CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3730  CVE-2001-0924  Candidate  Directory traversal vulnerability in ifx CGI program in Informix Web DataBlade allows remote attackers to read arbitrary files via a .. (dot dot) in the LO parameter.  Proposed (20020131)  ACCEPT(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall    View
3022  CVE-2001-0201  Candidate  The Postaci frontend for PostgreSQL does not properly filter characters such as semicolons, which could allow remote attackers to execute arbitrary SQL queries via the deletecontact.php program.  Proposed (20010309)  ACCEPT(1) Frech | NOOP(3) Lawler, Oliver, Ziese    View
3077  CVE-2001-0256  Candidate  FaSTream FTP++ Server 2.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long username.  Proposed (20010404)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(2) Bishop, Christey  Christey> CVE-2000-0831 and CVE-2001-0256 are probable duplicates, since | they involve the same product and version (Fastream FTP++ | 2.0), vuln type (buffer overflow), and attack vector (username).  View
3074  CVE-2001-0253  Candidate  Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a .. (dot dot) attack in the show parameter.  Modified (20050509)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop    View
3076  CVE-2001-0255  Candidate  FaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the "ls" command and including the drive letter name (e.g. C:) in the requested pathname.  Proposed (20010404)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop    View

Page 20250 of 20943, showing 5 records out of 104715 total, starting on record 101246, ending on 101250

Actions