CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4145 | CVE-2001-1341 | Candidate | The Beck GmbH IPC@Chip embedded web server installs the chipcfg.cgi program by default, which allows remote attackers to obtain sensitive network information via a request to the program. | Proposed (20020502) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | View | |
4147 | CVE-2001-1343 | Candidate | ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter. | Proposed (20020502) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | Green> As this vulnerability requires the exploiter to have an authenticated administrative login, is it an oxymoron? | View |
4148 | CVE-2001-1344 | Candidate | WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot). | Proposed (20020502) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | View | |
4152 | CVE-2001-1348 | Candidate | TWIG 2.6.2 and earlier allows remote attackers to perform unauthorized database operations via a SQL injection attack on the id parameter. | Proposed (20020502) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | Green> Even if vague, there is acknowledgement. | View |
4036 | CVE-2001-1232 | Candidate | GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary directory contents via an HTTP request with a lowercase "get". | Proposed (20020502) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | View |
Page 865 of 20943, showing 5 records out of 104715 total, starting on record 4321, ending on 4325