CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5268  CVE-2002-0878  Candidate  SQL injection vulnerability in the login form for LogiSense software including (1) Hawk-i Billing, (2) Hawk-i ASP and (3) DNS Manager allows remote attackers to bypass authentication via SQL code in the password field.  Proposed (20020830)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall    View
5269  CVE-2002-0879  Candidate  showtemp.cfm for Gafware CFXImage 1.6.6 allows remote attackers to read arbitrary files via (1) a .. or (2) a C: style pathname in the FILE parameter.  Proposed (20020830)  ACCEPT(2) Alderson, Frech | MODIFY(1) Jones | NOOP(4) Armstrong, Cole, Cox, Foat  Jones> Suggest description adds "...CFXImage 1.6.6 and earlier does not | filter form input, allowing remote attackers to read...". Regarding | abstraction, vote not to SPLIT; agree that vulnerability is lack of input | filtering. SPLITting would imply that Cross-site scripting, etc. due to | same lack of form input filtering would require a new candidate, etc.  View
5270  CVE-2002-0880  Candidate  Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated by (1) "jolt", (2) "jolt2", (3) "raped", (4) "hping2", (5) "bloop", (6) "bubonic", (7) "mutant", (8) "trash", and (9) "trash2."  Proposed (20020830)  ACCEPT(3) Alderson, Cole, Foat | MODIFY(3) Baker, Frech, Jones | NOOP(2) Armstrong, Cox  Jones> Suggest description removes tool references: "Cisco IP Phone | (VoIP) models 7910, 7940, and 7960 allow remote | attackers to cause a denial of service (crash) via a flood of malformed IP | packets." The tools are just generators of specific malformed packets and | don"t actually represent vulnerabilities; the vulnerability is in the | ability of the Cisco device IP stack to handle various malformed packets. | Cisco description indicates that the solution was to improve the devices" | ability to handle high rates of traffic (not to repair specific packet | handling code in the stack). This suggests a single CVE entry (vice | multiple entries if the stack had a set of different vulnerabilities). | Baker> I agree the description should be changed to describe the problem as failure to handle malformed IP packets | Frech> XF:cisco-ipphone-multiple-dos(9145)  View
5271  CVE-2002-0881  Candidate  Cisco IP Phone (VoIP) models 7910, 7940, and 7960 use a default administrative password, which allows attackers with physical access to the phone to modify the configuration settings.  Proposed (20020830)  ACCEPT(6) Alderson, Armstrong, Baker, Cole, Foat, Frech | MODIFY(1) Jones | NOOP(1) Cox  Jones> Description: "...use a default, publicly-known, and unchangeable | trusted path key combination to access configuration information, which | allows attackers..."  View
5272  CVE-2002-0882  Candidate  The web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read sensitive memory via a large integer value in (1) the stream ID of the StreamingStatistics script, or (2) the port ID of the PortInformation script.  Proposed (20020830)  ACCEPT(5) Alderson, Cole, Foat, Frech, Jones | NOOP(2) Armstrong, Cox | RECAST(1) Baker    View

Page 65 of 20943, showing 5 records out of 104715 total, starting on record 321, ending on 325

Actions