CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3641 | CVE-2001-0835 | Candidate | Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup. | Modified (20020226-01) | ACCEPT(5) Armstrong, Baker, Bishop, Cole, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat | Frech> XF:webalizer-html-tag-host(7350) | XF:webalizer-html-tags-keywords(7351) | Christey> ADDREF RHSA-2001:140 (per Mark Cox of Red Hat) | Christey> CONECTIVA:CLA-2001:435 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000435 | View |
3642 | CVE-2001-0836 | Entry | Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request. | View | |||
3643 | CVE-2001-0837 | Entry | DeltaThree Pc-To-Phone 3.0.3 places sensitive data in world-readable locations in the installation directory, which allows local users to read the information in (1) temp.html, (2) the log folder, and (3) the PhoneBook folder. | View | |||
3644 | CVE-2001-0838 | Candidate | Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers execute arbitrary code via format string specifiers in the -soa command. | Proposed (20011122) | ACCEPT(2) Armstrong, Baker | MODIFY(1) Frech | NOOP(5) Bishop, Christey, Cole, Foat, Wall | Frech> XF:rwhoisd-remote-format-string(7353) | CONFIRM:http://www.securityfocus.com/archive/1/223080 | Christey> The CONFIRM reference by Andre is really this one: | BUGTRAQ:20011026 RWhoisd patched | URL:http://www.securityfocus.com/archive/1/223080 | Christey> CONFIRM:http://lists.research.netsol.com/pipermail/rwhois-announce/2001-October/000022.html | View |
3645 | CVE-2001-0839 | Candidate | ibillpm.pl in iBill password management system generates weak passwords based on a client"s MASTER_ACCOUNT, which allows remote attackers to modify account information in the .htpasswd file via brute force password guessing. | Modified (20050528) | MODIFY(1) Frech | NOOP(5) Armstrong, Bishop, Cole, Foat, Wall | Frech> XF:ibillpm-cgi-insecure-password(7352) | View |
Page 729 of 20943, showing 5 records out of 104715 total, starting on record 3641, ending on 3645