CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4102 | CVE-2001-1298 | Candidate | Webodex PHP script 1.0 and earlier allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. | Proposed (20020502) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | View | |
56273 | CVE-2012-3030 | Candidate | WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with insufficient access control, which allows remote attackers to read a (1) log file or (2) configuration file via a direct request. | Assigned (20120530) | None (candidate not yet proposed) | View | |
56277 | CVE-2012-3034 | Candidate | WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to discover a username and password via crafted parameters to unspecified methods in ActiveX controls. | Assigned (20120530) | None (candidate not yet proposed) | View | |
20646 | CVE-2006-4542 | Candidate | Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs. | Assigned (20060905) | None (candidate not yet proposed) | View | |
19496 | CVE-2006-3392 | Candidate | Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274. | Assigned (20060706) | None (candidate not yet proposed) | View |
Page 242 of 20943, showing 5 records out of 104715 total, starting on record 1206, ending on 1210