CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4006 | CVE-2001-1202 | Candidate | Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden" error page, which allows remote attackers to execute arbitrary Javascript on other clients via a URL that generates an error. | Proposed (20020315) | ACCEPT(1) Frech | NOOP(5) Cole, Foat, Green, Wall, Ziese | Green> Change history at the DeleGate is not specific enough to determine if | the java scripting problem has been addressed. | View |
4007 | CVE-2001-1203 | Entry | Format string vulnerability in gpm-root in gpm 1.17.8 through 1.17.18 allows local users to gain root privileges. | View | |||
4008 | CVE-2001-1204 | Candidate | Directory traversal vulnerability in phprocketaddin in Total PC Solutions PHP Rocket Add-in for FrontPage 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. | Modified (20050705) | MODIFY(1) Frech | NOOP(5) Cole, Foat, Green, Wall, Ziese | Frech> XF:phprocket-directory-traversal(7749) | View |
4009 | CVE-2001-1205 | Candidate | Directory traversal vulnerability in lastlines.cgi for Last Lines 2.0 allows remote attackers to read arbitrary files via ".." sequences in the $error_log variable. | Modified (20070307) | MODIFY(1) Frech | NOOP(5) Cole, Foat, Green, Wall, Ziese | Green> WHEN AND IF IT IS SPLIT.......... | Frech> XF:lastlines-cgi-directory-traversal(7753) | View |
4010 | CVE-2001-1206 | Candidate | Matrix CGI vault Last Lines 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the $error_log variable. | Modified (20070307) | MODIFY(1) Frech | NOOP(5) Cole, Foat, Green, Wall, Ziese | Green> WHEN AND IF IT IS SPLIT.......... | Frech> XF:lastlines-cgi-command-execution(7754) | View |
Page 802 of 20943, showing 5 records out of 104715 total, starting on record 4006, ending on 4010