CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5268 | CVE-2002-0878 | Candidate | SQL injection vulnerability in the login form for LogiSense software including (1) Hawk-i Billing, (2) Hawk-i ASP and (3) DNS Manager allows remote attackers to bypass authentication via SQL code in the password field. | Proposed (20020830) | ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | View | |
5269 | CVE-2002-0879 | Candidate | showtemp.cfm for Gafware CFXImage 1.6.6 allows remote attackers to read arbitrary files via (1) a .. or (2) a C: style pathname in the FILE parameter. | Proposed (20020830) | ACCEPT(2) Alderson, Frech | MODIFY(1) Jones | NOOP(4) Armstrong, Cole, Cox, Foat | Jones> Suggest description adds "...CFXImage 1.6.6 and earlier does not | filter form input, allowing remote attackers to read...". Regarding | abstraction, vote not to SPLIT; agree that vulnerability is lack of input | filtering. SPLITting would imply that Cross-site scripting, etc. due to | same lack of form input filtering would require a new candidate, etc. | View |
5270 | CVE-2002-0880 | Candidate | Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated by (1) "jolt", (2) "jolt2", (3) "raped", (4) "hping2", (5) "bloop", (6) "bubonic", (7) "mutant", (8) "trash", and (9) "trash2." | Proposed (20020830) | ACCEPT(3) Alderson, Cole, Foat | MODIFY(3) Baker, Frech, Jones | NOOP(2) Armstrong, Cox | Jones> Suggest description removes tool references: "Cisco IP Phone | (VoIP) models 7910, 7940, and 7960 allow remote | attackers to cause a denial of service (crash) via a flood of malformed IP | packets." The tools are just generators of specific malformed packets and | don"t actually represent vulnerabilities; the vulnerability is in the | ability of the Cisco device IP stack to handle various malformed packets. | Cisco description indicates that the solution was to improve the devices" | ability to handle high rates of traffic (not to repair specific packet | handling code in the stack). This suggests a single CVE entry (vice | multiple entries if the stack had a set of different vulnerabilities). | Baker> I agree the description should be changed to describe the problem as failure to handle malformed IP packets | Frech> XF:cisco-ipphone-multiple-dos(9145) | View |
5271 | CVE-2002-0881 | Candidate | Cisco IP Phone (VoIP) models 7910, 7940, and 7960 use a default administrative password, which allows attackers with physical access to the phone to modify the configuration settings. | Proposed (20020830) | ACCEPT(6) Alderson, Armstrong, Baker, Cole, Foat, Frech | MODIFY(1) Jones | NOOP(1) Cox | Jones> Description: "...use a default, publicly-known, and unchangeable | trusted path key combination to access configuration information, which | allows attackers..." | View |
5272 | CVE-2002-0882 | Candidate | The web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read sensitive memory via a large integer value in (1) the stream ID of the StreamingStatistics script, or (2) the port ID of the PortInformation script. | Proposed (20020830) | ACCEPT(5) Alderson, Cole, Foat, Frech, Jones | NOOP(2) Armstrong, Cox | RECAST(1) Baker | View |
Page 65 of 20943, showing 5 records out of 104715 total, starting on record 321, ending on 325