CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2896 | CVE-2001-0075 | Candidate | Directory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the filename parameter. | Proposed (20010202) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | Frech> XF:http-cgi-technote-main(5813) | Contrary to current references, product is spelled TECH-NOTE | (see http://www.technote.co.kr/) | View |
2897 | CVE-2001-0076 | Candidate | register.cgi in Ikonboard 2.1.7b and earlier allows remote attackers to execute arbitrary commands via the SEND_MAIL parameter, which overwrites an internal program variable that references a program to be executed. | Proposed (20010202) | ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | View | |
2898 | CVE-2001-0077 | Entry | The clustmon service in Sun Cluster 2.x does not require authentication, which allows remote attackers to obtain sensitive information such as system logs and cluster configurations. | View | |||
2899 | CVE-2001-0078 | Entry | in.mond in Sun Cluster 2.x allows local users to read arbitrary files via a symlink attack on the status file of a host running HA-NFS. | View | |||
2900 | CVE-2001-0079 | Candidate | Support Tools Manager (STM) A.22.00 for HP-UX allows local users to overwrite arbitrary files via a symlink attack on the tool_stat.txt log file. | Proposed (20010202) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | Frech> XF:stm-log-files-symlink(6126) | BID-2158 | View |
Page 580 of 20943, showing 5 records out of 104715 total, starting on record 2896, ending on 2900