CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1030  CVE-1999-1050  Candidate  Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.  Proposed (20010912)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Christey  Christey> Abstraction and definition issue: CD:SF-LOC suggests combining | issues of the same type. Some people refer to "directory | traversal" and just mean .. problems; but there are other | issues (specifying an absolute pathname, using C: drive | letters, doing encodings) that, to my way of thinking, are | "different." Perhaps this should be split. | | My brain hurts too much right now. There are a couple | problems with the references and descriptions of CVE-1999-1050 | and CVE-1999-1051. I"m interpreting the underlying nature | of the problem(s) a little differently than others are. | Some of it may be due to differing definitions or thoughts | about what "directory traversal vulnerabilities" are.  View
66566  CVE-2013-6619  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20131105)  None (candidate not yet proposed)    View
1286  CVE-1999-1306  Candidate  Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the "established" keyword is set, which could allow attackers to bypass filters.  Proposed (20010912)  ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey  Frech> XF:cisco-acl-established(1248) | Possibly duplicate with CVE-1999-0162? | Christey> Might be a duplicate of CVE-1999-0162, but CVE-1999-0162 was | released in 1995, whereas this bug was released in 1992.  View
66822  CVE-2013-6875  Candidate  SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php.  Assigned (20131126)  None (candidate not yet proposed)    View
1542  CVE-1999-1562  Candidate  gFTP FTP client 1.13, and other versions before 2.0.0, records a password in plaintext in (1) the log window, or (2) in a log file.  Modified (20050309)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall  Frech> XF:gftp-plaintext-password(7319)  View

Page 481 of 20943, showing 5 records out of 104715 total, starting on record 2401, ending on 2405

Actions