CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4698  CVE-2002-0306  Candidate  ans.pl in Avenger"s News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter.  Proposed (20020502)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:ans-plugin-execute-commands(8256)  View
4699  CVE-2002-0307  Candidate  Directory traversal vulnerability in ans.pl in Avenger"s News System (ANS) 2.11 and earlier allows remote attackers to determine the existence of arbitrary files or execute any Perl program on the system via a .. (dot dot) in the p parameter, which reads the target file and attempts to execute the line using Perl"s eval function.  Proposed (20020502)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:ans-plugin-execute-commands(8256)  View
4700  CVE-2002-0308  Candidate  admin.asp in AdMentor 2.11 allows remote attackers to bypass authentication and gain privileges via a SQL injection attack on the Login and Password arguments.  Modified (20050527)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:admentor-asp-gain-access(8245)  View
4702  CVE-2002-0310  Candidate  Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the username/password combinations (1) testweb/newstest, (2) alwn3845/imaptest, (3) alwi3845/wtest3452, or (4) testweb2/wtest4879.  Modified (20050527)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:webnews-cgi-default-accounts(8255)  View
5476  CVE-2002-1089  Candidate  rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.  Modified (20050610)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:oracle-reports-information-disclosure(9628)  View

Page 19802 of 20943, showing 5 records out of 104715 total, starting on record 99006, ending on 99010

Actions