CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5141  CVE-2002-0751  Candidate  CGIscript.net csMailto.cgi program allows remote attackers to use csMailto as a "spam proxy" and send mail to arbitrary users via modified (1) form-to, (2) form-from, and (3) form-results parameters.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5142  CVE-2002-0752  Candidate  CGIscript.net csMailto.cgi program exports feedback to a file that is accessible from the web document root, which could allow remote attackers to obtain sensitive information by directly accessing the file.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5143  CVE-2002-0753  Candidate  Buffer overflow in Talentsoft Web+ 5.0 allows remote attackers to execute arbitrary code via an HTTP request with a long cookie.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5146  CVE-2002-0756  Candidate  Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert script into an error page and possibly steal cookies.  Proposed (20020726)  ACCEPT(2) Armstrong, Cole | NOOP(4) Christey, Cox, Foat, Wall  Christey> This *might* be vendor acknowledgement: | URL:http://www.geocrawler.com/lists/3/SourceForge/12082/0/8595354/ | | However, the person who"s credited by the vendor found *TWO* | authentication-related vulnerabilities at about the same time, | and the vendor is clearly fixing "a" vulnerability. So, which | issue did the vendor fix? Which issue is the vendor | acknowledging - CVE-2002-0757 or CVE-2002-0756?  View
5147  CVE-2002-0757  Candidate  (1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and gain privileges via certain control characters in the authentication information, which can force Webmin or Usermin to accept arbitrary username/session ID combinations.  Proposed (20020726)  ACCEPT(2) Baker, Cole | NOOP(5) Armstrong, Christey, Cox, Foat, Wall  Christey> This *might* be vendor acknowledgement: | URL:http://www.geocrawler.com/lists/3/SourceForge/12082/0/8595354/ | | However, the person who"s credited by the vendor found *TWO* | authentication-related vulnerabilities at about the same time, | and the vendor is clearly fixing "a" vulnerability. So, which | issue did the vendor fix? Which issue is the vendor | acknowledging - CVE-2002-0757 or CVE-2002-0756?  View

Page 20859 of 20943, showing 5 records out of 104715 total, starting on record 104291, ending on 104295

Actions