CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3641 | CVE-2001-0835 | Candidate | Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup. | Modified (20020226-01) | ACCEPT(5) Armstrong, Baker, Bishop, Cole, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat | Frech> XF:webalizer-html-tag-host(7350) | XF:webalizer-html-tags-keywords(7351) | Christey> ADDREF RHSA-2001:140 (per Mark Cox of Red Hat) | Christey> CONECTIVA:CLA-2001:435 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000435 | View |
3550 | CVE-2001-0743 | Candidate | Paging function in O"Reilly WebBoard Pager 4.10 allows remote attackers to cause a denial of service via a message with an escaped " character followed by JavaScript commands. | Proposed (20011012) | MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Foat, Oliver, Wall | Frech> XF:webboard-pager-javascript-dos(6653) | Christey> Need to re-examine this; sounds like XSS to me on a second | glance at the Bugtraq post. | View |
1433 | CVE-1999-1453 | Candidate | Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object. | Proposed (20010912) | ACCEPT(1) Wall | MODIFY(1) Frech | NOOP(2) Cole, Foat | Frech> XF:webbrowser-activex-view-clipboard(7565) | REMOVE:http://www.securityfocus.com/bid/215 This reference | deals with the Forms vulnerability only. | View |
3807 | CVE-2001-1003 | Candidate | Respondus 1.1.2 for WebCT uses weak encryption to remember usernames and passwords, which allows local users who can read the WEBCT.SVR file to decrypt the passwords and gain additional privileges. | Proposed (20020131) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> XF:webct-respondus-weak-encryption(7033) | View |
4702 | CVE-2002-0310 | Candidate | Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the username/password combinations (1) testweb/newstest, (2) alwn3845/imaptest, (3) alwi3845/wtest3452, or (4) testweb2/wtest4879. | Modified (20050527) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:webnews-cgi-default-accounts(8255) | View |
Page 20883 of 20943, showing 5 records out of 104715 total, starting on record 104411, ending on 104415