| OSVDB ID | Disclosure Date | Title |
|
693
Description:
zml.cgi contains a flaw that allows a remote attacker to view arbitrary files outside of the web path. The issue is due to the script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the "file" variable.
|
2001-12-31
|
Abe Timmerman zml.cgi file Parameter Traversal Arbitrary File Access
|
|
10851
Description:
Ipswitch IMail contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when an attacker gain administrator access to one domain, allowing a remote attacker to gain control of other domains and edit the info or delete it.
|
2001-12-31
|
Ipswitch IMail listadm1 Arbitrary Mail List/User Modification
|
|
10852
Description:
Ipswitch IMail aliasadmin contains a flaw that may allow a malicious user to gain administrative access to other domains hosted on the same server. The issue is triggered after the attacker has successfully authenticated to an administrative account on the vulnerable server. After they are authenticated, they may access any other domain hosted on the server, as the program only checks whether a given user is an administrator, and not specifically the administrator of the domain in question, before granting access. This may result in a loss of confidentiality, and integrity.
|
2001-12-31
|
Ipswitch IMail aliasadmin Arbitrary Mail List/User Modification
|
|
14226
Description:
A format string flaw exists in DayDream BBS. The program fails to properly sanitize format string specifiers (e.g., %s and %x). With a specially crafted request, a local attacker can crash the service or possibly execute arbitrary code.
|
2001-12-31
|
DayDream BBS ~#RA Control Code Format String
|
|
18237
Description:
SecureCRT SSH-1 Protocol is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a stack overflow. With a specially crafted input, a local attacker can potentially cause remote execution or crash.
|
2001-12-30
|
SecureCRT SSH-1 Protocol Multiple Field Remote Overflow
|
|
8843
Description:
(Description Provided by CVE) : Cisco ubr900 series routers that conform to the Data-over-Cable Service Interface Specifications (DOCSIS) standard must ship without SNMP access restrictions, which can allow remote attackers to read and write information to the MIB using arbitrary community strings.
|
2001-12-30
|
Cisco ubr900 Series Routers DOCSIS No SNMP Access Control
|
|
8960
Description:
(Description Provided by CVE) : Directory traversal vulnerability in lastlines.cgi for Last Lines 2.0 allows remote attackers to read arbitrary files via '..' sequences in the $error_log variable.
|
2001-12-30
|
Last Lines lastlines.cgi Double Dot Traversal Arbitrary File Access
|
|
10506
Description:
(Description Provided by CVE) : Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server.
|
2001-12-30
|
gzip Long File Name Overflow
|
|
14224
Description:
(Description Provided by CVE) : Matrix CGI vault Last Lines 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the $error_log variable.
|
2001-12-30
|
Matrix CGI vault Last Lines Arbitrary Command Execution
|
|
14225
Description:
(Description Provided by CVE) : Buffer overflows in DayDream BBS 2.9 through 2.13 allow remote attackers to possibly execute arbitrary code via the control codes (1) ~#MC, (2) ~#TF, or (3) ~#RA.
|
2001-12-30
|
DayDream BBS Control Code Arbitrary Code Execution
|
|
16981
Description:
(Description Provided by CVE) : Cherokee web server before 0.2.7 does not properly drop root privileges after binding to port 80, which could allow remote attackers to gain privileges via other vulnerabilities.
|
2001-12-29
|
Cherokee Web Server Port Bind Privilege Drop Weakness
|
|
16980
Description:
Cherokee Web Server contains a flaw that allows a remote attacker to read files outside of the web path. The issue is due to the program not properly sanitizing user input in browser requests, specifically traversal style attacks (../../). Due to a related flaw, Cherokee does not properly drop privileges, allowing an attacker to read any files on the system with root permissions.
|
2001-12-29
|
Cherokee Web Server URI Traversal Arbitrary File Access
|
|
12987
Description:
Unknown / Incomplete
|
2001-12-29
|
AWStats awstats.pl Direct Request Unauthorized Stat Update
|
|
20371
Description:
(Description Provided by CVE) : Point to Point Protocol daemon (pppd) in MacOS x 10.0 and 10.1 through 10.1.5 provides the username and password on the command line, which allows local users to obtain authentication information via the ps command.
|
2001-12-29
|
Mac OS pppd Command Line Authentication Credential Disclosure
|
|
6311
Description:
DeleGate contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate scripting commands within a "403 Forbidden" error page. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2001-12-28
|
DeleGate Error Page XSS
|
|
20193
Description:
(Description Provided by CVE) : smcboot in Sun SMC (Sun Management Center) 2.0 in Solaris 8 allows local users to delete arbitrary files via a symlink attack on /tmp/smc$SMC_PORT.
|
2001-12-28
|
Solaris SMC smcboot Symlink Arbitrary File Deletion
|
|
675
Description:
(Description Provided by CVE) : Oracle9iAS Web Cache 2.0.0.x allows remote attackers to cause a denial of service via (1) a request to TCP ports 1100, 4000, 4001, and 4002 with a large number of null characters, and (2) a request to TCP port 4000 with a large number of "." characters.
|
2001-12-28
|
Oracle Application Server Web Cache Null Character Request Remote DoS
|
|
694
Description:
(Description Provided by CVE) : Directory traversal vulnerability in phprocketaddin in Total PC Solutions PHP Rocket Add-in for FrontPage 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.
|
2001-12-28
|
PHP Rocket for FrontPage phprocketaddin page Parameter Traversal Arbitrary File Access
|
|
9411
Description:
(Description Provided by CVE) : Oracle9iAS Web Cache 2.0.0.x allows remote attackers to cause a denial of service via (1) a request to TCP ports 1100, 4000, 4001, and 4002 with a large number of null characters, and (2) a request to TCP port 4000 with a large number of "." characters.
|
2001-12-28
|
Oracle Application Server Web Cache Multiple Period Request webcached DoS
|
|
9461
Description:
(Description Provided by CVE) : An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml.
|
2001-12-28
|
Oracle Application Server Web Cache /webcache/webcache.xml Encrypted Password Local Disclosure
|
|
9462
Description:
(Description Provided by CVE) : An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml.
|
2001-12-28
|
Oracle Application Server Web Cache webcached Local Privilege Escalation
|
|
2013
Description:
(Description Provided by CVE) : Format string vulnerability in gpm-root in gpm 1.17.8 through 1.17.18 allows local users to gain root privileges.
|
2001-12-27
|
gpm-root Format String Privilege Escalation
|
|
5690
Description:
Namazu contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the index file name that is used when displaying hit counts. This could allow a user to create a specially crafted URL that would execute arbitrary JavaScript code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2001-12-27
|
Namazu Hit Number File Name XSS
|
|
5691
Description:
Namazu 2.0.9 contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the idxname parameter upon submission to the namazu script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2001-12-27
|
Namazu Error Message XSS
|
|
4661
Description:
(Description Provided by CVE) : globals.php in PHP Address before 0.2f, with the PHP allow_url_fopen and register_globals variables enabled, allows remote attackers to execute arbitrary PHP code via a URL to the code in the LangCookie parameter.
|
2001-12-26
|
PHPAddress globals.php LangCookie Variable Arbitrary Code Execution
|
|
10168
Description:
(Description Provided by CVE) : Hughes Technology Mini SQL 2.0.10 through 2.0.12 allows local users to cause a denial of service by creating a very large array in a table, which causes miniSQL to crash when the table is queried.
|
2001-12-26
|
Hughes Technology Mini SQL Large Character Array DoS
|
|
14228
Description:
(Description Provided by CVE) : The web administration server for ELSA Lancom 1100 Office does not require authentication, which allows arbitrary remote attackers to gain administrative privileges by connecting to the server.
|
2001-12-26
|
ELSA Lancom Office Web Admin Server Admin Password Remote Disclosure
|
|
20370
Description:
(Description Provided by CVE) : Format string vulnerability in libvanessa_logger 0.0.1 in Perdition 0.1.8 allows remote attackers to execute arbitrary code via format string specifiers in the __vanessa_logger_log function.
|
2001-12-25
|
Perdition libvanessa_logger __vanessa_logger_log Function Format String
|
|
10167
Description:
AdCycle contains a flaw that will allow a remote attacker to inject arbitrary SQL code. No further details have been provided.
|
2001-12-25
|
AdCycle Unspecified SQL Injection
|
|
43291
Description:
Unknown / Incomplete
|
2001-12-24
|
Ariadne CMS pinp Unspecified Issue
|
|
11783
Description:
(Description Provided by CVE) : get_input in adrotate.pm for Les VanBrunt AdRotate Pro 2.0 allows remote attackers to modify the database and possibly execute arbitrary commands via a SQL code injection attack.
|
2001-12-23
|
Les VanBrunt AdRotate Pro adrotate.pm SQL Injection
|
|
2012
Description:
(Description Provided by CVE) : Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code.
|
2001-12-21
|
Stunnel -n Option Client Negotiation Protocol Remote Format String
|
|
2011
Description:
(Description Provided by CVE) : Atmel Firmware 1.3 Wireless Access Point (WAP) allows remote attackers to cause a denial of service via a SNMP request with (1) a community string other than "public" or (2) an unknown OID, which causes the WAP to deny subsequent SNMP requests.
|
2001-12-21
|
Atmel SNMP public Community or Unknown OID DoS
|
|
9403
Description:
(Description Provided by CVE) : D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point stores the administrative password in plaintext in the default Management Information Base (MIB), which allows remote attackers to gain administrative privileges.
|
2001-12-21
|
D-Link DWL-1000AP MIB Cleartext Admin Password
|
|
11643
Description:
(Description Provided by CVE) : Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP address and a valid account name for the domain.
|
2001-12-21
|
Plesk Server Administrator PHP Source Disclosure
|
|
59517
Description:
(Description Provided by CVE) : D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point uses a default SNMP community string of 'public' which allows remote attackers to gain sensitive information.
|
2001-12-21
|
D-Link DWL-1000AP Default SNMP Community String
|
|
20367
Description:
(Description Provided by CVE) : Windows XP with fast user switching and account lockout enabled allows local users to deny user account access by setting the fast user switch to the same user (self) multiple times, which causes other accounts to be locked out.
|
2001-12-20
|
Microsoft Windows XP Fast User Switching Arbitrary Account Lockout
|
|
20366
Description:
(Description Provided by CVE) : The Remote Desktop client in Windows XP sends the most recent user account name in cleartext, which could allow remote attackers to obtain terminal server user account names via sniffing.
|
2001-12-20
|
Microsoft Windows XP Remote Desktop Client Cleartext Account Name Transmission
|
|
31321
Description:
(Description Provided by CVE) : Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via self.location.
|
2001-12-20
|
Microsoft IE Javascript self.location Refresh DoS
|
|
692
Description:
A local overflow exists in Windows. The Universal Plug and Play Server fails to validate the location field in NOTIFY packets resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2001-12-20
|
Microsoft Windows Universal Plug and Play NOTIFY Overflow
|