CVE List

Id CVE No. Status Description Phase Votes Comments Actions
717  CVE-1999-0737  Candidate  The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.  Proposed (19991208)  ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Cole  Frech> XF:iis-samples-viewcode | Cole> I would combine this with the previous. | Prosser> (modify) | See comments in 0736 above | Christey> See http://www.securityfocus.com/focus/microsoft/iis/showcode.html | for additional details. | Christey> Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317  View
3477  CVE-2001-0669  Candidate  Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort before 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before XPU 3.2, and (6) ISS RealSecure Server Sensor 5.5 and 6.0 for Windows, allow remote attackers to evade detection of HTTP attacks via non-standard "%u" Unicode encoding of ASCII characters in the requested URL.  Modified (20050510)  ACCEPT(4) Armstrong, Baker, Balinsky, Cole | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:iis-unicode-encoding-detected(6994) | XF:iis-unicode-wide-encoding(6995)  View
3158  CVE-2001-0337  Candidate  The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests.  Proposed (20010524)  ACCEPT(6) Baker, Cole, Renaud, Wall, Williams, Ziese | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:iis-webdav-lock-dos(6549) | Christey> ADDREF? BID:2736 | URL:http://www.securityfocus.com/bid/2736 | ADDREF? BUGTRAQ:20010517 def-2001-26: IIS WebDav Lock Method Memory Leak DoS | URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0170.html | CHANGE> [Christey changed vote from NOOP to REVIEWING]  View
3647  CVE-2001-0841  Candidate  Directory traversal vulnerability in Search.cgi in Ikonboard ib219 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie.  Modified (20050702)  MODIFY(1) Frech | NOOP(6) Armstrong, Bishop, Christey, Cole, Foat, Wall  Frech> XF:ikonboard-cookie-auth-privileges(7433) | Christey> BID:3486 | URL:http://www.securityfocus.com/bid/3486  View
4720  CVE-2002-0328  Candidate  Cross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonboard users and steal cookies via Javascript in an IMG tag.  Proposed (20020502)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:ikonboard-img-css(7460)  View

Page 20792 of 20943, showing 5 records out of 104715 total, starting on record 103956, ending on 103960

Actions