CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5425 | CVE-2002-1037 | Candidate | Cross-site scripting vulnerability in Double Choco Latte (DCL) before 20020706 allows remote attackers to inject arbitrary HTML, including script, into web pages via the (1) Ticket# Find, (2) Priorities, (3) Severities, (4) Projects, (5) WO# Find, (6) Departments and (7) Users features. | Proposed (20020830) | ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall | View | |
5426 | CVE-2002-1038 | Candidate | Double Choco Latte (DCL) before 20020706 does not properly verify if a file was uploaded, which allows remote attackers to conduct certain operations on arbitrary files via the (1) Projects: Upload File Attachment or (2) Work Orders: Import features. | Proposed (20020830) | ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall | View | |
5428 | CVE-2002-1040 | Candidate | Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames. | Proposed (20020830) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Frech> XF:aix-dsfweb-scripts-insecure(10390) | View |
5429 | CVE-2002-1041 | Candidate | Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames. | Proposed (20020830) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Frech> XF:aix-smit-panels-insecure(10393) | View |
5430 | CVE-2002-1042 | Candidate | Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via .. (dot-dot backslash) sequences in the NS-query-pat parameter. | Proposed (20020830) | ACCEPT(1) Frech | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Wall | View |
Page 51 of 20943, showing 5 records out of 104715 total, starting on record 251, ending on 255