CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1649 | CVE-2000-0071 | Candidate | IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions. | Proposed (20000125) | ACCEPT(2) LeBlanc, Levy | MODIFY(1) Frech | NOOP(1) Baker | REJECT(1) Christey | Frech> XF:iis-ida-idq-paths | Christey> Consider adding: | ADDREF BID:1065 | BUGTRAQ:20000309 Enumerate Root Web Server Directory Vulnerability for IIS 4.0 | Are there really 2 different threads on the same problem? | | Also consider XF:iis-root-enum | | May also be a dupe of CVE-1999-0450 (BID:194) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Appears to be a duplicate of CVE-2000-0098. Confirm with | Microsoft, and if it is a duplicate, then REJECT this | candidate. | CHANGE> [Christey changed vote from REVIEWING to REJECT] | Christey> Confirmed duplicate by Microsoft. | Christey> iis-ida-idq-paths(4346) is obsolete; ensure | http-indexserver-path(3890) is added to CVE-2000-0098. | View |
1652 | CVE-2000-0074 | Candidate | PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions. | Proposed (20000125) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Christey, Williams | Frech> XF:plusmail-password-permissions | Christey> Re-read the Bugtraq post to make sure the problem is described | properly. The advisory itself is vague as to the nature of | the problem, and the exploit doesn"t help clarify too much. | Christey> Consider adding BID:2653 | View |
1657 | CVE-2000-0079 | Candidate | The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL. | Proposed (20000125) | MODIFY(2) Baker, Frech | NOOP(2) Christey, Williams | RECAST(1) LeBlanc | Frech> XF:w3c-httpd-reveal-paths | LeBlanc> Title references IIS, vuln references W3C CERN httpd. Which | one is broken? | Christey> The mention of CERN httpd was buried in a followup on a | description of an IIS problem, so this is the correct reference. | Baker> Will the XF reference be added? | View |
1659 | CVE-2000-0081 | Candidate | Hotmail does not properly filter JavaScript code from a user"s mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. jAvascript. | Proposed (20000125) | MODIFY(1) Frech | REJECT(1) Baker | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:hotmail-vascript-java-injection | View |
1662 | CVE-2000-0084 | Candidate | CuteFTP uses weak encryption to store password information in its tree.dat file. | Proposed (20000125) | MODIFY(2) Baker, Frech | NOOP(1) Christey | Frech> XF:cuteftp-weak-encrypt(3910) | Christey> BUGTRAQ:20010823 Re: Respondus v1.1.2 stores passwords using weak encryption | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99861651923668&w=2 | This followup to a different thread mentions the sm.dat file | for the site manager. | Baker> The reference from the Bugtraq mentions the sm.dat uses better encryption, but doesn"t really address the tree.dat file. | View |
Page 383 of 20943, showing 5 records out of 104715 total, starting on record 1911, ending on 1915