CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8474  CVE-2004-0046  Candidate  Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script or HTML via a GET request containing a terminating """ (double quote) character.  Modified (20050430)  ACCEPT(2) Armstrong, Baker | NOOP(4) Cole, Cox, Wall, Williams  Williams> insufficient data.  View
3074  CVE-2001-0253  Candidate  Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a .. (dot dot) attack in the show parameter.  Modified (20050509)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop    View
3094  CVE-2001-0273  Candidate  pgp4pine Pine/PGP interface version 1.75-6 does not properly check to see if a public key has expired when obtaining the keys via Gnu Privacy Guard (GnuPG), which causes the message to be sent in cleartext.  Modified (20050509)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop  Frech> XF:pgp4pine-expired-keys(6135)  View
3368  CVE-2001-0555  Candidate  ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. (dot dot) attack through (1) the SITEWare Editor"s Desktop or (2) the template parameter in SWEditServlet.  Modified (20050509)  ACCEPT(6) Armstrong, Cole, Foat, Prosser, Stracener, Ziese | MODIFY(1) Frech | NOOP(2) Christey, Wall  Christey> ********************************************************************* | Note that this candidate was inadvertently used in Microsoft bulletin | MS01-044, for an unrelated vulnerability. The ScreamingMedia | SITEware problem is the correct vulnerability for | CVE-2001-0555. A different candidate will be used for the problem | described in the Microsoft bulletin. | ********************************************************************* | Frech> XF:siteware-dot-file-retrieval(6689) | Prosser> http://www01.screamingmedia.com/en/security/sms1001.php | Christey> Consider adding BID:3191 | Christey> CHANGEREF CONFIRM:http://www01.screamingmedia.com/en/security/security_notice.php?doc=sms1001 | CERT-VN:VU#795707 | URL:http://www.kb.cert.org/vuls/id/795707 | BID:2869 | URL:http://www.securityfocus.com/bid/2869 | XF:siteware-dot-file-retrieval(6689) | URL:http://xforce.iss.net/static/6689.php | | *DON"T* add BID:3191 - that"s for the Microsoft issue.  View
3370  CVE-2001-0557  Candidate  T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a ".." (dot dot) attack which is URL encoded (%2e%2e).  Modified (20050509)  ACCEPT(2) Frech, Ziese | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Bishop    View

Page 20412 of 20943, showing 5 records out of 104715 total, starting on record 102056, ending on 102060

Actions