Monthly Archive: January 2000

CVE-1999-0938

MBone SDR Package allows remote attackers to execute commands via shell metacharacters in Session Initiation Protocol (SIP) messages. Date published : 2000-01-04

CVE-1999-0937

BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable. Date published : 2000-01-04

CVE-1999-0936

BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters. Date published : 2000-01-04

CVE-1999-0935

classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form. Date published : 2000-01-04

CVE-1999-0907

sccw allows local users to read arbitrary files. Date published : 2000-01-04

CVE-1999-0902

ypserv allows local administrators to modify password tables. Date published : 2000-01-04