CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3848  CVE-2001-1044  Candidate  Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(4) Armstrong, Cole, Foat, Wall    View
3849  CVE-2001-1045  Candidate  Directory traversal vulnerability in basilix.php3 in Basilix Webmail 1.0.3beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the request_id[DUMMY] parameter.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(4) Armstrong, Cole, Foat, Wall    View
3854  CVE-2001-1050  Candidate  CCCSoftware CCC PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.  Proposed (20020131)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Green    View
3855  CVE-2001-1051  Candidate  Dark Hart Portal (darkportal) PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
3856  CVE-2001-1052  Candidate  Empris PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View

Page 20753 of 20943, showing 5 records out of 104715 total, starting on record 103761, ending on 103765

Actions