CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4974  CVE-2002-0583  Candidate  WorkforceROI Xpede 4.1 uses a small random namespace (5 alphanumeric characters) for temporary expense claim reports in the /reports/temp directory, which allows remote attackers to read the reports via a brute force attack.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
4719  CVE-2002-0327  Candidate  Buffer overflow in Century Software TERM allows local users to gain root privileges via a long tty argument to the callin program.  Proposed (20020502)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
4975  CVE-2002-0584  Candidate  WorkforceROI Xpede 4.1 allows remote attackers to read user timesheets by modifying the TSN ID parameter to the ts_app_process.asp script, which is easily guessable because it is incremented by 1 for each new timesheet.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
4723  CVE-2002-0331  Candidate  Directory traversal vulnerability in the HTTP server for BPM Studio Pro 4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request.  Proposed (20020502)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
4981  CVE-2002-0590  Candidate  Cross-site scripting (CSS) vulnerability in IcrediBB 1.1 Beta allows remote attackers to execute arbitrary script and steal cookies as other IcrediBB users via the (1) title or (2) body of posts.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View

Page 20244 of 20943, showing 5 records out of 104715 total, starting on record 101216, ending on 101220

Actions