CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3035  CVE-2001-0214  Candidate  Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte.  Proposed (20010309)  MODIFY(1) Frech | NOOP(3) Cole, Lawler, Ziese  Frech> XF:wayboard-cgi-view-files(6091)  View
3045  CVE-2001-0224  Candidate  Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter.  Modified (20060609)  MODIFY(1) Frech | NOOP(3) Cole, Lawler, Ziese  Frech> XF:muskat-empower-url-dir(6093)  View
3046  CVE-2001-0225  Candidate  fortran math component in Infobot 0.44.5.3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.  Proposed (20010309)  MODIFY(1) Frech | NOOP(3) Cole, Lawler, Ziese  Frech> XF:infobot-calc-gain-access(6078)  View
3750  CVE-2001-0944  Candidate  DDE in mIRC allows local users to launch applications under another user"s account via a DDE message that executes a command, which may be executed by the other user"s process.  Proposed (20020131)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Green  Frech> XF:mirc-dde-gain-privileges(8292)  View
1031  CVE-1999-1051  Candidate  Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Christey  Frech> XF:formhandler-cgi-reply-message(7782) | Christey> I view one of these as a configuration issue: FormHandler.cgi | *could* be configured to limit hard-coded pathnames to a single | directory which, while being an information leak, would still be | "reasonably secure." But by default, it"s just not configured that | way. | | My brain hurts too much right now. There are a couple | problems with the references and descriptions of CVE-1999-1050 | and CVE-1999-1051. I"m interpreting the underlying nature | of the problem(s) a little differently than others are. | Some of it may be due to differing definitions or thoughts | about what "directory traversal vulnerabilities" are.  View

Page 19819 of 20943, showing 5 records out of 104715 total, starting on record 99091, ending on 99095

Actions