CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5396 | CVE-2002-1008 | Candidate | Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil" HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via a request to urlcount.cgi that contains the script, which is not filtered when the REPORT capability prints the original request. | Proposed (20020830) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | Green> PUBLISHER"S WEBSITE INDICATES SECURITY FIXES | View |
4139 | CVE-2001-1335 | Candidate | Directory traversal vulnerability in CesarFTP 0.98b and earlier allows remote authenticated users (such as anonymous) to read arbitrary files via a GET with a filename that contains a ...%5c (modified dot dot). | Proposed (20020502) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | View | |
4140 | CVE-2001-1336 | Candidate | CesarFTP 0.98b and earlier stores usernames and passwords in plaintext in the settings.ini file, which allows attackers to gain privileges. | Proposed (20020502) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | View | |
4142 | CVE-2001-1338 | Candidate | Beck IPC GmbH IPC@CHIP TelnetD server generates different responses when given valid and invalid login names, which allows remote attackers to determine accounts on the system. | Proposed (20020502) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | View | |
4144 | CVE-2001-1340 | Candidate | Beck GmbH IPC@Chip TelnetD service supports only one connection and does not disconnect a user who does not complete the login process, which allows remote attackers to lock out the administrator account by connecting to the service. | Proposed (20020502) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | View |
Page 864 of 20943, showing 5 records out of 104715 total, starting on record 4316, ending on 4320