Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown
CVE-1999-1051
Disclosure Date: November 16, 1999 (last updated February 22, 2025)
Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.
0
Attacker Value
Unknown
CVE-1999-1050
Disclosure Date: November 12, 1999 (last updated February 22, 2025)
Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.
0
Attacker Value
Unknown
CVE-1999-0954
Disclosure Date: September 16, 1999 (last updated February 22, 2025)
WWWBoard has a default username and default password.
0
Attacker Value
Unknown
CVE-1999-0953
Disclosure Date: September 16, 1999 (last updated February 22, 2025)
WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers.
0
Attacker Value
Unknown
CVE-1999-1053
Disclosure Date: September 13, 1999 (last updated February 22, 2025)
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
0
Attacker Value
Unknown
CVE-1999-1377
Disclosure Date: September 09, 1999 (last updated February 22, 2025)
Matt Wright's download.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.
0
Attacker Value
Unknown
CVE-1999-0930
Disclosure Date: September 03, 1998 (last updated February 22, 2025)
wwwboard allows a remote attacker to delete message board articles via a malformed argument.
0
Attacker Value
Unknown
CVE-1999-1479
Disclosure Date: June 24, 1998 (last updated February 22, 2025)
The textcounter.pl by Matt Wright allows remote attackers to execute arbitrary commands via shell metacharacters.
0
Attacker Value
Unknown
CVE-1999-0173
Disclosure Date: January 01, 1997 (last updated February 22, 2025)
FormMail CGI program can be used by web servers other than the host server that the program resides on.
0
Attacker Value
Unknown
CVE-1999-0172
Disclosure Date: August 02, 1995 (last updated February 22, 2025)
FormMail CGI program allows remote execution of commands.
0