CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5700  CVE-2002-1316  Candidate  importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315).  Modified (20071014)  ACCEPT(1) Baker | NOOP(4) Christey, Cole, Cox, Wall | REVIEWING(1) Green  Christey> fix typo: "paramatar"  View
5726  CVE-2002-1342  Candidate  Unknown vulnerability in smb2www 980804-16 and earlier allows remote attackers to execute arbitrary commands.  Modified (20071014)  ACCEPT(2) Cole, Green | NOOP(1) Cox    View
5729  CVE-2002-1345  Candidate  Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.  Modified (20071014)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech | NOOP(1) Cox  Frech> XF:ftp-client-filename-traversal(10821)  View
3775  CVE-2001-0970  Candidate  Cross-site scripting vulnerability in TDForum 1.2 CGI script (tdforum12.cgi) allows remote attackers to execute arbitrary script on other clients via a forum message that contains the script.  Modified (20071006)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Green> HAS-INDEPENDENT-CONFIRMATION | Frech> XF:tdforum-cross-site-scripting(7009)  View
3777  CVE-2001-0972  Candidate  Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888."  Modified (20071006)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:surfnet-asp-cookie-seq-predictable(7011)  View

Page 474 of 20943, showing 5 records out of 104715 total, starting on record 2366, ending on 2370

Actions