CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2221 | CVE-2000-0645 | Candidate | WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE). | Proposed (20000803) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(3) Cole, LeBlanc, Wall | Frech> XF:wftpd-rest-dos(5004) | View |
2222 | CVE-2000-0646 | Candidate | WFTPD and WFTPD Pro 2.41 allows remote attackers to obtain the real pathname for a file by executing a STATUS (STAT) command while the file is being transferred. | Proposed (20000803) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(3) Cole, LeBlanc, Wall | Frech> XF:wftpd-stat-info(5005) | View |
2223 | CVE-2000-0647 | Candidate | WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing an MLST command before logging into the server. | Proposed (20000803) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(3) Cole, LeBlanc, Wall | Frech> XF:wftpd-mlst-dos(5006) | View |
2224 | CVE-2000-0648 | Candidate | WFTPD and WFTPD Pro 2.41 allows local users to cause a denial of service by executing the RENAME TO (RNTO) command before a RENAME FROM (RNFR) command. | Proposed (20000803) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(2) Cole, LeBlanc | REVIEWING(1) Wall | Frech> XF:wftpd-rnto-dos(4930) | View |
2225 | CVE-2000-0649 | Candidate | IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined. | Proposed (20000803) | ACCEPT(2) LeBlanc, Levy | MODIFY(1) Frech | NOOP(1) Cole | REVIEWING(2) Christey, Wall | Christey> ADDREF http://support.microsoft.com/support/kb/articles/Q218/1/80.ASP | | Change description to point out that the internal IP address | exposure is due to the default configuration as opposed to | a bug. | Frech> XF:iis-internal-ip-disclosure(5106) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> There are two variants of the same type of issue here. The | KB article shows that IIS 4.0 reveals the IP address in a | Content-Location MIME header field. The NTBugtraq article | says that the IP address is shown in the WWW-Authenticate | MIME header. Which one has been fixed, or both, and when? | Christey> MSKB:Q218180 identifies a problem in which IIS returns the | info in a Content-Location header, but the authentication | realm problem is not specifically mentioned. Are these the | same problem? | View |
Page 445 of 20943, showing 5 records out of 104715 total, starting on record 2221, ending on 2225