CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3112 | CVE-2001-0291 | Candidate | Buffer overflow in post-query sample CGI program allows remote attackers to execute arbitrary commands via an HTTP POST request that contains at least 10001 parameters. | Proposed (20010404) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop | Frech> XF:postquery-http-post-bo(6510) | View |
3113 | CVE-2001-0292 | Candidate | PHP-Nuke 4.4.1a allows remote attackers to modify a user"s email address and obtain the password by guessing the user id (UID) and calling user.php with the saveuser operator. | Proposed (20010404) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop | Frech> XF:phpnuke-saveuser-obtain-password(6511) | View |
3114 | CVE-2001-0293 | Candidate | Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command. | Proposed (20010404) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Bishop | Frech> XF:ftpxq-directory-traversal(6166) | Christey> Email inquiry sent to support@datawizard.net on March 10, 2002. | Christey> Acknowledgement received from rmawji@datawizard.net on March | 11, 2002: "that was fixed in the next version (2.0.94)." | View |
3115 | CVE-2001-0294 | Candidate | Directory traversal vulnerability in TYPSoft FTP Server 0.85 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in a GET command, or (2) a ... in a CWD command. | Proposed (20010404) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(2) Bishop, Christey | Frech> XF:typsoft-ftp-directory-traversal(6165) | Christey> BID:2489 | | The CWD... may have been rediscovered for version 0.95 in: | BUGTRAQ:20010507 Vulnerabilty in TYPsoft FTP server | URL:http://online.securityfocus.com/archive/1/183917 | | However, this CWD uses ".../" whereas the initial post | used just "..." and said that the vendor had fixed the issue. | So, this is probably just an incomplete fix by the vendor. | View |
3117 | CVE-2001-0296 | Candidate | Buffer overflow in WFTPD Pro 3.00 allows remote attackers to execute arbitrary commands via a long CWD command. | Proposed (20010404) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(2) Wall, Ziese | RECAST(1) Prosser | REVIEWING(1) Bishop | Frech> XF:wftpd-pro-cwd-bo(6184) | Prosser> See http://www.mail-archive.com/bugtraq@securityfocus.com/msg05671.html for additional info on this one. It looks like Can-2001-0296 may be a continuation of CVE 1999-0950. Appears from ref that this problem has been in every version since the 2.40 problem reported Oct 1999 (CVE 1999-0950). Just managed to change the code so it requires more characters to overflow the buffer. I haven"t tested this, but just from the available documentation, these problems look like a continuation of the early one. | View |
Page 302 of 20943, showing 5 records out of 104715 total, starting on record 1506, ending on 1510