CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2670 | CVE-2000-1103 | Candidate | rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line. | Proposed (20001219) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:rcvtty-elevate-privileges(5587) | View |
2671 | CVE-2000-1104 | Candidate | Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site. | Proposed (20001219) | ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech | Frech> XF:iis-cross-site-scripting(5156) | View |
2672 | CVE-2000-1105 | Candidate | The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled. | Proposed (20001219) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | REVIEWING(2) Christey, Wall | Frech> XF:win2k-index-service-ixsso(5502) | Christey> ADDREF MS:MS00-098 | ADDREF XF:win2k-index-service-activex | URL:http://xforce.iss.net/static/5800.php | Add "aka the "Indexing Service File Enumeration" vulnerability" | to the description. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> DUPE CVE-2001-0245? Need to check w/Microsoft. | View |
2677 | CVE-2000-1110 | Candidate | document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program. | Proposed (20001219) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:ibm-netdata-reveal-path(5599) | View |
2681 | CVE-2000-1114 | Candidate | Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20". | Proposed (20001219) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:ewave-jsp-source-read(5562) | View |
Page 325 of 20943, showing 5 records out of 104715 total, starting on record 1621, ending on 1625