Latest CVE Feed
-
5.0
MEDIUMCVE-2000-1243
Privacy leak in Dansie Shopping Cart 3.04, and probably earlier versions, sends sensitive information such as user credentials to an e-mail address controlled by the product developers.... Read more
Affected Products : shopping_cart- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1231
code.php3 in Phorum 3.0.7 allows remote attackers to read arbitrary files in the phorum directory via the query string.... Read more
Affected Products : phorum- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1227
Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back.... Read more
- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1240
Unspecified vulnerability in siteman.php3 in AnyPortal(php) before 22 APR 00 allows remote attackers to obtain sensitive information via unknown attack vectors, which reveal the absolute path. NOTE: the provenance of this information is unknown; the deta... Read more
Affected Products : anyportal_php- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1229
Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (dot dot) sequences in the default .langfile name field in the Master Settings administrative function, which causes the file to be disp... Read more
Affected Products : phorum- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1235
The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files.... Read more
Affected Products : application_server- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1230
Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to "boogieman".... Read more
Affected Products : phorum- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1241
Unspecified vulnerability in Haakon Nilsen simple, integrated publishing system (SIPS) before 0.2.4 has an unknown impact and attack vectors, related to a "grave security fault."... Read more
Affected Products : sips- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1225
Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain sensitive configuration information about the web server by accessing the program.... Read more
Affected Products : xitami- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1233
SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary SQL queries via the sSQL parameter.... Read more
Affected Products : phorum- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-1236
SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL.... Read more
Affected Products : application_server- Published: Dec. 31, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-1999-0307
Buffer overflow in HP-UX cstm program allows local users to gain root privileges.... Read more
Affected Products : hp-ux- Published: Dec. 20, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0941
Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter.... Read more
Affected Products : kootenay_web_inc_whois- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-0948
GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack.... Read more
Affected Products : gnorpm- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0917
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.... Read more
Affected Products : linux secure_linux openlinux openlinux_ebuilder openlinux_edesktop openlinux_eserver- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0952
global.cgi CGI program in Global 3.55 and earlier on NetBSD allows remote attackers to execute arbitrary commands via shell metacharacters.... Read more
Affected Products : global- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0886
IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.... Read more
- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-0960
The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.... Read more
Affected Products : messaging_server- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0817
Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malformed data, aka the "Netmon Protocol Parsing" vulnerability.... Read more
Affected Products : network_monitor- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0945
The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory.... Read more
Affected Products : catalyst_3500_xl- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025