CVE-2000-1235
published 2000-12-31CVE-2000-1235: The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to…
PriorityP421medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
4.83%
91.1th percentile
The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | application_server | <= 3.0.7 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
XFree86 X11R6 3.3.5/3.3.6/4.0 Xserver - Denial of Service
exploitdb·2000-05-18
CVE-2000-0453 XFree86 X11R6 3.3.5/3.3.6/4.0 Xserver - Denial of Service
XFree86 X11R6 3.3.5/3.3.6/4.0 Xserver - Denial of Service
---
/*
source: https://www.securityfocus.com/bid/1235/info
A denial of service exists in XFree86 3.3.5, 3.3.6 and 4.0. A remote user can send a malformed packet to the TCP listening port, 6000, which will cause the X server to be unresponsive for some period of time. During this time, the keyboard will not respond to user input, and in some cases, the mouse will also not respond. During this time period, the X server will utilize 100% of the CPU, and can only be repaired by being signaled. This vulnerability exists only in servers compiled with the XCSECURITY #define set. This can be verified by running the following:
strings /path/to/XF86_SVGA | grep "XC-QUERY-SECURITY-1"
To quote the Bugtraq post, by Chris Evans :
"Observe xc/
Exploit-DB
Microsoft Internet Explorer 5 - FTP Password Storage
exploitdb·1999-08-25
CVE-1999-1235 Microsoft Internet Explorer 5 - FTP Password Storage
Microsoft Internet Explorer 5 - FTP Password Storage
---
Microsoft Internet Explorer 5.0 for Windows 2000/Windows NT 4 FTP Password Storage Vulnerability
source: https://www.securityfocus.com/bid/610/info
FTP usernames and passwords for sites accessed via Internet Explorer 5.X are stored (cleartext) in history files stored under \Winnt\Profiles\[Username]\History\History.IE5\index.dat and \Winnt\Profiles\[Username]\History\History.IE5\MSHist..\index.dat. By default, the \Winnt\Profiles\[Username]\History directories are secured with ACLs to allow Full Control for System, the Administrators group, and the given Username. The index.dat files, however, are created with Everyone:Full Control permissions.
Because the "Bypass Traverse Checking" right is assigned by default to the Everyone g
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2000-12/0339.htmlhttp://archives.neohapsis.com/archives/bugtraq/2000-12/0372.htmlhttp://archives.neohapsis.com/archives/bugtraq/2000-12/0463.htmlhttp://online.securityfocus.com/archive/1/155881http://www.iss.net/security_center/static/5818.phphttp://www.securityfocus.com/bid/2150http://archives.neohapsis.com/archives/bugtraq/2000-12/0339.htmlhttp://archives.neohapsis.com/archives/bugtraq/2000-12/0372.htmlhttp://archives.neohapsis.com/archives/bugtraq/2000-12/0463.htmlhttp://online.securityfocus.com/archive/1/155881http://www.iss.net/security_center/static/5818.phphttp://www.securityfocus.com/bid/2150
2000-12-31
Published