate Pro 2.0 allows remote attackers to modify the database and possibly execute arbitrary commands via a SQL code injection attack.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese    View
4029  CVE-2001-1225  Candidate  Hughes Technology Mini SQL 2.0.10 through 2.0.12 allows local users to cause a denial of service by creating a very large array in a table, which causes miniSQL to crash when the table is queried.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese    View
4030  CVE-2001-1226  Candidate  AdCycle 1.17 and earlier allow remote attackers to modify SQL queries, which are not properly sanitized before being passed to the MySQL database.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(5) Christey, Cole, Foat, Wall, Ziese  Christey> CERT-VN:VU#282403 | URL:http://www.kb.cert.org/vuls/id/282403  View

Page 175 of 20943, showing 5 records out of 104715 total, starting on record 871, ending on 875

Actions