CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2256  CVE-2000-0680  Candidate  The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committers to modify or create Trojan horse programs with the Checkin.prog or Update.prog names, then performing a CVS commit action.  Proposed (20000921)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:cvs-checkin-execute-binary  View
2257  CVE-2000-0681  Entry  Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension.        View
2258  CVE-2000-0682  Entry  BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /ConsoleHelp/ into the URL, which invokes the FileServlet.        View
2259  CVE-2000-0683  Entry  BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /*.shtml/ into the URL, which invokes the SSIServlet.        View
2260  CVE-2000-0684  Entry  BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.        View

Page 452 of 20943, showing 5 records out of 104715 total, starting on record 2256, ending on 2260

Actions