CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4801  CVE-2002-0409  Candidate  orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.  Proposed (20020611)  ACCEPT(2) Alderson, Wall | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Frech  Alderson> This is a whole new breed of exposure... vulnerable example code | leading to cross industry and application exposure. This to a point made by | Gene Kim recently "they keep deploying problems faster than we can deploy | solutions".  View
4802  CVE-2002-0410  Candidate  send_message.php in AeroMail before 1.45 allows remote attackers to read arbitrary files on the server, instead of just uploaded files, via an attachment that modifies the filename to be uploaded.  Proposed (20020611)  ACCEPT(4) Alderson, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4803  CVE-2002-0411  Candidate  Cross-site scripting vulnerability in message.php for AeroMail before 1.45 allows remote attackers to execute Javascript as an AeroMail user via an email message with the script in the Subject line.  Proposed (20020611)  ACCEPT(4) Alderson, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4805  CVE-2002-0413  Candidate  Cross-site scripting vulnerability in ReBB allows remote attackers to execute arbitrary Javascript and steal cookies via an IMG tag whose URL includes the malicious script.  Proposed (20020611)  ACCEPT(2) Alderson, Frech | NOOP(4) Cole, Cox, Foat, Wall    View
4807  CVE-2002-0415  Candidate  Directory traversal vulnerability in the web server used in RealPlayer 6.0.7, and possibly other versions, may allow local users to read files that are accessible to RealPlayer via a .. (dot dot) in an HTTP GET request to port 1275.  Proposed (20020611)  ACCEPT(2) Alderson, Frech | NOOP(4) Cole, Cox, Foat, Wall    View

Page 20849 of 20943, showing 5 records out of 104715 total, starting on record 104241, ending on 104245

Actions