CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3731  CVE-2001-0925  Candidate  The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.  Proposed (20020131)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Green | NOOP(2) Christey, Wall | REJECT(1) Frech  Frech> I"m using both candidates until we decide if it is a dupe, | and then which | candidate to deprecate. | Christey> BUGTRAQ:20010615 TSLSA-2001-0010 - Apache | URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0180.html | Christey> CVE-2001-0925 and CVE-2001-0729 are different issues. | CVE-2001-0925 only applies to versions before 1.3.19, whereas | CVE-2001-0729 applies to 1.3.20, and only Windows. | | The Change Log at http://www.apache.org/dist/httpd/CHANGES_1.3 | specifically mentions these CANs separately.  View
3732  CVE-2001-0926  Candidate  SSIFilter in Allaire JRun 3.1, 3.0 and 2.3.3 allows remote attackers to obtain source code for Java server pages (.jsp) and other files in the web root via an HTTP request for a non-existent SSI page, in which the request"s body has an #include statement.  Proposed (20020131)  ACCEPT(2) Baker, Frech | NOOP(4) Armstrong, Cole, Foat, Wall    View
3737  CVE-2001-0931  Candidate  Directory traversal vulnerability in Cooolsoft PowerFTP Server 2.03 allows attackers to list or read arbitrary files and directories via a .. (dot dot) in (1) LS or (2) GET.  Proposed (20020131)  ACCEPT(3) Baker, Foat, Frech | NOOP(3) Armstrong, Cole, Wall    View
3738  CVE-2001-0932  Candidate  Buffer overflow in Cooolsoft PowerFTP Server 2.03 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long command.  Proposed (20020131)  ACCEPT(2) Foat, Frech | NOOP(3) Armstrong, Cole, Wall    View
3739  CVE-2001-0933  Candidate  Cooolsoft PowerFTP Server 2.03 allows remote attackers to list the contents of arbitrary drives via a ls (LIST) command that includes the drive letter as an argument, e.g. "ls C:".  Proposed (20020131)  ACCEPT(1) Foat | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Wall  Frech> XF:powerftp-dot-directory-traversal(7615)  View

Page 182 of 20943, showing 5 records out of 104715 total, starting on record 906, ending on 910

Actions