CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4698 | CVE-2002-0306 | Candidate | ans.pl in Avenger"s News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter. | Proposed (20020502) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:ans-plugin-execute-commands(8256) | View |
4699 | CVE-2002-0307 | Candidate | Directory traversal vulnerability in ans.pl in Avenger"s News System (ANS) 2.11 and earlier allows remote attackers to determine the existence of arbitrary files or execute any Perl program on the system via a .. (dot dot) in the p parameter, which reads the target file and attempts to execute the line using Perl"s eval function. | Proposed (20020502) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:ans-plugin-execute-commands(8256) | View |
4703 | CVE-2002-0311 | Candidate | Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi or (2) service_action.cgi. | Proposed (20020502) | ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall | View | |
4704 | CVE-2002-0312 | Candidate | Directory traversal vulnerability in Essentia Web Server 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL. | Proposed (20020502) | ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall | View | |
4706 | CVE-2002-0314 | Candidate | fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message. | Proposed (20020502) | ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | View |
Page 20809 of 20943, showing 5 records out of 104715 total, starting on record 104041, ending on 104045