CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4700 | CVE-2002-0308 | Candidate | admin.asp in AdMentor 2.11 allows remote attackers to bypass authentication and gain privileges via a SQL injection attack on the Login and Password arguments. | Modified (20050527) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:admentor-asp-gain-access(8245) | View |
2728 | CVE-2000-1161 | Candidate | The installation of AdCycle banner management system leaves the build.cgi program in a web-accessible directory, which allows remote attackers to execute the program and view passwords or delete databases. | Proposed (20001219) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Wall | Frech> XF:adcycle-password-disclosure(5559) | View |
3243 | CVE-2001-0425 | Candidate | AdLibrary.pm in AdCycle 0.78b allows remote attackers to gain privileges to AdCycle via a malformed Agent: header in the HTTP request, which is inserted into a resulting SQL query that is used to verify login information. | Proposed (20010524) | MODIFY(1) Frech | NOOP(4) Cole, Oliver, Wall, Ziese | Frech> XF:adcycle-adlibrarypm-unauthorized-access(6618) | View |
2265 | CVE-2000-0689 | Candidate | Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the amadmin.pl script with the setpasswd parameter. | Modified (20061027) | ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> XF:account-manager-overwrite-password | In description, you probably want to indicate both Account Manager LITE and PRO. | Because CONFIRM redirects, you may want to verify and normalize to http://www.cgiscriptcenter.com/acctman/index2.html. | Christey> XF:account-manager-overwrite-password | http://xforce.iss.net/static/5125.php | Frech> XF:account-manager-overwrite-password(5125) | View |
4935 | CVE-2002-0544 | Candidate | Aprelium Abyss Web Server (abyssws) before 1.0.3 stores the administrative console password in plaintext in the abyss.conf file, which allows local users with access to the file to gain privileges. | Proposed (20020611) | ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Frech> XF:abyss-unicode-directory-traversal(8805) | View |
Page 215 of 20943, showing 5 records out of 104715 total, starting on record 1071, ending on 1075