CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4651  CVE-2002-0259  Candidate  InstantServers MiniPortal 1.1.5 and earlier stores sensitive login and account data in plaintext in (1) .pwd files in the miniportal/apache directory, or (2) mplog.txt, which could allow local users to gain privileges.  Proposed (20020502)  ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall    View
4652  CVE-2002-0260  Candidate  Buffer overflow in InstantServers MiniPortal 1.1.5 and earlier allows remote attackers to execute arbitrary code via a long login name, which is not properly handled by the logging utility.  Proposed (20020502)  ACCEPT(3) Armstrong, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4653  CVE-2002-0261  Candidate  Directory traversal vulnerability in InstantServers MiniPortal 1.1.5 and earlier allows remote authenticated users to read arbitrary files via a ... (modified dot dot) in the GET command.  Proposed (20020502)  ACCEPT(3) Armstrong, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4654  CVE-2002-0262  Candidate  Directory traversal vulnerability in netget for Sybex E-Trainer web server allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.  Proposed (20020502)  ACCEPT(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
4655  CVE-2002-0263  Candidate  Buffer overflow in EasyBoard 2000 1.27 (aka EZboard) allows remote attackers to execute arbitrary code via a long boundary value in a multipart Content-Type header to (1) ezboard.cgi, (2) ezman.cgi, or (3) ezadmin.cgi.  Proposed (20020502)  ACCEPT(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View

Page 931 of 20943, showing 5 records out of 104715 total, starting on record 4651, ending on 4655

Actions