CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3805  CVE-2001-1000  Candidate  rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to read arbitrary files via a symlink attack on the rlmadmin.help file.  Proposed (20020131)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Green  Frech> If the software is available to the general public, then it | should | be included in CVE. Marking the software "MichNet Only" does not | prevent | someone from running it outside of MichNet, but it allegedly may | protect | MichNet against actual or perceived liabilities.  View
1030  CVE-1999-1050  Candidate  Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.  Proposed (20010912)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Christey  Christey> Abstraction and definition issue: CD:SF-LOC suggests combining | issues of the same type. Some people refer to "directory | traversal" and just mean .. problems; but there are other | issues (specifying an absolute pathname, using C: drive | letters, doing encodings) that, to my way of thinking, are | "different." Perhaps this should be split. | | My brain hurts too much right now. There are a couple | problems with the references and descriptions of CVE-1999-1050 | and CVE-1999-1051. I"m interpreting the underlying nature | of the problem(s) a little differently than others are. | Some of it may be due to differing definitions or thoughts | about what "directory traversal vulnerabilities" are.  View
1539  CVE-1999-1559  Candidate  Xylan OmniSwitch before 3.2.6 allows remote attackers to bypass the login prompt via a CTRL-D (control d) character, which locks other users out of the switch because it only supports one session at a time.  Proposed (20010912)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall    View
1043  CVE-1999-1063  Candidate  CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter.  Proposed (20010912)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall    View
1051  CVE-1999-1071  Candidate  Excite for Web Servers (EWS) 1.1 installs the Architext.conf authentication file with world-writeable permissions, which allows local users to gain access to Excite accounts by modifying the file.  Proposed (20010912)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall    View

Page 20255 of 20943, showing 5 records out of 104715 total, starting on record 101271, ending on 101275

Actions