|
314571
|
- |
|
linux
|
linux_kernel
|
nfs2acl.c in the Linux kernel 2.6.14.4 does not check for MAY_SATTR privilege before setting access controls (ACL) on files on exported NFS filesystems, which allows remote attackers to bypass ACLs f…
|
CWE-862
Missing Authorization
|
CVE-2005-3623
|
2024-02-2 11:19 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314572
|
7.5 |
HIGH
Network
|
oracle
|
sun_one_application_server
|
Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" extension instead of the lowercase .jsp extension.
|
CWE-178
Improper Handling of Case Sensitivity
|
CVE-2003-0411
|
2024-02-2 11:18 |
2003-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314573
|
7.5 |
HIGH
Network
|
symantec
|
norton_antivirus
|
Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some…
|
CWE-178
Improper Handling of Case Sensitivity
|
CVE-2002-0485
|
2024-02-2 11:17 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314574
|
7.5 |
HIGH
Network
|
netscape
|
fasttrack_server
|
Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.
|
CWE-178
Improper Handling of Case Sensitivity
|
CVE-1999-0239
|
2024-02-2 11:16 |
1998-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314575
|
9.8 |
CRITICAL
Network
|
sir
|
gnuboard
|
The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that inc…
|
CWE-178
Improper Handling of Case Sensitivity
|
CVE-2005-0269
|
2024-02-2 11:15 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314576
|
9.8 |
CRITICAL
Network
|
apache
|
http_server
|
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.
|
CWE-178
Improper Handling of Case Sensitivity
|
CVE-2001-0766
|
2024-02-2 11:13 |
2001-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314577
|
7.5 |
HIGH
Network
|
cmfperception
|
liteserve
|
Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3 file names.
|
CWE-178
Improper Handling of Case Sensitivity
|
CVE-2001-0795
|
2024-02-2 11:12 |
2001-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314578
|
7.8 |
HIGH
Local
|
microsoft
|
windows_2000
|
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which coul…
|
CWE-178
Improper Handling of Case Sensitivity
|
CVE-2001-1238
|
2024-02-2 11:11 |
2001-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314579
|
7.5 |
HIGH
Network
|
transsoft
|
broker_ftp_server
|
Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.
|
CWE-59
Link Following
|
CVE-2001-1042
|
2024-02-2 11:05 |
2001-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314580
|
7.5 |
HIGH
Network
|
qualcomm
|
eudora
|
Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment."
|
CWE-59
Link Following
|
CVE-2000-0342
|
2024-02-2 11:05 |
2000-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|