CVE List

Id CVE No. Status Description Phase Votes Comments Actions
286  CVE-1999-0287  Candidate  Vulnerability in the Wguest CGI program.  Proposed (19990714)  MODIFY(2) Frech, Shostack | NOOP(4) Blake, Levy, Northcutt, Wall | REJECT(2) Baker, Christey  Shostack> allows file reading | Frech> XF:http-cgi-webcom-guestbook | Christey> CVE-1999-0287 is probably a duplicate of CVE-1999-0467. In | NTBUGTRAQ:19990409 Webcom"s CGI Guestbook for Win32 web servers | Mnemonix says that he had previously reported on a similar | problem. Let"s refer to the NTBugtraq posting as | CVE-1999-0467. We will refer to the "previous report" as | CVE-1999-0287, which could be found at: | http://oliver.efri.hr/~crv/security/bugs/NT/httpd41.html | | 0287 describes an exploit via the "template" hidden variable. | The exploit describes manually editing the HTML form to | change the filename to read from the template variable. | | The exploit as described in 0467 encodes the template variable | directly into the URL. However, hidden variables are also | encoded into the URL, which would have looked the same to | the web server regardless of the exploit. Therefore 0287 | and 0467 are the same. | Christey> BID:2024  View
287  CVE-1999-0288  Entry  The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.        View
288  CVE-1999-0289  Entry  The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.        View
289  CVE-1999-0290  Entry  The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost.        View
290  CVE-1999-0291  Entry  The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication.        View

Page 58 of 20943, showing 5 records out of 104715 total, starting on record 286, ending on 290

Actions