CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4311  CVE-2001-1511  Candidate  JRun 3.0 and 3.1 running on JRun Web Server (JWS) and IIS allows remote attackers to read arbitrary JavaServer Pages (JSP) source code via a request URL containing the source filename ending in (1) "jsp%00" or (2) "js%2570".  Assigned (20050714)  None (candidate not yet proposed)    View
4312  CVE-2001-1512  Candidate  Unknown vulnerability in Allaire JRun 3.1 allows remote attackers to directly access the WEB-INF and META-INF directories and execute arbitrary JavaServer Pages (JSP), a variant of CVE-2000-1050.  Assigned (20050714)  None (candidate not yet proposed)    View
4313  CVE-2001-1513  Candidate  Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing "/" (slash), as demonstrated using ctx.  Assigned (20050714)  None (candidate not yet proposed)    View
4314  CVE-2001-1514  Candidate  ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with <CFEXECUTE> and (2) child processes that call the CreateProcess function and are executed with <CFOBJECT> or end with the CFX extension, which allows attackers to execute programs with the permissions of the System account.  Assigned (20050714)  None (candidate not yet proposed)    View
4315  CVE-2001-1515  Candidate  Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less restrictive permissions than intended.  Assigned (20050714)  None (candidate not yet proposed)    View

Page 863 of 20943, showing 5 records out of 104715 total, starting on record 4311, ending on 4315

Actions