CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5097 | CVE-2002-0707 | Candidate | The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large GET requests, possibly due to a buffer overflow. | Modified (20071016) | ACCEPT(1) Baker | NOOP(5) Christey, Cole, Cox, Green, Wall | Christey> BID:5854 | URL:http://www.securityfocus.com/bid/5854 | XF:superscout-webfilter-get-dos(10242) | URL:http://www.iss.net/security_center/static/10242.php | View |
5794 | CVE-2002-1410 | Candidate | Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of config.cgi. | Proposed (20030317) | ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall | Baker> ADD: http://bosen.net/advisories/aresu-adv.002.txt | View |
5795 | CVE-2002-1411 | Candidate | Directory traversal vulnerability in update.dpgs in Duma Photo Gallery System (DPGS) 0.99.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the id parameter. | Proposed (20030317) | ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall | Baker> Since the vendor no longer maintains the code, no fix appears available. | The dpgs.pll file has insufficient filtering to preclude this, so a fix | should not be too difficult to make and should be straightforward. | The description should probably reflect that the lax filtering in | the dpgs.pll file allows form to be posted with the directory traversal | and null byte data. | View |
5805 | CVE-2002-1421 | Candidate | SQL injection vulnerabilities in FUDforum before 2.2.0 allow remote attackers to perform unauthorized database operations via (1) report.php, (2) selmsg.php, and (3) showposts.php. | Proposed (20030317) | ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall | Baker> http://fud.prohost.org/CHANGELOG | The changelog addresses some of the corrections, but is very vague. | View |
5806 | CVE-2002-1422 | Candidate | admbrowse.php in FUDforum before 2.2.0 allows remote attackers to create or delete files via URL-encoded pathnames in the cur and dest parameters. | Proposed (20030317) | ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall | Baker> http://fud.prohost.org/CHANGELOG | The changelog addresses some of the fixes, but is vague | View |
Page 644 of 20943, showing 5 records out of 104715 total, starting on record 3216, ending on 3220