CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2896  CVE-2001-0075  Candidate  Directory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the filename parameter.  Proposed (20010202)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese  Frech> XF:http-cgi-technote-main(5813) | Contrary to current references, product is spelled TECH-NOTE | (see http://www.technote.co.kr/)  View
2897  CVE-2001-0076  Candidate  register.cgi in Ikonboard 2.1.7b and earlier allows remote attackers to execute arbitrary commands via the SEND_MAIL parameter, which overwrites an internal program variable that references a program to be executed.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View
2898  CVE-2001-0077  Entry  The clustmon service in Sun Cluster 2.x does not require authentication, which allows remote attackers to obtain sensitive information such as system logs and cluster configurations.        View
2899  CVE-2001-0078  Entry  in.mond in Sun Cluster 2.x allows local users to read arbitrary files via a symlink attack on the status file of a host running HA-NFS.        View
2900  CVE-2001-0079  Candidate  Support Tools Manager (STM) A.22.00 for HP-UX allows local users to overwrite arbitrary files via a symlink attack on the tool_stat.txt log file.  Proposed (20010202)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese  Frech> XF:stm-log-files-symlink(6126) | BID-2158  View

Page 580 of 20943, showing 5 records out of 104715 total, starting on record 2896, ending on 2900

Actions