CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5457 | CVE-2002-1069 | Candidate | The remote administration capability for the D-Link DI-804 router 4.68 allows remote attackers to bypass authentication and release DHCP addresses or obtain sensitive information via a direct web request to the pages (1) release.htm, (2) Device Status, or (3) Device Information. | Proposed (20020830) | ACCEPT(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | View | |
5458 | CVE-2002-1070 | Candidate | Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter. | Proposed (20020830) | ACCEPT(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall | Christey> CONFIRM:http://cvs.sourceforge.net/viewcvs.py/phpwiki/phpwiki/lib/Request.php | This URL is a changelog for Request.php. For revsion 1.17, | dated 20020909, the author says "Prevent from possible XSS attacks" | and includes a sample exploit for the pagename parameter. | View |
5459 | CVE-2002-1071 | Candidate | ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet with both the SYN and ACK flags set. | Proposed (20020830) | ACCEPT(1) Frech | NOOP(5) Cole, Cox, Foat, Green, Wall | View | |
5460 | CVE-2002-1072 | Candidate | ZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized, fragmented "jolt" style ICMP packet. | Proposed (20020830) | NOOP(4) Cole, Cox, Foat, Wall | View | |
5205 | CVE-2002-0815 | Candidate | The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server"s parent DNS domain name to the restricted site, loading a page from the restricted site into one frame, and passing the information to the attacker-controlled frame, which is allowed because the document.domain of the two frames matches on the parent domain. | Proposed (20020830) | ACCEPT(1) Baker | NOOP(4) Cole, Cox, Foat, Wall | View |
Page 20876 of 20943, showing 5 records out of 104715 total, starting on record 104376, ending on 104380