CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4685 | CVE-2002-0293 | Candidate | FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root"s .profile file. | Modified (20050527) | MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall | Frech> XF:omnipcx-ftp-root-access(8225) | Christey> Acknowledged by Alcatel via email October 4, 2002 | View |
4688 | CVE-2002-0296 | Candidate | The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file. | Modified (20050527) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:tarantella-tmp-spinning-symlink(8223) | View |
4700 | CVE-2002-0308 | Candidate | admin.asp in AdMentor 2.11 allows remote attackers to bypass authentication and gain privileges via a SQL injection attack on the Login and Password arguments. | Modified (20050527) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:admentor-asp-gain-access(8245) | View |
4702 | CVE-2002-0310 | Candidate | Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the username/password combinations (1) testweb/newstest, (2) alwn3845/imaptest, (3) alwi3845/wtest3452, or (4) testweb2/wtest4879. | Modified (20050527) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:webnews-cgi-default-accounts(8255) | View |
4525 | CVE-2002-0131 | Candidate | ActivePython ActiveX control for Python in the AXScript package, when used in Internet Explorer, does not prevent a script from reading files from the client"s filesystem, which allows remote attackers to read arbitrary files via a malicious web page containing Python script. | Modified (20050527) | ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall | View |
Page 522 of 20943, showing 5 records out of 104715 total, starting on record 2606, ending on 2610