CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8395 | CVE-2003-1571 | Candidate | Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for database/WWGguestbook.mdb. NOTE: it was later reported that 8.21 is also affected. | Assigned (20090402) | None (candidate not yet proposed) | View | |
8394 | CVE-2003-1570 | Candidate | The server in IBM Tivoli Storage Manager (TSM) 5.1.x, 5.2.x before 5.2.1.2, and 6.x before 6.1 does not require credentials to observe the server console in some circumstances, which allows remote authenticated administrators to monitor server operations by establishing a console mode session, related to "session exposure." | Assigned (20090331) | None (candidate not yet proposed) | View | |
8393 | CVE-2003-1569 | Candidate | GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different vectors than CVE-2001-0385. | Assigned (20090206) | None (candidate not yet proposed) | View | |
8392 | CVE-2003-1568 | Candidate | GoAhead WebServer before 2.1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an invalid URL, related to the websSafeUrl function. | Assigned (20090206) | None (candidate not yet proposed) | View | |
8391 | CVE-2003-1567 | Candidate | The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass the HttpOnly protection mechanism, by using TRACK to read the contents of the HTTP headers that are returned in the response, a technique that is similar to cross-site tracing (XST) using HTTP TRACE. | Assigned (20090114) | None (candidate not yet proposed) | View |
Page 19265 of 20943, showing 5 records out of 104715 total, starting on record 96321, ending on 96325