VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 20 hours ago
Reset
More filters (2)
Columns
Published from 2000-01-01Published to 2000-12-31
Overview 1,020 matches · 5 in RASP scope · 0 protected · 0 KEV · 431 public PoC · 0 CISA SSVC · 20 EPSS ≥ 0.5 · 0 disputed
1,020matches 5in RASP scope0.5% 0protected0.0% 0KEV0.0% 431public PoC42.3% 0CISA SSVC0.0% 20EPSS ≥ 0.52.0% 0disputed0.0%
Protected by RASP 0 0.0% Rule in development 0 0.0% Mitigation candidate 3 0.3% No exploit published 0 0.0% No fix identified 2 0.2% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 1,013 99.3% Out of RASP scope 1 0.1% Rejected 1 0.1%
blocked by ARMR today 0 0.0% not blocked 1,020 100.0% not established 0 0.0% unrecorded 0 0.0%
split by peak 212 / month
Unknown: 1None: 0Low: 96Medium: 467High: 454Critical: 2 Rejected: 1Out of RASP scope: 1Not applicable: 1,013Queued for review: 0Mitigated by environment configuration: 0No fix identified: 2No exploit published: 0Mitigation candidate: 3Rule in development: 0Protected by RASP: 0 unrecorded: 0not established: 0not blocked: 1,020blocked by ARMR today: 0 No public exploit: 588Forecast only: 1Proof of concept only: 0Working exploit published: 431Exploited in the wild: 0 January 2000: 68 CVEs February 2000: 86 CVEs March 2000: 57 CVEs April 2000: 79 CVEs May 2000: 110 CVEs June 2000: 119 CVEs July 2000: 74 CVEs August 2000: 3 CVEs September 2000: 3 CVEs October 2000: 136 CVEs November 2000: 73 CVEs December 2000: 212 CVEs
Jan 00Feb 00Mar 00Apr 00May 00Jun 00Jul 00Aug 00Sep 00Oct 00Nov 00Dec 00
1,020 matches CSV JSON ‹ prev page 1 of 11 next ›
CVE Severity Published Status Exploitation Description
CVE-2000-1244 High 2000-12-31 Not applicable Working exploit published Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP header is missing the "From" field, which allows remote attackers to bypass virus protection.
CVE-2000-1243 Medium 2000-12-31 Not applicable No public exploit Privacy leak in Dansie Shopping Cart 3.04, and probably earlier versions, sends sensitive information such as user credentials to an e-mail address controlled by the product developers.
CVE-2000-1242 High 2000-12-31 Not applicable No public exploit The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain system access.
CVE-2000-1241 High 2000-12-31 Not applicable No public exploit Unspecified vulnerability in Haakon Nilsen simple, integrated publishing system (SIPS) before 0.2.4 has an unknown impact and attack vectors, related to a "grave security fault."
CVE-2000-1240 Medium 2000-12-31 Not applicable No public exploit Unspecified vulnerability in siteman.php3 in AnyPortal(php) before 22 APR 00 allows remote attackers to obtain sensitive information via unknown attack vectors, which reveal the absolute path. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
CVE-2000-1239 High 2000-12-31 Not applicable No public exploit The HTTP interface of Tivoli Lightweight Client Framework (LCF) in IBM Tivoli Management Framework 3.7.1 sets http_disable to zero at install time, which allows remote authenticated users to bypass file permissions on Tivoli Endpoint Configuration data files via an unspecified manipulation of log files.
CVE-2000-1238 High 2000-12-31 Not applicable No public exploit BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages.
CVE-2000-1237 Medium 2000-12-31 Not applicable No public exploit The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote attackers to determine valid usernames and conduct brute force password guessing.
CVE-2000-1236 High 2000-12-31 Not applicable No public exploit SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL.
CVE-2000-1235 Medium 2000-12-31 Not applicable No public exploit The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files.
CVE-2000-1234 Medium 2000-12-31 Not applicable Working exploit published violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the Mod and ForumName parameters.
CVE-2000-1233 High 2000-12-31 Not applicable No public exploit SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary SQL queries via the sSQL parameter.
CVE-2000-1232 Medium 2000-12-31 Not applicable No public exploit upgrade.php3 in Phorum 3.0.7 could allow remote attackers to modify certain Phorum database tables via an unknown method.
CVE-2000-1231 Medium 2000-12-31 Not applicable No public exploit code.php3 in Phorum 3.0.7 allows remote attackers to read arbitrary files in the phorum directory via the query string.
CVE-2000-1230 Medium 2000-12-31 Not applicable Working exploit published Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to "boogieman".
CVE-2000-1229 Medium 2000-12-31 Not applicable No public exploit Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (dot dot) sequences in the default .langfile name field in the Master Settings administrative function, which causes the file to be displayed in admin.php3.
CVE-2000-1228 Medium 2000-12-31 Not applicable Working exploit published Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.
CVE-2000-1227 Medium 2000-12-31 Not applicable No public exploit Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back.
CVE-2000-1226 Medium 2000-12-31 Not applicable No public exploit Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service (crash) by sending non-IP protocols that Snort does not know about, as demonstrated by an nmap protocol scan.
CVE-2000-1225 Medium 2000-12-31 Not applicable No public exploit Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain sensitive configuration information about the web server by accessing the program.
CVE-1999-0307 High 2000-12-20 Not applicable No public exploit Buffer overflow in HP-UX cstm program allows local users to gain root privileges.
CVE-2000-0997 High 2000-12-19 Not applicable No public exploit Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges.
CVE-2000-0996 High 2000-12-19 Not applicable No public exploit Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell.
CVE-2000-0995 High 2000-12-19 Not applicable No public exploit Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name.
CVE-2000-0994 High 2000-12-19 Not applicable Working exploit published Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable.
CVE-2000-0993 High 2000-12-19 Not applicable Working exploit published Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.
CVE-2000-0992 Medium 2000-12-19 Not applicable Working exploit published Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack.
CVE-2000-0991 High 2000-12-19 Not applicable Working exploit published Buffer overflow in Hilgraeve, Inc. HyperTerminal client on Windows 98, ME, and 2000 allows remote attackers to execute arbitrary commands via a long telnet URL, aka the "HyperTerminal Buffer Overflow" vulnerability.
CVE-2000-0990 High 2000-12-19 Not applicable No public exploit cmd5checkpw 0.21 and earlier allows remote attackers to cause a denial of service via an "SMTP AUTH" command with an unknown username.
CVE-2000-0989 Medium 2000-12-19 Not applicable Working exploit published Buffer overflow in Intel InBusiness eMail Station 1.04.87 POP service allows remote attackers to cause a denial of service and possibly execute commands via a long username.
CVE-2000-0988 High 2000-12-19 Not applicable No public exploit WinU 1.0 through 5.1 has a backdoor password that allows remote attackers to gain access to its administrative interface and modify configuration.
CVE-2000-0987 Medium 2000-12-19 Not applicable Working exploit published Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter.
CVE-2000-0986 Medium 2000-12-19 Not applicable No public exploit Buffer overflow in Oracle 8.1.5 applications such as names, namesctl, onrsd, osslogin, tnslsnr, tnsping, trcasst, and trcroute possibly allow local users to gain privileges via a long ORACLE_HOME environmental variable.
CVE-2000-0985 High 2000-12-19 Not applicable Working exploit published Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO" command.
CVE-2000-0984 Medium 2000-12-19 Not applicable Working exploit published The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string.
CVE-2000-0983 Medium 2000-12-19 Not applicable Working exploit published Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability.
CVE-2000-0982 High 2000-12-19 Not applicable No public exploit Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credentials" vulnerability.
CVE-2000-0981 High 2000-12-19 Not applicable No public exploit MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.
CVE-2000-0980 Medium 2000-12-19 Not applicable No public exploit NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network.
CVE-2000-0979 Medium 2000-12-19 Not applicable Working exploit published File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability.
CVE-2000-0978 High 2000-12-19 Not applicable No public exploit bbd server in Big Brother System and Network Monitor before 1.5c2 allows remote attackers to execute arbitrary commands via the "&" shell metacharacter.
CVE-2000-0977 Medium 2000-12-19 Not applicable Working exploit published mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email to the address specified in the "email" parameter.
CVE-2000-0976 Medium 2000-12-19 Not applicable Working exploit published Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter.
CVE-2000-0975 Medium 2000-12-19 Not applicable Working exploit published Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-2000-0974 High 2000-12-19 Not applicable No public exploit GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection.
CVE-2000-0973 High 2000-12-19 Not applicable Working exploit published Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbitrary commands by forcing a long error message to be generated.
CVE-2000-0972 Medium 2000-12-19 Not applicable Working exploit published HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.
CVE-2000-0971 High 2000-12-19 Not applicable Working exploit published Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long "RCPT TO" or "MAIL FROM" command.
CVE-2000-0970 High 2000-12-19 Not applicable No public exploit IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.
CVE-2000-0969 High 2000-12-19 Not applicable No public exploit Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon.
CVE-2000-0968 High 2000-12-19 Not applicable No public exploit Buffer overflow in Half Life dedicated server before build 3104 allows remote attackers to execute arbitrary commands via a long rcon command.
CVE-2000-0967 High 2000-12-19 Not applicable Working exploit published PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.
CVE-2000-0966 Medium 2000-12-19 Not applicable No public exploit Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges.
CVE-2000-0965 Medium 2000-12-19 Not applicable No public exploit The NSAPI plugins for TGA and the Java Servlet proxy in HP-UX VVOS 10.24 and 11.04 allows an attacker to cause a denial of service (high CPU utilization).
CVE-2000-0964 High 2000-12-19 Not applicable No public exploit Buffer overflow in the web administration service for the HiNet LP5100 IP-phone allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.
CVE-2000-0963 High 2000-12-19 Not applicable No public exploit Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.
CVE-2000-0962 Medium 2000-12-19 Not applicable No public exploit The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service.
CVE-2000-0961 High 2000-12-19 Not applicable No public exploit Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST command.
CVE-2000-0960 Medium 2000-12-19 Not applicable No public exploit The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.
CVE-2000-0959 Low 2000-12-19 Not applicable No public exploit glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.
CVE-2000-0958 Medium 2000-12-19 Not applicable Working exploit published HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window.
CVE-2000-0957 High 2000-12-19 Not applicable No public exploit The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes.
CVE-2000-0956 Medium 2000-12-19 Not applicable No public exploit cyrus-sasl before 1.5.24 in Red Hat Linux 7.0 does not properly verify the authorization for a local user, which could allow the users to bypass specified access restrictions.
CVE-2000-0955 High 2000-12-19 Not applicable Working exploit published Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges.
CVE-2000-0954 High 2000-12-19 Not applicable No public exploit Shambala Server 4.5 stores passwords in plaintext, which could allow local users to obtain the passwords and compromise the server.
CVE-2000-0953 Medium 2000-12-19 Not applicable Working exploit published Shambala Server 4.5 allows remote attackers to cause a denial of service by opening then closing a connection.
CVE-2000-0952 High 2000-12-19 Not applicable No public exploit global.cgi CGI program in Global 3.55 and earlier on NetBSD allows remote attackers to execute arbitrary commands via shell metacharacters.
CVE-2000-0951 Medium 2000-12-19 Not applicable Working exploit published A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search.
CVE-2000-0950 High 2000-12-19 Not applicable No public exploit Format string vulnerability in x-gw in TIS Firewall Toolkit (FWTK) allows local users to execute arbitrary commands via a malformed display name.
CVE-2000-0949 High 2000-12-19 Not applicable Working exploit published Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.
CVE-2000-0948 High 2000-12-19 Not applicable No public exploit GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack.
CVE-2000-0947 High 2000-12-19 Not applicable No public exploit Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.
CVE-2000-0946 Medium 2000-12-19 Not applicable No public exploit Compaq Easy Access Keyboard software 1.3 does not properly disable access to custom buttons when the screen is locked, which could allow an attacker to gain privileges or execute programs without authorization.
CVE-2000-0945 High 2000-12-19 Not applicable Working exploit published The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory.
CVE-2000-0944 Critical 2000-12-19 Not applicable Working exploit published CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password.
CVE-2000-0943 High 2000-12-19 Not applicable No public exploit Buffer overflow in bftp daemon (bftpd) 1.0.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER command.
CVE-2000-0942 Medium 2000-12-19 Not applicable Working exploit published The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.
CVE-2000-0941 High 2000-12-19 Not applicable Working exploit published Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter.
CVE-2000-0940 Medium 2000-12-19 Not applicable No public exploit Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter.
CVE-2000-0939 Medium 2000-12-19 Not applicable No public exploit Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and forcing it to restart.
CVE-2000-0938 Medium 2000-12-19 Not applicable No public exploit Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided versus an invalid name, which allows remote attackers to identify valid users on the server.
CVE-2000-0937 High 2000-12-19 Not applicable Working exploit published Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which allows remote attackers to conduct brute force password guessing attacks.
CVE-2000-0936 Low 2000-12-19 Not applicable Working exploit published Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, which allows local users to read sensitive information such as user names and passwords.
CVE-2000-0935 High 2000-12-19 Not applicable Working exploit published Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file.
CVE-2000-0934 High 2000-12-19 Not applicable No public exploit Glint in Red Hat Linux 5.2 allows local users to overwrite arbitrary files and cause a denial of service via a symlink attack.
CVE-2000-0933 Medium 2000-12-19 Not applicable No public exploit The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recognition" vulnerability.
CVE-2000-0932 Medium 2000-12-19 Not applicable No public exploit MAILsweeper for SMTP 3.x does not properly handle corrupt CDA documents in a ZIP file and hangs, which allows remote attackers to cause a denial of service.
CVE-2000-0931 High 2000-12-19 Not applicable No public exploit Buffer overflow in Pegasus Mail 3.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long email message containing binary data.
CVE-2000-0930 Medium 2000-12-19 Not applicable Working exploit published Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch.
CVE-2000-0929 Medium 2000-12-19 Not applicable Working exploit published Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability.
CVE-2000-0928 Low 2000-12-19 Not applicable No public exploit WQuinn QuotaAdvisor 4.1 allows users to list directories and files by running a report on the targeted shares.
CVE-2000-0927 Medium 2000-12-19 Not applicable No public exploit WQuinn QuotaAdvisor 4.1 does not properly record file sizes if they are stored in alternative data streams, which allows users to bypass quota restrictions.
CVE-2000-0926 High 2000-12-19 Not applicable Working exploit published SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the "Price" hidden form variable.
CVE-2000-0925 Medium 2000-12-19 Not applicable Working exploit published The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information.
CVE-2000-0924 Medium 2000-12-19 Not applicable Working exploit published Directory traversal vulnerability in search.cgi CGI script in Armada Master Index allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catigory" parameter.
CVE-2000-0923 High 2000-12-19 Not applicable No public exploit authenticate.cgi CGI program in Aplio PRO allows remote attackers to execute arbitrary commands via shell metacharacters in the password parameter.
CVE-2000-0922 Medium 2000-12-19 Not applicable Working exploit published Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the newpage parameter.
CVE-2000-0921 Medium 2000-12-19 Not applicable Working exploit published Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.
CVE-2000-0920 Medium 2000-12-19 Not applicable Working exploit published Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "."
CVE-2000-0919 Medium 2000-12-19 Not applicable Working exploit published Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.
‹ prev page 1 of 11 next ›