CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4876 | CVE-2002-0484 | Entry | move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system. | View | |||
4877 | CVE-2002-0485 | Candidate | Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients. | Modified (20040811) | ACCEPT(1) Prosser | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:nav-case-bypass-protection(9860) | Prosser> This issues was a continuation of an earlier reported issue | with non-RFC compliant MIME headers. The discover was testing a | non-updated version of NAV 2002 which was vulnerable to this and other | non-RFC compliant configurations. Updated and current releases are not | vulnerable to this problem | | http://securityresponse.symantec.com/avcenter/security/Content/2002.04.03.html | is the posted response to this issue. | View |
4878 | CVE-2002-0486 | Candidate | Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the cookies to gain privileges. | Proposed (20020611) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:xpede-password-weak-encryption(8614) | View |
4879 | CVE-2002-0487 | Candidate | Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by reading the password from the source file, e.g. from the browser"s cache. | Proposed (20020611) | ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall | View | |
4880 | CVE-2002-0488 | Entry | Linux Directory Penguin traceroute.pl CGI script 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the host parameter. | View |
Page 976 of 20943, showing 5 records out of 104715 total, starting on record 4876, ending on 4880