CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4501  CVE-2002-0107  Entry  Web administration interface in CacheFlow CacheOS 4.0.13 and earlier allows remote attackers to obtain sensitive information via a series of GET requests that do not end in with HTTP/1.0 or another version string, which causes the information to be leaked in the error message.        View
4502  CVE-2002-0108  Candidate  Allaire Forums 2.0.4 and 2.0.5 and Forums! 3.0 and 3.1 allows remote authenticated users to spoof messages as other users by modifying the hidden form fields for the name and e-mail address.  Modified (20050313)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese    View
4503  CVE-2002-0109  Candidate  Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81 Routers, and possibly other products, allow remote attackers to gain sensitive information and cause a denial of service via an SNMP query for the default community string "public," which causes the router to change its configuration and send SNMP trap information back to the system that initiated the query.  Proposed (20020315)  ACCEPT(2) Frech, Green | MODIFY(1) Foat | NOOP(2) Cole, Wall  Foat> Our testing showed that this vulnerabiltiy did not apply to BEFSR41 | routers.  View
4504  CVE-2002-0110  Candidate  Nevrona Designs MiraMail 1.04 and earlier stores authentication information such as POP usernames and passwords in plaintext in a .ini file, which allows an attacker to gain privileges by reading the passwords from the file.  Modified (20050328)  ACCEPT(4) Balinsky, Cole, Frech, Green | NOOP(2) Foat, Wall    View
4505  CVE-2002-0111  Entry  Directory traversal vulnerability in Funsoft Dino"s Webserver 1.2 and earlier allows remote attackers to read files or execute arbitrary commands via a .. (dot dot) in the URL.        View

Page 901 of 20943, showing 5 records out of 104715 total, starting on record 4501, ending on 4505

Actions