CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3805 | CVE-2001-1000 | Candidate | rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to read arbitrary files via a symlink attack on the rlmadmin.help file. | Proposed (20020131) | ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Green | Frech> If the software is available to the general public, then it | should | be included in CVE. Marking the software "MichNet Only" does not | prevent | someone from running it outside of MichNet, but it allegedly may | protect | MichNet against actual or perceived liabilities. | View |
1030 | CVE-1999-1050 | Candidate | Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template. | Proposed (20010912) | ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Christey | Christey> Abstraction and definition issue: CD:SF-LOC suggests combining | issues of the same type. Some people refer to "directory | traversal" and just mean .. problems; but there are other | issues (specifying an absolute pathname, using C: drive | letters, doing encodings) that, to my way of thinking, are | "different." Perhaps this should be split. | | My brain hurts too much right now. There are a couple | problems with the references and descriptions of CVE-1999-1050 | and CVE-1999-1051. I"m interpreting the underlying nature | of the problem(s) a little differently than others are. | Some of it may be due to differing definitions or thoughts | about what "directory traversal vulnerabilities" are. | View |
1539 | CVE-1999-1559 | Candidate | Xylan OmniSwitch before 3.2.6 allows remote attackers to bypass the login prompt via a CTRL-D (control d) character, which locks other users out of the switch because it only supports one session at a time. | Proposed (20010912) | ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | View | |
1043 | CVE-1999-1063 | Candidate | CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter. | Proposed (20010912) | ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | View | |
1051 | CVE-1999-1071 | Candidate | Excite for Web Servers (EWS) 1.1 installs the Architext.conf authentication file with world-writeable permissions, which allows local users to gain access to Excite accounts by modifying the file. | Proposed (20010912) | ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | View |
Page 20255 of 20943, showing 5 records out of 104715 total, starting on record 101271, ending on 101275