CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4622  CVE-2002-0230  Candidate  Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cmd parameter, which causes the script to be inserted into an error message.  Proposed (20020502)  ACCEPT(2) Cole, Green | NOOP(2) Foat, Wall | RECAST(1) Christey  Christey> XF:faqomatic-cgi-css(8066) | URL:http://www.iss.net/security_center/static/8066.php | BID:4023 | URL:http://www.securityfocus.com/bid/4023 | | A similar issue was discovered a few months afterward in the | "file" parameter, but it was already fixed by the vendor along | with the cmd parameter. Thus CD:SF-LOC suggests combining | these into a single item. | CONFIRM:http://sourceforge.net/mailarchive/forum.php?thread_id=477665&forum_id=6367 | BID:4565 | URL:http://www.securityfocus.com/bid/4565  View
4485  CVE-2002-0091  Candidate  Multiple CGI scripts in CIDER SHADOW 1.5 and 1.6 allows remote attackers to execute arbitrary commands via certain form fields.  Modified (20050707)  ACCEPT(2) Cole, Green | NOOP(4) Christey, Foat, Wall, Ziese  Christey> VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 2408 - CIDER SHADOW CGI | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0038.html | BID:4625 | URL:http://www.securityfocus.com/bid/4625 | BUGTRAQ:20020429 eSecurityOnline Security Advisory 2408 - CIDER SHADOW CGI | URL:http://online.securityfocus.com/archive/1/270111  View
5366  CVE-2002-0978  Candidate  Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to upload or download arbitrary files to arbitrary locations via a man-in-the-middle attack with modified TGT and TGN parameters in a call to the "Persist" function.  Proposed (20020830)  ACCEPT(2) Cole, LeBlanc | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Cox, Foat | REVIEWING(1) Wall  Christey> XF:ms-ftm-file-upload(9907) | URL:http://www.iss.net/security_center/static/9907.php | BID:5512 | URL:http://www.securityfocus.com/bid/5512 | | Discloser claimed bug was fixed, but I can"t find independent | acknowledgement from Microsoft. Inquiry sent to Microsoft on | November 18, 2002. They acknowledged, via email, that the | issue was fixed. | Frech> XF:ms-ftm-file-upload(9907)  View
2199  CVE-2000-0623  Candidate  Buffer overflow in O"Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header.  Proposed (20000803)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(1) LeBlanc | REVIEWING(1) Wall  Frech> XF:website-httpd32-bo(4970) | In the description, I think it"s spelled "referer"  View
2262  CVE-2000-0686  Candidate  Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the fromfile parameter.  Proposed (20000921)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:cgi-auction-weaver-read-files | Frech> XF:cgi-auction-weaver-read-files(5150)  View

Page 842 of 20943, showing 5 records out of 104715 total, starting on record 4206, ending on 4210

Actions