CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3848 | CVE-2001-1044 | Candidate | Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(4) Armstrong, Cole, Foat, Wall | View | |
3849 | CVE-2001-1045 | Candidate | Directory traversal vulnerability in basilix.php3 in Basilix Webmail 1.0.3beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the request_id[DUMMY] parameter. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(4) Armstrong, Cole, Foat, Wall | View | |
3854 | CVE-2001-1050 | Candidate | CCCSoftware CCC PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. | Proposed (20020131) | ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Green | View | |
3855 | CVE-2001-1051 | Candidate | Dark Hart Portal (darkportal) PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall | View | |
3856 | CVE-2001-1052 | Candidate | Empris PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall | View |
Page 20753 of 20943, showing 5 records out of 104715 total, starting on record 103761, ending on 103765