CVE List

Id CVE No. Status Description Phase Votes Comments Actions
890  CVE-1999-0910  Candidate  Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user.  Proposed (19991208)  ACCEPT(4) Baker, Ozancin, Prosser, Wall | MODIFY(2) Frech, Stracener | REJECT(1) Cole  Frech> XF:siteserver-cis-cookie-cache | Cole> Whether cookies are a vulnerbality is a debate for another time, the | question here is whether the | expiration feature is a vulnerability and I do not think it is | because the underlying concerns for this | are present even without this feature. The expiration feature does | not add any new vulenrabilities | that are not already present with cookies. | Stracener> Add Ref: MSKB Q238647  View
651  CVE-1999-0670  Candidate  Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands.  Proposed (19991208)  ACCEPT(3) Ozancin, Prosser, Wall | MODIFY(2) Frech, Stracener | REJECT(2) Baker, Cole  Frech> XF:ie-eyedog-bo | Cole> Based on the references and information listed this is the same as | CVE-1999-0669 | Stracener> Add Ref: MSKB Q240308 | Baker> Duplicate  View
717  CVE-1999-0737  Candidate  The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.  Proposed (19991208)  ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Cole  Frech> XF:iis-samples-viewcode | Cole> I would combine this with the previous. | Prosser> (modify) | See comments in 0736 above | Christey> See http://www.securityfocus.com/focus/microsoft/iis/showcode.html | for additional details. | Christey> Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317  View
718  CVE-1999-0738  Candidate  The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.  Proposed (19991208)  ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Cole  Frech> XF:iis-samples-code | Cole> Same as above | Prosser> (modify) | See comments in 0736 above | Christey> See http://www.securityfocus.com/focus/microsoft/iis/showcode.html | for additional details. | Christey> Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317  View
719  CVE-1999-0739  Candidate  The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.  Proposed (19991208)  ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Cole  Frech> XF:iis-samples-codebrws | Cole> Same as above. | Prosser> (modify) | See comments in 0736 above | Christey> codebrw2.asp and Codebrw1.asp also need to be included | somewhere. | | Also see http://www.securityfocus.com/focus/microsoft/iis/showcode.html | Christey> Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317  View

Page 20553 of 20943, showing 5 records out of 104715 total, starting on record 102761, ending on 102765

Actions