CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3730 | CVE-2001-0924 | Candidate | Directory traversal vulnerability in ifx CGI program in Informix Web DataBlade allows remote attackers to read arbitrary files via a .. (dot dot) in the LO parameter. | Proposed (20020131) | ACCEPT(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | View | |
3022 | CVE-2001-0201 | Candidate | The Postaci frontend for PostgreSQL does not properly filter characters such as semicolons, which could allow remote attackers to execute arbitrary SQL queries via the deletecontact.php program. | Proposed (20010309) | ACCEPT(1) Frech | NOOP(3) Lawler, Oliver, Ziese | View | |
3077 | CVE-2001-0256 | Candidate | FaSTream FTP++ Server 2.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long username. | Proposed (20010404) | ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(2) Bishop, Christey | Christey> CVE-2000-0831 and CVE-2001-0256 are probable duplicates, since | they involve the same product and version (Fastream FTP++ | 2.0), vuln type (buffer overflow), and attack vector (username). | View |
3074 | CVE-2001-0253 | Candidate | Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a .. (dot dot) attack in the show parameter. | Modified (20050509) | ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop | View | |
3076 | CVE-2001-0255 | Candidate | FaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the "ls" command and including the drive letter name (e.g. C:) in the requested pathname. | Proposed (20010404) | ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop | View |
Page 20250 of 20943, showing 5 records out of 104715 total, starting on record 101246, ending on 101250