CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1754 | CVE-2000-0176 | Candidate | The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist. | Proposed (20000322) | ACCEPT(4) Blake, Cole, Levy, Ozancin | MODIFY(1) Frech | NOOP(3) Baker, LeBlanc, Wall | Frech> XF:servu-ftp-server-path(4060) | View |
1755 | CVE-2000-0177 | Candidate | DNSTools CGI applications allow remote attackers to execute arbitrary commands via shell metacharacters. | Proposed (20000322) | ACCEPT(4) Blake, Cole, Levy, Ozancin | MODIFY(1) Frech | NOOP(3) Baker, LeBlanc, Wall | Frech> XF:dnstools-invalid-input(4876) | View |
1765 | CVE-2000-0187 | Candidate | EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters. | Proposed (20000322) | ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(6) Baker, Blake, Christey, Cole, LeBlanc, Wall | Christey> Since EZShopper is written in Perl, there is strong evidence | that both the .. and metacharacter attack probably go | through the same insecure open() call. (Perl"s open can | either read a regular file, or read piped output from | a command that is specified to the open). | Frech> XF:ezshopper-loadpage-cgi(4044) | View |
1766 | CVE-2000-0188 | Candidate | EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters. | Proposed (20000322) | ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(6) Baker, Blake, Christey, Cole, LeBlanc, Wall | Christey> The exploit is different than CVE-2000-0187 by going through | a different field in a different script, so maybe this should | be kept separate, even though it"s probably another open() | call problem. | Frech> XF:ezshopper-search-cgi(4045) | View |
1768 | CVE-2000-0190 | Candidate | AOL Instant Messenger (AIM) client allows remote attackers to cause a denial of service via a message with a malformed ASCII value. | Proposed (20000322) | ACCEPT(2) Blake, Cole | MODIFY(1) Frech | NOOP(3) Baker, LeBlanc, Ozancin | REVIEWING(2) Levy, Wall | Frech> XF:aolim-malformed-ascii-dos(4877) | View |
Page 20571 of 20943, showing 5 records out of 104715 total, starting on record 102851, ending on 102855