|
CVE-2000-1244
|
High
|
2000-12-31
|
Not applicable
|
Working exploit published
|
Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP header is missing the "From" field, which allows remote attackers to bypass virus protection.
|
|
CVE-2000-1243
|
Medium
|
2000-12-31
|
Not applicable
|
No public exploit
|
Privacy leak in Dansie Shopping Cart 3.04, and probably earlier versions, sends sensitive information such as user credentials to an e-mail address controlled by the product developers.
|
|
CVE-2000-1242
|
High
|
2000-12-31
|
Not applicable
|
No public exploit
|
The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain system access.
|
|
CVE-2000-1241
|
High
|
2000-12-31
|
Not applicable
|
No public exploit
|
Unspecified vulnerability in Haakon Nilsen simple, integrated publishing system (SIPS) before 0.2.4 has an unknown impact and attack vectors, related to a "grave security fault."
|
|
CVE-2000-1240
|
Medium
|
2000-12-31
|
Not applicable
|
No public exploit
|
Unspecified vulnerability in siteman.php3 in AnyPortal(php) before 22 APR 00 allows remote attackers to obtain sensitive information via unknown attack vectors, which reveal the absolute path. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
|
|
CVE-2000-1239
|
High
|
2000-12-31
|
Not applicable
|
No public exploit
|
The HTTP interface of Tivoli Lightweight Client Framework (LCF) in IBM Tivoli Management Framework 3.7.1 sets http_disable to zero at install time, which allows remote authenticated users to bypass file permissions on Tivoli Endpoint Configuration data files via an unspecified manipulation of log files.
|
|
CVE-2000-1238
|
High
|
2000-12-31
|
Not applicable
|
No public exploit
|
BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages.
|
|
CVE-2000-1237
|
Medium
|
2000-12-31
|
Not applicable
|
No public exploit
|
The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote attackers to determine valid usernames and conduct brute force password guessing.
|
|
CVE-2000-1236
|
High
|
2000-12-31
|
Not applicable
|
No public exploit
|
SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL.
|
|
CVE-2000-1235
|
Medium
|
2000-12-31
|
Not applicable
|
No public exploit
|
The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files.
|
|
CVE-2000-1234
|
Medium
|
2000-12-31
|
Not applicable
|
Working exploit published
|
violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the Mod and ForumName parameters.
|
|
CVE-2000-1233
|
High
|
2000-12-31
|
Not applicable
|
No public exploit
|
SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary SQL queries via the sSQL parameter.
|
|
CVE-2000-1232
|
Medium
|
2000-12-31
|
Not applicable
|
No public exploit
|
upgrade.php3 in Phorum 3.0.7 could allow remote attackers to modify certain Phorum database tables via an unknown method.
|
|
CVE-2000-1231
|
Medium
|
2000-12-31
|
Not applicable
|
No public exploit
|
code.php3 in Phorum 3.0.7 allows remote attackers to read arbitrary files in the phorum directory via the query string.
|
|
CVE-2000-1230
|
Medium
|
2000-12-31
|
Not applicable
|
Working exploit published
|
Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to "boogieman".
|
|
CVE-2000-1229
|
Medium
|
2000-12-31
|
Not applicable
|
No public exploit
|
Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (dot dot) sequences in the default .langfile name field in the Master Settings administrative function, which causes the file to be displayed in admin.php3.
|
|
CVE-2000-1228
|
Medium
|
2000-12-31
|
Not applicable
|
Working exploit published
|
Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.
|
|
CVE-2000-1227
|
Medium
|
2000-12-31
|
Not applicable
|
No public exploit
|
Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back.
|
|
CVE-2000-1226
|
Medium
|
2000-12-31
|
Not applicable
|
No public exploit
|
Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service (crash) by sending non-IP protocols that Snort does not know about, as demonstrated by an nmap protocol scan.
|
|
CVE-2000-1225
|
Medium
|
2000-12-31
|
Not applicable
|
No public exploit
|
Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain sensitive configuration information about the web server by accessing the program.
|
|
CVE-1999-0307
|
High
|
2000-12-20
|
Not applicable
|
No public exploit
|
Buffer overflow in HP-UX cstm program allows local users to gain root privileges.
|
|
CVE-2000-0997
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges.
|
|
CVE-2000-0996
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell.
|
|
CVE-2000-0995
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name.
|
|
CVE-2000-0994
|
High
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable.
|
|
CVE-2000-0993
|
High
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.
|
|
CVE-2000-0992
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack.
|
|
CVE-2000-0991
|
High
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Buffer overflow in Hilgraeve, Inc. HyperTerminal client on Windows 98, ME, and 2000 allows remote attackers to execute arbitrary commands via a long telnet URL, aka the "HyperTerminal Buffer Overflow" vulnerability.
|
|
CVE-2000-0990
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
cmd5checkpw 0.21 and earlier allows remote attackers to cause a denial of service via an "SMTP AUTH" command with an unknown username.
|
|
CVE-2000-0989
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Buffer overflow in Intel InBusiness eMail Station 1.04.87 POP service allows remote attackers to cause a denial of service and possibly execute commands via a long username.
|
|
CVE-2000-0988
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
WinU 1.0 through 5.1 has a backdoor password that allows remote attackers to gain access to its administrative interface and modify configuration.
|
|
CVE-2000-0987
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter.
|
|
CVE-2000-0986
|
Medium
|
2000-12-19
|
Not applicable
|
No public exploit
|
Buffer overflow in Oracle 8.1.5 applications such as names, namesctl, onrsd, osslogin, tnslsnr, tnsping, trcasst, and trcroute possibly allow local users to gain privileges via a long ORACLE_HOME environmental variable.
|
|
CVE-2000-0985
|
High
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO" command.
|
|
CVE-2000-0984
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string.
|
|
CVE-2000-0983
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability.
|
|
CVE-2000-0982
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credentials" vulnerability.
|
|
CVE-2000-0981
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.
|
|
CVE-2000-0980
|
Medium
|
2000-12-19
|
Not applicable
|
No public exploit
|
NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network.
|
|
CVE-2000-0979
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability.
|
|
CVE-2000-0978
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
bbd server in Big Brother System and Network Monitor before 1.5c2 allows remote attackers to execute arbitrary commands via the "&" shell metacharacter.
|
|
CVE-2000-0977
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email to the address specified in the "email" parameter.
|
|
CVE-2000-0976
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter.
|
|
CVE-2000-0975
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrary files via a .. (dot dot) attack.
|
|
CVE-2000-0974
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection.
|
|
CVE-2000-0973
|
High
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbitrary commands by forcing a long error message to be generated.
|
|
CVE-2000-0972
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.
|
|
CVE-2000-0971
|
High
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long "RCPT TO" or "MAIL FROM" command.
|
|
CVE-2000-0970
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.
|
|
CVE-2000-0969
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon.
|
|
CVE-2000-0968
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
Buffer overflow in Half Life dedicated server before build 3104 allows remote attackers to execute arbitrary commands via a long rcon command.
|
|
CVE-2000-0967
|
High
|
2000-12-19
|
Not applicable
|
Working exploit published
|
PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.
|
|
CVE-2000-0966
|
Medium
|
2000-12-19
|
Not applicable
|
No public exploit
|
Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges.
|
|
CVE-2000-0965
|
Medium
|
2000-12-19
|
Not applicable
|
No public exploit
|
The NSAPI plugins for TGA and the Java Servlet proxy in HP-UX VVOS 10.24 and 11.04 allows an attacker to cause a denial of service (high CPU utilization).
|
|
CVE-2000-0964
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
Buffer overflow in the web administration service for the HiNet LP5100 IP-phone allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.
|
|
CVE-2000-0963
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.
|
|
CVE-2000-0962
|
Medium
|
2000-12-19
|
Not applicable
|
No public exploit
|
The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service.
|
|
CVE-2000-0961
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST command.
|
|
CVE-2000-0960
|
Medium
|
2000-12-19
|
Not applicable
|
No public exploit
|
The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.
|
|
CVE-2000-0959
|
Low
|
2000-12-19
|
Not applicable
|
No public exploit
|
glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.
|
|
CVE-2000-0958
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window.
|
|
CVE-2000-0957
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes.
|
|
CVE-2000-0956
|
Medium
|
2000-12-19
|
Not applicable
|
No public exploit
|
cyrus-sasl before 1.5.24 in Red Hat Linux 7.0 does not properly verify the authorization for a local user, which could allow the users to bypass specified access restrictions.
|
|
CVE-2000-0955
|
High
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges.
|
|
CVE-2000-0954
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
Shambala Server 4.5 stores passwords in plaintext, which could allow local users to obtain the passwords and compromise the server.
|
|
CVE-2000-0953
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Shambala Server 4.5 allows remote attackers to cause a denial of service by opening then closing a connection.
|
|
CVE-2000-0952
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
global.cgi CGI program in Global 3.55 and earlier on NetBSD allows remote attackers to execute arbitrary commands via shell metacharacters.
|
|
CVE-2000-0951
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search.
|
|
CVE-2000-0950
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
Format string vulnerability in x-gw in TIS Firewall Toolkit (FWTK) allows local users to execute arbitrary commands via a malformed display name.
|
|
CVE-2000-0949
|
High
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.
|
|
CVE-2000-0948
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack.
|
|
CVE-2000-0947
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.
|
|
CVE-2000-0946
|
Medium
|
2000-12-19
|
Not applicable
|
No public exploit
|
Compaq Easy Access Keyboard software 1.3 does not properly disable access to custom buttons when the screen is locked, which could allow an attacker to gain privileges or execute programs without authorization.
|
|
CVE-2000-0945
|
High
|
2000-12-19
|
Not applicable
|
Working exploit published
|
The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory.
|
|
CVE-2000-0944
|
Critical
|
2000-12-19
|
Not applicable
|
Working exploit published
|
CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password.
|
|
CVE-2000-0943
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
Buffer overflow in bftp daemon (bftpd) 1.0.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER command.
|
|
CVE-2000-0942
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.
|
|
CVE-2000-0941
|
High
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter.
|
|
CVE-2000-0940
|
Medium
|
2000-12-19
|
Not applicable
|
No public exploit
|
Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter.
|
|
CVE-2000-0939
|
Medium
|
2000-12-19
|
Not applicable
|
No public exploit
|
Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and forcing it to restart.
|
|
CVE-2000-0938
|
Medium
|
2000-12-19
|
Not applicable
|
No public exploit
|
Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided versus an invalid name, which allows remote attackers to identify valid users on the server.
|
|
CVE-2000-0937
|
High
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which allows remote attackers to conduct brute force password guessing attacks.
|
|
CVE-2000-0936
|
Low
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, which allows local users to read sensitive information such as user names and passwords.
|
|
CVE-2000-0935
|
High
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file.
|
|
CVE-2000-0934
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
Glint in Red Hat Linux 5.2 allows local users to overwrite arbitrary files and cause a denial of service via a symlink attack.
|
|
CVE-2000-0933
|
Medium
|
2000-12-19
|
Not applicable
|
No public exploit
|
The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recognition" vulnerability.
|
|
CVE-2000-0932
|
Medium
|
2000-12-19
|
Not applicable
|
No public exploit
|
MAILsweeper for SMTP 3.x does not properly handle corrupt CDA documents in a ZIP file and hangs, which allows remote attackers to cause a denial of service.
|
|
CVE-2000-0931
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
Buffer overflow in Pegasus Mail 3.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long email message containing binary data.
|
|
CVE-2000-0930
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch.
|
|
CVE-2000-0929
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability.
|
|
CVE-2000-0928
|
Low
|
2000-12-19
|
Not applicable
|
No public exploit
|
WQuinn QuotaAdvisor 4.1 allows users to list directories and files by running a report on the targeted shares.
|
|
CVE-2000-0927
|
Medium
|
2000-12-19
|
Not applicable
|
No public exploit
|
WQuinn QuotaAdvisor 4.1 does not properly record file sizes if they are stored in alternative data streams, which allows users to bypass quota restrictions.
|
|
CVE-2000-0926
|
High
|
2000-12-19
|
Not applicable
|
Working exploit published
|
SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the "Price" hidden form variable.
|
|
CVE-2000-0925
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information.
|
|
CVE-2000-0924
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Directory traversal vulnerability in search.cgi CGI script in Armada Master Index allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catigory" parameter.
|
|
CVE-2000-0923
|
High
|
2000-12-19
|
Not applicable
|
No public exploit
|
authenticate.cgi CGI program in Aplio PRO allows remote attackers to execute arbitrary commands via shell metacharacters in the password parameter.
|
|
CVE-2000-0922
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the newpage parameter.
|
|
CVE-2000-0921
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.
|
|
CVE-2000-0920
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "."
|
|
CVE-2000-0919
|
Medium
|
2000-12-19
|
Not applicable
|
Working exploit published
|
Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.
|