CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4696 | CVE-2002-0304 | Candidate | Lil HTTP Server 2.1 allows remote attackers to read password-protected files via a /./ in the HTTP request. | Modified (20050705) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall | Christey> VULNWATCH:20020222 [VulnWatch] SecurityOffice Security Advisories: Essentia and LilHTTP web servers | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0051.html | XF:lilhttp-protected-file-access(8247) | URL:http://www.iss.net/security_center/static/8247.php | BID:4153 | URL:http://www.securityfocus.com/bid/4153 | Frech> XF:lilhttp-protected-file-access(8247) | View |
4697 | CVE-2002-0305 | Candidate | Zero One Tech (ZOT) P100s print server does not properly disable the SNMP service or change the default password, which could leave the server open to attack without the administrator"s knowledge. | Modified (20050528) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:zot-default-snmp-string(8270) | View |
4698 | CVE-2002-0306 | Candidate | ans.pl in Avenger"s News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter. | Proposed (20020502) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:ans-plugin-execute-commands(8256) | View |
4699 | CVE-2002-0307 | Candidate | Directory traversal vulnerability in ans.pl in Avenger"s News System (ANS) 2.11 and earlier allows remote attackers to determine the existence of arbitrary files or execute any Perl program on the system via a .. (dot dot) in the p parameter, which reads the target file and attempts to execute the line using Perl"s eval function. | Proposed (20020502) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:ans-plugin-execute-commands(8256) | View |
4700 | CVE-2002-0308 | Candidate | admin.asp in AdMentor 2.11 allows remote attackers to bypass authentication and gain privileges via a SQL injection attack on the Login and Password arguments. | Modified (20050527) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:admentor-asp-gain-access(8245) | View |
Page 940 of 20943, showing 5 records out of 104715 total, starting on record 4696, ending on 4700