CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1701 | CVE-2000-0123 | Candidate | The shopping cart application provided with Filemaker allows remote users to modify sensitive purchase information via hidden form fields. | Proposed (20000208) | ACCEPT(1) Baker | MODIFY(1) Frech | RECAST(1) Cole | REVIEWING(1) Wall | Cole> See comments for CVE-2000-0101 | Frech> XF:shopping-cart-form-tampering | View |
1702 | CVE-2000-0124 | Candidate | surfCONTROL SuperScout does not properly asign a category to web sites with a . (dot) at the end, which may allow users to bypass web access restrictions. | Proposed (20000208) | MODIFY(2) Baker, Frech | NOOP(2) Christey, Wall | RECAST(1) Cole | Cole> See comments for CVE-2000-0101 | Frech> XF:surfcontrol-superscout-bypass-filter(4009) | Christey> Fix typo: "asign" | Baker> Description still has typo asign instead of assign | View |
1703 | CVE-2000-0125 | Candidate | wwwthreads does not properly cleanse numeric data or table names that are passed to SQL queries, which allows remote attackers to gain privileges for wwwthreads forums. | Proposed (20000208) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> XF:wwwthreads-sql-command-privs(4011) | Christey> CONFIRM:http://www.wwwthreads.com/perl/showflat.pl?Cat=&Board=info&Number=9932&page=1&view=collapsed&sb=5 | View |
1704 | CVE-2000-0126 | Candidate | Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack. | Proposed (20000208) | ACCEPT(4) Baker, Cole, LeBlanc, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF:iis-dir-traversal-read | Christey> This may be a variant of CVE-2000-0097 or CVE-2000-0098. | MS:MS00-006 says that a new variant was announced on February 4, | but that it only revealed the physical path. The post related | to this CAN is dated February 2, but it describes the impact | as being able to read files. | | See http://marc.theaimsgroup.com/?l=bugtraq&m=94972759912790&w=2 | Christey> According to Mark Burnett: "CISADV000202 [described] idq.dll | and involving .idq files... IDQ files are vulnerable to a | double-dot bug that allows files on the same partition as the | web root to be viewed.... [This candidate] refers to the same | MS00-006" | | ADDREF MS:MS00-006 | ADDREF BID:968 ? | Frech> Change iis-dir-traversal-read(4014) to http-indexserver-view-files(4232) | View |
1707 | CVE-2000-0129 | Candidate | Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file. | Proposed (20000208) | ACCEPT(3) Baker, Blake, Cole | MODIFY(2) Frech, Levy | NOOP(2) Armstrong, Ozancin | RECAST(1) Christey | REVIEWING(1) Wall | Frech> XF:win-shortcut-api-bo | The real problem seems to be with the Windows API call, not the Serv-U FTP | app. As the "Windows Api SHGetPathFromIDList Buffer Overflow" reference | states, [The bug can] "cause whatever handles the shortcuts to crash." | As a suggestion, rephrase the description from Windows"s context, and state | that the Serv-U FTP server is an example of an app that exhibits this | problem. | Wall> Comment: the original UssrLabs advisory does mention the SHGetPathFromIDList | buffer overflow in a Windows API and that Serv-U FTP uses this API to cause the | problem. The problem does not exist on Windows 2000. The solution seems to be | in a new release of Serv-U FTP. | Levy> BID 970 | Christey> | Reports indicate that while the vulnerable function was found in Serv-U FTP | server, the function is actually from Microsoft, and as such may affect other | applications. | XF:win-shortcut-api-bo | BID:970 | View |
Page 379 of 20943, showing 5 records out of 104715 total, starting on record 1891, ending on 1895