CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3129  CVE-2001-0308  Candidate  UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program.  Modified (20080213)  MODIFY(1) Frech | NOOP(4) Bishop, Cole, Wall, Ziese  Frech> XF:bajie-directory-traversal(6115)  View
3606  CVE-2001-0800  Candidate  lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.  Modified (20080211)  ACCEPT(5) Armstrong, Baker, Bishop, Cole, Foat | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF;irix-lpsched-execute-commands(7642)  View
6930  CVE-2003-0101  Candidate  miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.  Modified (20080207)  ACCEPT(4) Armstrong, Cole, Green, Jones | NOOP(2) Christey, Cox  Christey> SGI:20030602-01-I | The "websetup v 3.5 package from IRIX 6.5.20 Applications CD" | uses Webmin; may wish to add this name to the description. | Christey> DEBIAN:DSA-319 | Christey> CIAC:N-058 | URL:http://www.ciac.org/ciac/bulletins/n-058.shtml | ENGARDE:ESA-20030225-006 | URL:http://archives.neohapsis.com/archives/linux/engarde/2003-q1/0008.html | HP:HPSBUX0303-250 | URL:http://archives.neohapsis.com/archives/hp/2003-q1/0063.html | BID:6915 | URL:http://www.securityfocus.com/bid/6915  View
5777  CVE-2002-1393  Candidate  Multiple vulnerabilities in KDE 2 and KDE 3.x through 3.0.5 do not quote certain parameters that are inserted into a shell command, which could allow remote attackers to execute arbitrary commands via (1) URLs, (2) filenames, or (3) e-mail addresses.  Modified (20080207)  ACCEPT(2) Cole, Green | MODIFY(1) Cox | NOOP(1) Christey  Cox> Addref: RHSA-2003:003 | Christey> REDHAT:RHSA-2003:002 | URL:http://www.redhat.com/support/errata/RHSA-2003-002.html  View
5549  CVE-2002-1165  Candidate  Sendmail Consortium"s Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or (2) "/" characters, which are not properly filtered or verified.  Modified (20080207)  ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox  Cox> Addref: RHSA-2002:259  View

Page 452 of 20943, showing 5 records out of 104715 total, starting on record 2256, ending on 2260

Actions