CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5805 | CVE-2002-1421 | Candidate | SQL injection vulnerabilities in FUDforum before 2.2.0 allow remote attackers to perform unauthorized database operations via (1) report.php, (2) selmsg.php, and (3) showposts.php. | Proposed (20030317) | ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall | Baker> http://fud.prohost.org/CHANGELOG | The changelog addresses some of the corrections, but is very vague. | View |
5806 | CVE-2002-1422 | Candidate | admbrowse.php in FUDforum before 2.2.0 allows remote attackers to create or delete files via URL-encoded pathnames in the cur and dest parameters. | Proposed (20030317) | ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall | Baker> http://fud.prohost.org/CHANGELOG | The changelog addresses some of the fixes, but is vague | View |
5807 | CVE-2002-1423 | Candidate | tmp_view.php in FUDforum before 2.2.0 allows remote attackers to read arbitrary files via an absolute pathname in the file parameter. | Proposed (20030317) | ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall | Baker> http://fud.prohost.org/CHANGELOG | The change log addresses some of the fixes, but is very vague | View |
5825 | CVE-2002-1441 | Candidate | Multiple buffer overflows in Tomahawk SteelArrow before 4.5 allow remote attackers to execute arbitrary code via (1) the Steelarrow Service (Steelarrow.exe) using a long UserIdent Cookie header, (2) DLLHOST.EXE (Steelarrow.dll) via a request for a long .aro file, or (3) DLLHOST.EXE via a Chunked Transfer-Encoding request. | Proposed (20030317) | ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall | Baker> THere is no changelog file in the installer either, so it is difficult to determine how many issues were addressed in the new version. | View |
5097 | CVE-2002-0707 | Candidate | The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large GET requests, possibly due to a buffer overflow. | Modified (20071016) | ACCEPT(1) Baker | NOOP(5) Christey, Cole, Cox, Green, Wall | Christey> BID:5854 | URL:http://www.securityfocus.com/bid/5854 | XF:superscout-webfilter-get-dos(10242) | URL:http://www.iss.net/security_center/static/10242.php | View |
Page 20300 of 20943, showing 5 records out of 104715 total, starting on record 101496, ending on 101500