Monthly Archive: February 2000

CVE-2000-0081

Hotmail does not properly filter JavaScript code from a user’s mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. jAvascript. Date published :...

CVE-2000-0079

The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL. Date published : 2000-02-04 http://www.securityfocus.com/bid/936

CVE-2000-0078

The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command. Date published : 2000-02-04

CVE-2000-0077

The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands. Date published : 2000-02-04

CVE-2000-0074

PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions. Date published : 2000-02-04

CVE-2000-0069

The recover program in Solstice Backup allows local users to restore sensitive files. Date published : 2000-02-04

CVE-2000-0067

CyberCash Merchant Connection Kit (MCK) allows local users to modify files via a symlink attack. Date published : 2000-02-04

CVE-2000-0066

WebSite Pro allows remote attackers to determine the real pathname of webdirectories via a malformed URL request. Date published : 2000-02-04

CVE-2000-0061

Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript...

CVE-2000-0059

PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands. Date published : 2000-02-04 http://www.securityfocus.com/bid/911