CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1133 | CVE-1999-1153 | Candidate | HAMcards Postcard CGI script 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address. | Proposed (20010912) | ACCEPT(2) Cole, Frech | NOOP(2) Foat, Wall | View | |
1134 | CVE-1999-1154 | Candidate | LakeWeb Filemail CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address. | Proposed (20010912) | ACCEPT(2) Cole, Frech | NOOP(3) Christey, Foat, Wall | Christey> I confirmed this problem via visual inspection of the | source code in http://www.lakeweb.com/scripts/filemail.zip | Line 82 has an insufficient check for shell metacharacters | that doesn"t exclude semicolons. Line 129 is the | call where the metacharacters are injected. | | Need to add "filemail.pl" to the description. | View |
1390 | CVE-1999-1410 | Candidate | addnetpr in IRIX 5.3 and 6.2 allows local users to overwrite arbitrary files and possibly gain root privileges via a symlink attack on the printers temporary file. | Proposed (20010912) | NOOP(2) Cole, Foat | REJECT(2) Christey, Frech | Christey> DUPE CVE-1999-1286 | Need to add these references to CVE-1999-1286 | View |
1135 | CVE-1999-1155 | Candidate | LakeWeb Mail List CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address. | Proposed (20010912) | ACCEPT(2) Cole, Frech | NOOP(2) Foat, Wall | View | |
1392 | CVE-1999-1412 | Candidate | A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes. | Proposed (20010912) | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Frech | Frech> (Task 2288) | View |
Page 226 of 20943, showing 5 records out of 104715 total, starting on record 1126, ending on 1130