CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7340 | CVE-2003-0513 | Candidate | Microsoft Internet Explorer allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Internet Explorer to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application. | Proposed (20040318) | ACCEPT(5) Armstrong, Baker, Balinsky, Cole, Green | MODIFY(1) Frech | NOOP(1) Cox | REVIEWING(2) Christey, Wall | Frech> XF:web-browser-cookie-bypass(15424) | http://xforce.iss.net/xforce/xfdb/15424 | Christey> Consider whether this is really a design-level problem that applies to | the interaction between any vulnerable XSS, its associated domain, and | any web browser, because browsers enforce security boundaries at the | domain level. If so, then the "%2e%2e" problem may be a red herring, | or a single attack vector of any number of vectors. | | CVE-2003-0513, CVE-2003-0514, CVE-2003-0592, CVE-2003-0593, | and CVE-2003-0594 all cover this specific issue (each for a | different browser). | View |
7339 | CVE-2003-0512 | Candidate | Cisco IOS 12.2 and earlier generates a "% Login invalid" message instead of prompting for a password when an invalid username is provided, which allows remote attackers to identify valid usernames on the system and conduct brute force password guessing, as reported for the Aironet Bridge. | Assigned (20030707) | None (candidate not yet proposed) | View | |
7338 | CVE-2003-0511 | Candidate | The web server for Cisco Aironet AP1x00 Series Wireless devices running certain versions of IOS 12.2 allow remote attackers to cause a denial of service (reload) via a malformed URL. | Assigned (20030707) | None (candidate not yet proposed) | View | |
7337 | CVE-2003-0510 | Candidate | Format string vulnerability in ezbounce 1.0 through 1.50 allows remote attackers to execute arbitrary code via the "sessions" command. | Assigned (20030703) | None (candidate not yet proposed) | View | |
7336 | CVE-2003-0509 | Candidate | SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp. | Assigned (20030703) | None (candidate not yet proposed) | View |
Page 19476 of 20943, showing 5 records out of 104715 total, starting on record 97376, ending on 97380