CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5313  CVE-2002-0924  Candidate  CGIScript.net csNews.cgi allows remote authenticated users to execute arbitrary Perl code via terminating quotes and metacharacters in text fields of the "Advanced Settings" capability.  Proposed (20020830)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(2) Foat, Wall | REVIEWING(1) Christey  Frech> XF:cgiscript-url-execute-commands(8636) | Christey> need to see if this is the same as CVE-2002-0495  View
2262  CVE-2000-0686  Candidate  Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the fromfile parameter.  Proposed (20000921)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:cgi-auction-weaver-read-files | Frech> XF:cgi-auction-weaver-read-files(5150)  View
2263  CVE-2000-0687  Candidate  Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the catdir parameter.  Proposed (20000921)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall  Frech> XF:cgi-auction-weaver-read-files | Christey> Need to double-check BID"s on all these Auction Weaver prob"s. | Frech> XF:cgi-auction-weaver-read-files(5150)  View
3632  CVE-2001-0826  Candidate  Buffer overflows in CesarFTPD 0.98b allows remote attackers to execute arbitrary commands via long arguments to (1) HELP, (2) USER, (3) PASS, (4) PORT, (5) DELE, (6) REST, (7) RMD, or (8) MKD.  Proposed (20011122)  MODIFY(1) Frech | NOOP(5) Armstrong, Bishop, Cole, Foat, Wall  Frech> XF:cesarftp-long-command-bo(6768)  View
4531  CVE-2002-0137  Candidate  CDRDAO 1.1.4 and 1.1.5 allows local users to overwrite arbitrary files via a symlink attack on the $HOME/.cdrdao configuration file.  Proposed (20020315)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall  Frech> XF:cdrdao-home-symlink(7934)  View

Page 196 of 20943, showing 5 records out of 104715 total, starting on record 976, ending on 980

Actions