CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4801  CVE-2002-0409  Candidate  orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.  Proposed (20020611)  ACCEPT(2) Alderson, Wall | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Frech  Alderson> This is a whole new breed of exposure... vulnerable example code | leading to cross industry and application exposure. This to a point made by | Gene Kim recently "they keep deploying problems faster than we can deploy | solutions".  View
4802  CVE-2002-0410  Candidate  send_message.php in AeroMail before 1.45 allows remote attackers to read arbitrary files on the server, instead of just uploaded files, via an attachment that modifies the filename to be uploaded.  Proposed (20020611)  ACCEPT(4) Alderson, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4803  CVE-2002-0411  Candidate  Cross-site scripting vulnerability in message.php for AeroMail before 1.45 allows remote attackers to execute Javascript as an AeroMail user via an email message with the script in the Subject line.  Proposed (20020611)  ACCEPT(4) Alderson, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4804  CVE-2002-0412  Entry  Format string vulnerability in TraceEvent function for ntop before 2.1 allows remote attackers to execute arbitrary code by causing format strings to be injected into calls to the syslog function, via (1) an HTTP GET request, (2) a user name in HTTP authentication, or (3) a password in HTTP authentication.        View
4805  CVE-2002-0413  Candidate  Cross-site scripting vulnerability in ReBB allows remote attackers to execute arbitrary Javascript and steal cookies via an IMG tag whose URL includes the malicious script.  Proposed (20020611)  ACCEPT(2) Alderson, Frech | NOOP(4) Cole, Cox, Foat, Wall    View

Page 961 of 20943, showing 5 records out of 104715 total, starting on record 4801, ending on 4805

Actions