CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4006  CVE-2001-1202  Candidate  Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden" error page, which allows remote attackers to execute arbitrary Javascript on other clients via a URL that generates an error.  Proposed (20020315)  ACCEPT(1) Frech | NOOP(5) Cole, Foat, Green, Wall, Ziese  Green> Change history at the DeleGate is not specific enough to determine if | the java scripting problem has been addressed.  View
4007  CVE-2001-1203  Entry  Format string vulnerability in gpm-root in gpm 1.17.8 through 1.17.18 allows local users to gain root privileges.        View
4008  CVE-2001-1204  Candidate  Directory traversal vulnerability in phprocketaddin in Total PC Solutions PHP Rocket Add-in for FrontPage 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.  Modified (20050705)  MODIFY(1) Frech | NOOP(5) Cole, Foat, Green, Wall, Ziese  Frech> XF:phprocket-directory-traversal(7749)  View
4009  CVE-2001-1205  Candidate  Directory traversal vulnerability in lastlines.cgi for Last Lines 2.0 allows remote attackers to read arbitrary files via ".." sequences in the $error_log variable.  Modified (20070307)  MODIFY(1) Frech | NOOP(5) Cole, Foat, Green, Wall, Ziese  Green> WHEN AND IF IT IS SPLIT.......... | Frech> XF:lastlines-cgi-directory-traversal(7753)  View
4010  CVE-2001-1206  Candidate  Matrix CGI vault Last Lines 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the $error_log variable.  Modified (20070307)  MODIFY(1) Frech | NOOP(5) Cole, Foat, Green, Wall, Ziese  Green> WHEN AND IF IT IS SPLIT.......... | Frech> XF:lastlines-cgi-command-execution(7754)  View

Page 802 of 20943, showing 5 records out of 104715 total, starting on record 4006, ending on 4010

Actions