CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5060 | CVE-2002-0670 | Candidate | The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to steal and easily decode the passwords via sniffing. | Modified (20050610) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:pingtel-xpressa-plaintext-passwords(9565) | View |
5070 | CVE-2002-0680 | Candidate | Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely that this candidate will be REJECTED because it has been reported to be a duplicate of CVE-2001-0228. | Proposed (20020726) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:goahead-directory-traversal(6046) | View |
3296 | CVE-2001-0479 | Candidate | Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script. | Proposed (20010524) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Balinsky, Cole, Renaud, Wall, Ziese | REVIEWING(1) Williams | Frech> XF:phppgadmin-sqlphp-include-file(6484) | Balinsky> Advisory site no longer exists. There is not enough detail in the advisory, and the vendor does not acknowledge. | View |
2905 | CVE-2001-0084 | Candidate | GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program. | Proposed (20010202) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Christey, Cole, Prosser, Wall, Ziese | Frech> XF:gtk-module-execute-code(5832) | Christey> XF:gtk-module-execute-code | URL:http://xforce.iss.net/static/5832.php | Christey> TURBO:TLSA2001026 | URL:http://www.turbolinux.com/pipermail/tl-security-announce/2001-June/000440.html | View |
3630 | CVE-2001-0824 | Candidate | Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page. | Proposed (20011122) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Bishop, Christey, Cole, Foat, Wall | Frech> XF:java-servlet-crosssite-scripting(6793) | This issue is associated with multiple operating | environments. | Christey> CERT-VN:VU#560659 | URL:http://www.kb.cert.org/vuls/id/560659 | MISC:http://www.kb.cert.org/vuls/id/JARL-4YZKLU | View |
Page 631 of 20943, showing 5 records out of 104715 total, starting on record 3151, ending on 3155