CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3776 | CVE-2001-0971 | Candidate | Directory traversal vulnerability in ACI 4d webserver allows remote attackers to read arbitrary files via a .. (dot dot) or drive letter (e.g., C:) in an HTTP request. | Modified (20020313-01) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | REJECT(1) Christey | Christey> According to an email message from the vendor | (bcoveney@4d.com) on March 13, 2002, this problem is only | possible if the server admin has already configured the | server"s web root to be at the top-level folder. This is not | the default. As such, any "directory traversal" attack would | not escape above the folder that has already been specified by | the admin. Since this is a generic misconfiguration problem | for all web servers, and not a default configuration of ACI | 4D, then this candidate should not be included in CVE. | | The quote from the vendor is: "By default the 4D WebServer | doesn"t have this behavior. A property has to be turned on to allow | this (despite our warnings of the consequences). We don"t allow pages | outside of our web folder to be served but if the developer of the | site wishes they can set the webroot folder to be whatever they | want. In the system that "krfinisterre@checkfree.com" evaluated the | developer had chosen to set their root folder to be the root of the | computer system (C:) and therefore all the files on the system were | available. By default we set the root folder at the same level as the | database folder so this doesn"t happen. You cannot look at any files | outside the designated WebFolder root tree." | Frech> XF:4d-webserver-directory-traversal(7010) | View |
3777 | CVE-2001-0972 | Candidate | Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888." | Modified (20071006) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> XF:surfnet-asp-cookie-seq-predictable(7011) | View |
3778 | CVE-2001-0973 | Entry | BSCW groupware system 3.3 through 4.0.2 beta allows remote attackers to read or modify arbitrary files by uploading and extracting a tar file with a symlink into the data-bag space. | View | |||
3779 | CVE-2001-0974 | Candidate | Format string vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. | Modified (20020416-01) | ACCEPT(6) Armstrong, Baker, Cole, Frech, Green, Wall | NOOP(1) Foat | View | |
3780 | CVE-2001-0975 | Candidate | Buffer overflow vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. | Modified (20020416-01) | ACCEPT(6) Armstrong, Baker, Cole, Frech, Green, Wall | NOOP(1) Foat | View |
Page 756 of 20943, showing 5 records out of 104715 total, starting on record 3776, ending on 3780