CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1766 | CVE-2000-0188 | Candidate | EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters. | Proposed (20000322) | ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(6) Baker, Blake, Christey, Cole, LeBlanc, Wall | Christey> The exploit is different than CVE-2000-0187 by going through | a different field in a different script, so maybe this should | be kept separate, even though it"s probably another open() | call problem. | Frech> XF:ezshopper-search-cgi(4045) | View |
1767 | CVE-2000-0189 | Entry | ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files. | View | |||
1768 | CVE-2000-0190 | Candidate | AOL Instant Messenger (AIM) client allows remote attackers to cause a denial of service via a message with a malformed ASCII value. | Proposed (20000322) | ACCEPT(2) Blake, Cole | MODIFY(1) Frech | NOOP(3) Baker, LeBlanc, Ozancin | REVIEWING(2) Levy, Wall | Frech> XF:aolim-malformed-ascii-dos(4877) | View |
1769 | CVE-2000-0191 | Entry | Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack. | View | |||
1770 | CVE-2000-0192 | Entry | The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows remote attackers to determine what packages are installed on the system. | View |
Page 354 of 20943, showing 5 records out of 104715 total, starting on record 1766, ending on 1770