Monthly Archive: February 2000

CVE-2000-0135

The @Retail shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. Date published : 2000-02-08

CVE-2000-0134

The Check It Out shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. Date published : 2000-02-08

CVE-2000-0133

Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD, XRMD, APPE, SIZE, and RNFR commands. Date published : 2000-02-08 http://www.securityfocus.com/bid/961

CVE-2000-0129

Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file. Date published : 2000-02-08

CVE-2000-0126

Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack. Date published : 2000-02-08

CVE-2000-0124

surfCONTROL SuperScout does not properly asign a category to web sites with a . (dot) at the end, which may allow users to bypass web access restrictions. Date published : 2000-02-08 http://www.securityfocus.com/bid/965

CVE-2000-0123

The shopping cart application provided with Filemaker allows remote users to modify sensitive purchase information via hidden form fields. Date published : 2000-02-08

CVE-2000-0119

The default configurations for McAfee Virus Scan and Norton Anti-Virus virus checkers do not check files in the RECYCLED folder that is used by the Windows Recycle Bin utility, which allows attackers to store...

CVE-2000-0118

The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing. Date published...

CVE-2000-0115

IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page. Date published : 2000-02-08

CVE-2000-0114

Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory. Date published : 2000-02-08