CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3266 | CVE-2001-0449 | Entry | Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail command line option. | View | |||
3267 | CVE-2001-0450 | Candidate | Directory traversal vulnerability in Transsoft FTP Broker before 5.5 allows attackers to (1) delete arbitrary files via DELETE, or (2) list arbitrary directories via LIST, via a .. (dot dot) in the file name. | Proposed (20010524) | ACCEPT(5) Baker, Cole, Frech, Oliver, Ziese | NOOP(2) Christey, Wall | Christey> Change "LIST" to "DIR" - see original post. The problem with | LIST (and NLST) occurred in Broker 3.0, not 5.0. | | The CONFIRM link is dead. | | Thanks to John Segura of secureinfo.com for noticing this. | View |
3268 | CVE-2001-0451 | Candidate | INDEXU 2.0 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the cookie_admin_authenticated cookie value to 1. | Proposed (20010524) | ACCEPT(1) Frech | NOOP(4) Cole, Oliver, Wall, Ziese | View | |
3269 | CVE-2001-0452 | Candidate | BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls command. | Proposed (20010524) | ACCEPT(4) Baker, Cole, Williams, Ziese | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:webweaver-ftp-path-disclosure(6477) | View |
3270 | CVE-2001-0453 | Candidate | Directory traversal vulnerability in BRS WebWeaver HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the (1) syshelp, (2) sysimages, or (3) scripts directories. | Proposed (20010524) | ACCEPT(3) Baker, Balinsky, Williams | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | Frech> XF:webweaver-web-directory-traversal(6476) | View |
Page 654 of 20943, showing 5 records out of 104715 total, starting on record 3266, ending on 3270