CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4879 | CVE-2002-0487 | Candidate | Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by reading the password from the source file, e.g. from the browser"s cache. | Proposed (20020611) | ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall | View | |
4881 | CVE-2002-0489 | Candidate | Linux Directory Penguin NsLookup CGI script (nslookup.pl) 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the (1) query or (2) type parameters. | Proposed (20020611) | ACCEPT(2) Foat, Frech | NOOP(4) Cole, Cox, Green, Wall | View | |
4883 | CVE-2002-0491 | Candidate | admin.php in AlGuest 1.0 guestbook checks for the existence of the admin cookie to authenticate the AlGuest administrator, which allows remote attackers to bypass the authentication and gain privileges by setting the admin cookie to an arbitrary value. | Proposed (20020611) | ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall | View | |
4884 | CVE-2002-0492 | Candidate | dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter. | Proposed (20020611) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:dscshop-cgi-delete-setup(9854) | View |
4888 | CVE-2002-0496 | Candidate | The HTTP server for SouthWest Talker server 1.0.0 allows remote attackers to cause a denial of service (server crash) via a malformed URL to port 5002. | Proposed (20020611) | ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall | View |
Page 20830 of 20943, showing 5 records out of 104715 total, starting on record 104146, ending on 104150