CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4715  CVE-2002-0323  Candidate  comment2.jse in ScriptEase:WebServer allows remote attackers to read arbitrary files by specifying the target file as an argument in the URL.  Proposed (20020502)  MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall  Frech> XF:netware-webserver-directory-traversal(7726) | Christey> Need to investigate why some information sources are combining | this with a Novell web server viewcode.asp issue (e.g. the ISS | reference). | | Consider BID:3715  View
4733  CVE-2002-0341  Candidate  GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.  Proposed (20020502)  MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall  Frech> XF:groupwise-arg-path-disclosure(8311) | Christey> Desc: "... which leaks the pathname in an error message."  View
4878  CVE-2002-0486  Candidate  Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the cookies to gain privileges.  Proposed (20020611)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:xpede-password-weak-encryption(8614)  View
4884  CVE-2002-0492  Candidate  dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.  Proposed (20020611)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:dscshop-cgi-delete-setup(9854)  View
4636  CVE-2002-0244  Candidate  Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the pathname argument to chdir.  Modified (20050528)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:atheos-dot-directory-traversal(8108)  View

Page 19793 of 20943, showing 5 records out of 104715 total, starting on record 98961, ending on 98965

Actions