CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
717 | CVE-1999-0737 | Candidate | The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | Proposed (19991208) | ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Cole | Frech> XF:iis-samples-viewcode | Cole> I would combine this with the previous. | Prosser> (modify) | See comments in 0736 above | Christey> See http://www.securityfocus.com/focus/microsoft/iis/showcode.html | for additional details. | Christey> Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317 | View |
3477 | CVE-2001-0669 | Candidate | Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort before 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before XPU 3.2, and (6) ISS RealSecure Server Sensor 5.5 and 6.0 for Windows, allow remote attackers to evade detection of HTTP attacks via non-standard "%u" Unicode encoding of ASCII characters in the requested URL. | Modified (20050510) | ACCEPT(4) Armstrong, Baker, Balinsky, Cole | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:iis-unicode-encoding-detected(6994) | XF:iis-unicode-wide-encoding(6995) | View |
3158 | CVE-2001-0337 | Candidate | The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests. | Proposed (20010524) | ACCEPT(6) Baker, Cole, Renaud, Wall, Williams, Ziese | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF:iis-webdav-lock-dos(6549) | Christey> ADDREF? BID:2736 | URL:http://www.securityfocus.com/bid/2736 | ADDREF? BUGTRAQ:20010517 def-2001-26: IIS WebDav Lock Method Memory Leak DoS | URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0170.html | CHANGE> [Christey changed vote from NOOP to REVIEWING] | View |
3647 | CVE-2001-0841 | Candidate | Directory traversal vulnerability in Search.cgi in Ikonboard ib219 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie. | Modified (20050702) | MODIFY(1) Frech | NOOP(6) Armstrong, Bishop, Christey, Cole, Foat, Wall | Frech> XF:ikonboard-cookie-auth-privileges(7433) | Christey> BID:3486 | URL:http://www.securityfocus.com/bid/3486 | View |
4720 | CVE-2002-0328 | Candidate | Cross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonboard users and steal cookies via Javascript in an IMG tag. | Proposed (20020502) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:ikonboard-img-css(7460) | View |
Page 20792 of 20943, showing 5 records out of 104715 total, starting on record 103956, ending on 103960