CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8474 | CVE-2004-0046 | Candidate | Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script or HTML via a GET request containing a terminating """ (double quote) character. | Modified (20050430) | ACCEPT(2) Armstrong, Baker | NOOP(4) Cole, Cox, Wall, Williams | Williams> insufficient data. | View |
3074 | CVE-2001-0253 | Candidate | Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a .. (dot dot) attack in the show parameter. | Modified (20050509) | ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop | View | |
3094 | CVE-2001-0273 | Candidate | pgp4pine Pine/PGP interface version 1.75-6 does not properly check to see if a public key has expired when obtaining the keys via Gnu Privacy Guard (GnuPG), which causes the message to be sent in cleartext. | Modified (20050509) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop | Frech> XF:pgp4pine-expired-keys(6135) | View |
3368 | CVE-2001-0555 | Candidate | ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. (dot dot) attack through (1) the SITEWare Editor"s Desktop or (2) the template parameter in SWEditServlet. | Modified (20050509) | ACCEPT(6) Armstrong, Cole, Foat, Prosser, Stracener, Ziese | MODIFY(1) Frech | NOOP(2) Christey, Wall | Christey> ********************************************************************* | Note that this candidate was inadvertently used in Microsoft bulletin | MS01-044, for an unrelated vulnerability. The ScreamingMedia | SITEware problem is the correct vulnerability for | CVE-2001-0555. A different candidate will be used for the problem | described in the Microsoft bulletin. | ********************************************************************* | Frech> XF:siteware-dot-file-retrieval(6689) | Prosser> http://www01.screamingmedia.com/en/security/sms1001.php | Christey> Consider adding BID:3191 | Christey> CHANGEREF CONFIRM:http://www01.screamingmedia.com/en/security/security_notice.php?doc=sms1001 | CERT-VN:VU#795707 | URL:http://www.kb.cert.org/vuls/id/795707 | BID:2869 | URL:http://www.securityfocus.com/bid/2869 | XF:siteware-dot-file-retrieval(6689) | URL:http://xforce.iss.net/static/6689.php | | *DON"T* add BID:3191 - that"s for the Microsoft issue. | View |
3370 | CVE-2001-0557 | Candidate | T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a ".." (dot dot) attack which is URL encoded (%2e%2e). | Modified (20050509) | ACCEPT(2) Frech, Ziese | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Bishop | View |
Page 20412 of 20943, showing 5 records out of 104715 total, starting on record 102056, ending on 102060