CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8500 | CVE-2004-0072 | Candidate | Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded .. (backslash .., "%5c%2e%2e") sequences in an HTTP request. | Modified (20071113) | ACCEPT(2) Armstrong, Baker | NOOP(4) Cole, Cox, Wall, Williams | Williams> insufficient data. | View |
8501 | CVE-2004-0073 | Candidate | PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrary PHP code by modifying the edp_relative_path parameter to reference a URL on a remote web server that contains a malicious serverdata.php script. | Modified (20060907) | ACCEPT(2) Armstrong, Baker | NOOP(4) Cole, Cox, Wall, Williams | Williams> insufficient data. | View |
5868 | CVE-2002-1484 | Candidate | DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message. | Proposed (20030317) | ACCEPT(2) Armstrong, Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall | Baker> The default behavior is the verbose debug messages, so the description should indicate that this is the default configuration. | View |
8645 | CVE-2004-0217 | Candidate | The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log. | Proposed (20040318) | ACCEPT(2) Armstrong, Cole | MODIFY(1) Frech | NOOP(1) Cox | REVIEWING(1) Wall | Frech> XF:symantec-scanengine-race-condition(15215) | http://xforce.iss.net/xforce/xfdb/15215 | View |
4670 | CVE-2002-0278 | Candidate | Directory traversal vulnerability in Add2it Mailman Free 1.73 and earlier allows remote attackers to modify arbitrary files via a .. (dot dot) in the list parameter. | Modified (20050707) | ACCEPT(2) Armstrong, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:mailman-open-directory-traversal(8202) | View |
Page 759 of 20943, showing 5 records out of 104715 total, starting on record 3791, ending on 3795