Show filters
45 Total Results
Displaying 31-40 of 45
Sort by:
Attacker Value
Unknown

CVE-2004-2214

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.
Attacker Value
Unknown

CVE-2004-2154

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.
Attacker Value
Unknown

CVE-2004-1083

Disclosure Date: December 03, 2004 (last updated February 22, 2025)
Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate capitalization.
Attacker Value
Unknown

CVE-2003-0411

Disclosure Date: June 30, 2003 (last updated February 22, 2025)
Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" extension instead of the lowercase .jsp extension.
Attacker Value
Unknown

CVE-2002-1820

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker to impersonate the administrator by registering an account name of admin with a lower case "a."
Attacker Value
Unknown

CVE-2002-2119

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password guessing.
Attacker Value
Unknown

CVE-2002-0485

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients.
Attacker Value
Unknown

CVE-2001-0766

Disclosure Date: October 18, 2001 (last updated February 22, 2025)
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.
Attacker Value
Unknown

CVE-2001-0795

Disclosure Date: October 18, 2001 (last updated February 22, 2025)
Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3 file names.
Attacker Value
Unknown

CVE-2001-1238

Disclosure Date: July 16, 2001 (last updated February 22, 2025)
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager.