CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5833  CVE-2002-1449  Candidate  eUpload 1.0 stores the password.txt password file in plaintext under the web document root, which allows remote attackers to overwrite arbitrary files by reading password.txt.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
5835  CVE-2002-1451  Candidate  Blazix before 1.2.2 allows remote attackers to read source code of JSP scripts or list restricted web directories via an HTTP request that ends in a (1) "+" or (2) "" (backslash) character.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
5836  CVE-2002-1452  Candidate  Buffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a long searchTarget parameter.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
5837  CVE-2002-1453  Candidate  Cross-site scripting (XSS) vulnerability in MyWebServer 1.0.2 allows remote attackers to insert script and HTML via a long request followed by the malicious script, which is echoed back to the user in an error message.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
5838  CVE-2002-1454  Candidate  MyWebServer 1.0.2 allows remote attackers to determine the absolute path of the web document root via a request for a directory that does not exist, which leaks the pathname in an error message.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View

Page 20286 of 20943, showing 5 records out of 104715 total, starting on record 101426, ending on 101430

Actions