CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1131  CVE-1999-1151  Candidate  Compaq/Microcom 6000 Access Integrator does not cause a session timeout after prompting for a username or password, which allows remote attackers to cause a denial of service by connecting to the integrator without providing a username or password.  Proposed (20010912)  ACCEPT(2) Cole, Frech | NOOP(2) Foat, Wall    View
1132  CVE-1999-1152  Candidate  Compaq/Microcom 6000 Access Integrator does not disconnect a client after a certain number of failed login attempts, which allows remote attackers to guess usernames or passwords via a brute force attack.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall  Frech> XF:microcom-brute-force(7301)  View
1133  CVE-1999-1153  Candidate  HAMcards Postcard CGI script 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.  Proposed (20010912)  ACCEPT(2) Cole, Frech | NOOP(2) Foat, Wall    View
1134  CVE-1999-1154  Candidate  LakeWeb Filemail CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.  Proposed (20010912)  ACCEPT(2) Cole, Frech | NOOP(3) Christey, Foat, Wall  Christey> I confirmed this problem via visual inspection of the | source code in http://www.lakeweb.com/scripts/filemail.zip | Line 82 has an insufficient check for shell metacharacters | that doesn"t exclude semicolons. Line 129 is the | call where the metacharacters are injected. | | Need to add "filemail.pl" to the description.  View
1135  CVE-1999-1155  Candidate  LakeWeb Mail List CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.  Proposed (20010912)  ACCEPT(2) Cole, Frech | NOOP(2) Foat, Wall    View

Page 227 of 20943, showing 5 records out of 104715 total, starting on record 1131, ending on 1135

Actions