CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
890 | CVE-1999-0910 | Candidate | Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user. | Proposed (19991208) | ACCEPT(4) Baker, Ozancin, Prosser, Wall | MODIFY(2) Frech, Stracener | REJECT(1) Cole | Frech> XF:siteserver-cis-cookie-cache | Cole> Whether cookies are a vulnerbality is a debate for another time, the | question here is whether the | expiration feature is a vulnerability and I do not think it is | because the underlying concerns for this | are present even without this feature. The expiration feature does | not add any new vulenrabilities | that are not already present with cookies. | Stracener> Add Ref: MSKB Q238647 | View |
651 | CVE-1999-0670 | Candidate | Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands. | Proposed (19991208) | ACCEPT(3) Ozancin, Prosser, Wall | MODIFY(2) Frech, Stracener | REJECT(2) Baker, Cole | Frech> XF:ie-eyedog-bo | Cole> Based on the references and information listed this is the same as | CVE-1999-0669 | Stracener> Add Ref: MSKB Q240308 | Baker> Duplicate | View |
717 | CVE-1999-0737 | Candidate | The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | Proposed (19991208) | ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Cole | Frech> XF:iis-samples-viewcode | Cole> I would combine this with the previous. | Prosser> (modify) | See comments in 0736 above | Christey> See http://www.securityfocus.com/focus/microsoft/iis/showcode.html | for additional details. | Christey> Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317 | View |
718 | CVE-1999-0738 | Candidate | The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | Proposed (19991208) | ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Cole | Frech> XF:iis-samples-code | Cole> Same as above | Prosser> (modify) | See comments in 0736 above | Christey> See http://www.securityfocus.com/focus/microsoft/iis/showcode.html | for additional details. | Christey> Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317 | View |
719 | CVE-1999-0739 | Candidate | The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | Proposed (19991208) | ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Cole | Frech> XF:iis-samples-codebrws | Cole> Same as above. | Prosser> (modify) | See comments in 0736 above | Christey> codebrw2.asp and Codebrw1.asp also need to be included | somewhere. | | Also see http://www.securityfocus.com/focus/microsoft/iis/showcode.html | Christey> Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317 | View |
Page 20553 of 20943, showing 5 records out of 104715 total, starting on record 102761, ending on 102765