CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4878  CVE-2002-0486  Candidate  Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the cookies to gain privileges.  Proposed (20020611)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:xpede-password-weak-encryption(8614)  View
4879  CVE-2002-0487  Candidate  Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by reading the password from the source file, e.g. from the browser"s cache.  Proposed (20020611)  ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall    View
4881  CVE-2002-0489  Candidate  Linux Directory Penguin NsLookup CGI script (nslookup.pl) 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the (1) query or (2) type parameters.  Proposed (20020611)  ACCEPT(2) Foat, Frech | NOOP(4) Cole, Cox, Green, Wall    View
4883  CVE-2002-0491  Candidate  admin.php in AlGuest 1.0 guestbook checks for the existence of the admin cookie to authenticate the AlGuest administrator, which allows remote attackers to bypass the authentication and gain privileges by setting the admin cookie to an arbitrary value.  Proposed (20020611)  ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall    View
4884  CVE-2002-0492  Candidate  dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.  Proposed (20020611)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:dscshop-cgi-delete-setup(9854)  View

Page 91 of 20943, showing 5 records out of 104715 total, starting on record 451, ending on 455

Actions