CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4696 | CVE-2002-0304 | Candidate | Lil HTTP Server 2.1 allows remote attackers to read password-protected files via a /./ in the HTTP request. | Modified (20050705) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall | Christey> VULNWATCH:20020222 [VulnWatch] SecurityOffice Security Advisories: Essentia and LilHTTP web servers | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0051.html | XF:lilhttp-protected-file-access(8247) | URL:http://www.iss.net/security_center/static/8247.php | BID:4153 | URL:http://www.securityfocus.com/bid/4153 | Frech> XF:lilhttp-protected-file-access(8247) | View |
4008 | CVE-2001-1204 | Candidate | Directory traversal vulnerability in phprocketaddin in Total PC Solutions PHP Rocket Add-in for FrontPage 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. | Modified (20050705) | MODIFY(1) Frech | NOOP(5) Cole, Foat, Green, Wall, Ziese | Frech> XF:phprocket-directory-traversal(7749) | View |
3590 | CVE-2001-0783 | Candidate | Cisco TFTP server 1.1 allows remote attackers to read arbitrary files via a ..(dot dot) attack in the GET command. | Modified (20050706) | ACCEPT(1) Foat | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Oliver, Wall | Frech> XF:cisco-tftp-directory-traversal(6722) | View |
4497 | CVE-2002-0103 | Candidate | An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml. | Modified (20050706) | ACCEPT(5) Cole, Foat, Green, Wall, Ziese | MODIFY(1) Frech | Frech> XF:oracle-appserver-webcached-privileges(7766) | XF:oracle-appserver-webcache-password(7768) | CHANGE> [Foat changed vote from NOOP to ACCEPT] | View |
4850 | CVE-2002-0458 | Candidate | Cross-site scripting vulnerability in News-TNK 1.2.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter. | Modified (20050706) | ACCEPT(4) Baker, Cole, Frech, Green | NOOP(3) Cox, Foat, Wall | View |
Page 20442 of 20943, showing 5 records out of 104715 total, starting on record 102206, ending on 102210