CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5795  CVE-2002-1411  Candidate  Directory traversal vulnerability in update.dpgs in Duma Photo Gallery System (DPGS) 0.99.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the id parameter.  Proposed (20030317)  ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall  Baker> Since the vendor no longer maintains the code, no fix appears available. | The dpgs.pll file has insufficient filtering to preclude this, so a fix | should not be too difficult to make and should be straightforward. | The description should probably reflect that the lax filtering in | the dpgs.pll file allows form to be posted with the directory traversal | and null byte data.  View
5794  CVE-2002-1410  Candidate  Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of config.cgi.  Proposed (20030317)  ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall  Baker> ADD: http://bosen.net/advisories/aresu-adv.002.txt  View
5793  CVE-2002-1409  Candidate  ptrace on HP-UX 11.00 through 11.11 allows local users to cause a denial of service (data page fault panic) via "an incorrect reference to thread register state."  Modified (20090302)  ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox    View
5792  CVE-2002-1408  Candidate  Unknown vulnerability or vulnerabilities in HP OpenView EMANATE 14.2 snmpModules allow the SNMP read-write community name to be exposed, related to (1) ""read-only" community access," and/or (2) an easily guessable community name.  Proposed (20030317)  ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox    View
5791  CVE-2002-1407  Entry  TinySSL 1.02 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack.        View

Page 19785 of 20943, showing 5 records out of 104715 total, starting on record 98921, ending on 98925

Actions