CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5794  CVE-2002-1410  Candidate  Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of config.cgi.  Proposed (20030317)  ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall  Baker> ADD: http://bosen.net/advisories/aresu-adv.002.txt  View
5795  CVE-2002-1411  Candidate  Directory traversal vulnerability in update.dpgs in Duma Photo Gallery System (DPGS) 0.99.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the id parameter.  Proposed (20030317)  ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall  Baker> Since the vendor no longer maintains the code, no fix appears available. | The dpgs.pll file has insufficient filtering to preclude this, so a fix | should not be too difficult to make and should be straightforward. | The description should probably reflect that the lax filtering in | the dpgs.pll file allows form to be posted with the directory traversal | and null byte data.  View
5799  CVE-2002-1415  Candidate  Format string vulnerability in SMTP service for WebEasyMail 3.4.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in SMTP requests.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall | REVIEWING(1) Baker  Baker> There is an updated version available from the vendor"s website, | http://www.51webmail.com/downloadwem.html | however, I am unable to determine whether this bug has been fixed or | not, since the site is in Chinese. There is no english language version | of it, apparently. There is an upgrade notes and patch listing under the | download menu, so if we have someone with chinese language skills, we might | be able to get this one sorted out...  View
5800  CVE-2002-1416  Candidate  The POP3 service for WebEasyMail 3.4.2.2 and earlier generates diffferent error messages for valid and invalid usernames during authentication, which makes it easier for remote attackers to conduct brute force attacks.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall | REVIEWING(1) Baker  Baker> See entry for CAN 2002-1415...  View
5805  CVE-2002-1421  Candidate  SQL injection vulnerabilities in FUDforum before 2.2.0 allow remote attackers to perform unauthorized database operations via (1) report.php, (2) selmsg.php, and (3) showposts.php.  Proposed (20030317)  ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall  Baker> http://fud.prohost.org/CHANGELOG | The changelog addresses some of the corrections, but is very vague.  View

Page 20911 of 20943, showing 5 records out of 104715 total, starting on record 104551, ending on 104555

Actions