CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3035 | CVE-2001-0214 | Candidate | Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte. | Proposed (20010309) | MODIFY(1) Frech | NOOP(3) Cole, Lawler, Ziese | Frech> XF:wayboard-cgi-view-files(6091) | View |
3045 | CVE-2001-0224 | Candidate | Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter. | Modified (20060609) | MODIFY(1) Frech | NOOP(3) Cole, Lawler, Ziese | Frech> XF:muskat-empower-url-dir(6093) | View |
3046 | CVE-2001-0225 | Candidate | fortran math component in Infobot 0.44.5.3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters. | Proposed (20010309) | MODIFY(1) Frech | NOOP(3) Cole, Lawler, Ziese | Frech> XF:infobot-calc-gain-access(6078) | View |
3750 | CVE-2001-0944 | Candidate | DDE in mIRC allows local users to launch applications under another user"s account via a DDE message that executes a command, which may be executed by the other user"s process. | Proposed (20020131) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Green | Frech> XF:mirc-dde-gain-privileges(8292) | View |
1031 | CVE-1999-1051 | Candidate | Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Christey | Frech> XF:formhandler-cgi-reply-message(7782) | Christey> I view one of these as a configuration issue: FormHandler.cgi | *could* be configured to limit hard-coded pathnames to a single | directory which, while being an information leak, would still be | "reasonably secure." But by default, it"s just not configured that | way. | | My brain hurts too much right now. There are a couple | problems with the references and descriptions of CVE-1999-1050 | and CVE-1999-1051. I"m interpreting the underlying nature | of the problem(s) a little differently than others are. | Some of it may be due to differing definitions or thoughts | about what "directory traversal vulnerabilities" are. | View |
Page 19819 of 20943, showing 5 records out of 104715 total, starting on record 99091, ending on 99095