276601
|
4.6 |
MEDIUM
|
caldera
|
openlinux_server openlinux_workstation
|
startkde in KDE for Caldera OpenLinux 2.3 through 3.1.1 sets the LD_LIBRARY_PATH environment variable to include the current working directory, which could allow local users to gain privileges of oth…
|
NVD-CWE-Other
|
CVE-2002-0512
|
2008-09-6 05:28 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276602
|
10.0 |
HIGH
|
squirrelmail
|
squirrelmail
|
SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cookie.
|
NVD-CWE-Other
|
CVE-2002-0516
|
2008-09-6 05:28 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276603
|
7.2 |
HIGH
|
caldera
|
unixware openunix
|
Buffer overflow in X11 library (libX11) on Caldera Open UNIX 8.0.0, UnixWare 7.1.1, and possibly other operating systems, allows local users to gain root privileges via a long -xrm argument to progra…
|
NVD-CWE-Other
|
CVE-2002-0517
|
2008-09-6 05:28 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276604
|
5.0 |
MEDIUM
|
freebsd
|
freebsd
|
The SYN cache (syncache) and SYN cookie (syncookie) mechanism in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (crash) (1) via a SYN packet that is accepted using synco…
|
NVD-CWE-Other
|
CVE-2002-0518
|
2008-09-6 05:28 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276605
|
7.5 |
HIGH
|
asp-nuke
|
asp-nuke
|
Cross-site scripting vulnerability in functions-inc.asp for ASP-Nuke RC1 allows remote attackers to execute script as other ASP-Nuke users by embedding it within an IMG tag.
|
NVD-CWE-Other
|
CVE-2002-0520
|
2008-09-6 05:28 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276606
|
5.1 |
MEDIUM
|
asp-nuke
|
asp-nuke
|
Cross-site scripting vulnerabilities in ASP-Nuke RC2 and earlier allow remote attackers to execute script or gain privileges as other ASP-Nuke users via script in (1) the name parameter in downloads.…
|
NVD-CWE-Other
|
CVE-2002-0521
|
2008-09-6 05:28 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276607
|
7.5 |
HIGH
|
asp-nuke
|
asp-nuke
|
ASP-Nuke RC2 and earlier allows remote attackers to bypass authentication and gain privileges by modifying the "pseudo" cookie.
|
NVD-CWE-Other
|
CVE-2002-0522
|
2008-09-6 05:28 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276608
|
5.0 |
MEDIUM
|
asp-nuke
|
asp-nuke
|
ASP-Nuke RC2 and earlier allows remote attackers to list all logged-in users by submitting an invalid "pseudo" cookie.
|
NVD-CWE-Other
|
CVE-2002-0523
|
2008-09-6 05:28 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276609
|
5.0 |
MEDIUM
|
asp-nuke
|
asp-nuke
|
ASP-Nuke RC2 and earlier allows remote attackers to determine the absolute path of the server by (1) calling database-inc.asp with incorrect cookies, or (2) calling Post.asp with certain arguments, w…
|
NVD-CWE-Other
|
CVE-2002-0524
|
2008-09-6 05:28 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276610
|
10.0 |
HIGH
|
isc
|
inn
|
Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses.
|
NVD-CWE-Other
|
CVE-2002-0525
|
2008-09-6 05:28 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276611
|
5.0 |
MEDIUM
|
watchguard
|
soho_firewall
|
Watchguard SOHO firewall before 5.0.35 allows remote attackers to cause a denial of service (crash and reboot) when SOHO forwards a packet with bad IP options.
|
NVD-CWE-Other
|
CVE-2002-0527
|
2008-09-6 05:28 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276612
|
10.0 |
HIGH
|
watchguard
|
soho_firewall
|
Watchguard SOHO firewall 5.0.35 unpredictably disables certain IP restrictions for customized services that were set before the administrator upgrades to 5.0.35, which could allow remote attackers to…
|
NVD-CWE-Other
|
CVE-2002-0528
|
2008-09-6 05:28 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276613
|
6.2 |
MEDIUM
|
hp
|
photosmart_print_driver
|
HP Photosmart printer driver for Mac OS X installs the hp_imaging_connectivity program and the hp_imaging_connectivity.app directory with world-writable permissions, which allows local users to gain …
|
NVD-CWE-Other
|
CVE-2002-0529
|
2008-09-6 05:28 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276614
|
5.0 |
MEDIUM
|
emumail
|
emumail emumail_red_hat_linux emumail_unix
|
Directory traversal vulnerability in emumail.cgi in EMU Webmail 4.5.x and 5.1.0 allows remote attackers to read arbitrary files or list arbitrary directories via a .. (dot dot) in the type parameter.
|
NVD-CWE-Other
|
CVE-2002-0531
|
2008-09-6 05:28 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276615
|
7.2 |
HIGH
|
emumail
|
emumail emumail_red_hat_linux emumail_unix
|
EMU Webmail allows local users to execute arbitrary programs via a .. (dot dot) in the HTTP Host header that points to a Trojan horse configuration file that contains a pageroot specifier that contai…
|
NVD-CWE-Other
|
CVE-2002-0532
|
2008-09-6 05:28 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276616
|
5.0 |
MEDIUM
|
postboard
|
postboard
|
PostBoard 2.0.1 and earlier with BBcode allows remote attackers to cause a denial of service (CPU consumption) and corrupt the database via null \0 characters within [code] tags.
|
NVD-CWE-Other
|
CVE-2002-0534
|
2008-09-6 05:28 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276617
|
7.5 |
HIGH
|
phpgroupware
|
phpgroupware
|
PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the database via a SQL injection attack.
|
NVD-CWE-Other
|
CVE-2002-0536
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276618
|
10.0 |
HIGH
|
stepweb
|
sws
|
The admin.html file in StepWeb Search Engine (SWS) 2.5 stores passwords in links to manager.pl, which allows remote attackers who can access the admin.html file to gain administrative privileges to S…
|
NVD-CWE-Other
|
CVE-2002-0537
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276619
|
10.0 |
HIGH
|
demarc_security
|
puresecure
|
Demarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session ID that is stored in the s_key cookie.
|
NVD-CWE-Other
|
CVE-2002-0539
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276620
|
7.5 |
HIGH
|
nortel
|
cvx_1800_multi-service_access_switch
|
Nortel CVX 1800 is installed with a default "public" community string, which allows remote attackers to read usernames and passwords and modify the CVX configuration.
|
NVD-CWE-Other
|
CVE-2002-0540
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276621
|
7.5 |
HIGH
|
ibm
|
tivoli_storage_manager
|
Buffer overflow in Tivoli Storage Manager TSM (1) Server or Storage Agents 3.1 through 5.1, and (2) the TSM Client Acceptor Service 4.2 and 5.1, allows remote attackers to cause a denial of service (…
|
NVD-CWE-Other
|
CVE-2002-0541
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276622
|
5.0 |
MEDIUM
|
aprelium_technologies
|
abyss_web_server
|
Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read files outside the web root, including the abyss.conf file, via URL-encoded .. (…
|
NVD-CWE-Other
|
CVE-2002-0543
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276623
|
7.2 |
HIGH
|
aprelium_technologies
|
abyss_web_server
|
Aprelium Abyss Web Server (abyssws) before 1.0.3 stores the administrative console password in plaintext in the abyss.conf file, which allows local users with access to the file to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-0544
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276624
|
5.0 |
MEDIUM
|
cisco
|
aironet_ap340 aironet_ap350
|
Cisco Aironet before 11.21 with Telnet enabled allows remote attackers to cause a denial of service (reboot) via a series of login attempts with invalid usernames and passwords.
|
NVD-CWE-Other
|
CVE-2002-0545
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276625
|
7.5 |
HIGH
|
nullsoft
|
winamp
|
Cross-site scripting vulnerability in the mini-browser for Winamp 2.78 and 2.79 allows remote attackers to execute script via an ID3v1 or ID3v2 tag in an MP3 file.
|
NVD-CWE-Other
|
CVE-2002-0546
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276626
|
7.5 |
HIGH
|
nullsoft
|
winamp
|
Buffer overflow in the mini-browser for Winamp 2.79 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the title field o…
|
NVD-CWE-Other
|
CVE-2002-0547
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276627
|
7.5 |
HIGH
|
anthill
|
anthill
|
Anthill allows remote attackers to bypass authentication and file bug reports by directly accessing the postbug.php program instead of enterbug.php.
|
NVD-CWE-Other
|
CVE-2002-0548
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276628
|
7.5 |
HIGH
|
anthill
|
anthill
|
Cross-site scripting vulnerabilities in Anthill allow remote attackers to execute script as other Anthill users.
|
NVD-CWE-Other
|
CVE-2002-0549
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276629
|
7.5 |
HIGH
|
gcf
|
dynamic_guestbook
|
Dynamic Guestbook 3.0 allows remote attackers to execute arbitrary code via shell metacharacters in the gbdaten parameter.
|
NVD-CWE-Other
|
CVE-2002-0550
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276630
|
7.5 |
HIGH
|
gcf
|
dynamic_guestbook
|
Cross-site scripting vulnerability in Dynamic Guestbook 3.0 allows remote attackers to execute code in clients who access guestbook pages via the parameters (1) name, (2) mail, or (3) kommentar.
|
NVD-CWE-Other
|
CVE-2002-0551
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276631
|
7.5 |
HIGH
|
melange
|
melange_chat_system
|
Multiple buffer overflows in Melange Chat server 2.02 allow remote or local attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long argument in the /yell com…
|
NVD-CWE-Other
|
CVE-2002-0552
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276632
|
7.5 |
HIGH
|
turnkey_solutions
|
sunshop_shopping_cart
|
Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by injecting the script into fields during new customer registration.
|
NVD-CWE-Other
|
CVE-2002-0553
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276633
|
7.5 |
HIGH
|
ibm
|
informix_web_datablade
|
webdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary files via a SQL injection attack in an HTTP request.
|
NVD-CWE-Other
|
CVE-2002-0554
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276634
|
7.5 |
HIGH
|
ibm
|
informix_web_datablade
|
IBM Informix Web DataBlade 4.12 unescapes user input even if an application has escaped it, which could allow remote attackers to execute SQL code in a web form even when the developer has attempted …
|
NVD-CWE-Other
|
CVE-2002-0555
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276635
|
5.0 |
MEDIUM
|
deep_forest_software
|
quik-serv_webserver
|
Directory traversal vulnerability in Quik-Serv HTTP server 1.1B allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.
|
NVD-CWE-Other
|
CVE-2002-0556
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276636
|
7.5 |
HIGH
|
openbsd
|
openbsd
|
Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, p…
|
NVD-CWE-Other
|
CVE-2002-0557
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276637
|
5.0 |
MEDIUM
|
typsoft
|
typsoft_ftp_server
|
Directory traversal vulnerability in TYPSoft FTP server 0.97.1 and earlier allows a remote authenticated user (possibly anonymous) to list arbitrary directories via a .. in a LIST (ls) command ending…
|
NVD-CWE-Other
|
CVE-2002-0558
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276638
|
7.5 |
HIGH
|
oracle
|
oracle9i
|
Oracle Oracle9i database server 9.0.1.x allows local users to access restricted data via a SQL query using ANSI outer join syntax.
|
NVD-CWE-Other
|
CVE-2002-0571
|
2008-09-6 05:28 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276639
|
5.0 |
MEDIUM
|
allaire
|
coldfusion_server
|
ColdFusion 5.0 and earlier on Windows systems allows remote attackers to determine the absolute pathname of .cfm or .dbm files via an HTTP request that contains an MS-DOS device name such as NUL, whi…
|
NVD-CWE-Other
|
CVE-2002-0576
|
2008-09-6 05:28 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276640
|
7.5 |
HIGH
|
aci
|
4d_webserver
|
Buffer overflow in 4D WebServer 6.7.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP request with Basic Authentication containing a long (1) user…
|
NVD-CWE-Other
|
CVE-2002-0578
|
2008-09-6 05:28 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276641
|
7.5 |
HIGH
|
workforceroi
|
xpede
|
WorkforceROI Xpede 4.1 allows remote attackers to gain privileges as an Xpede administrator via a direct HTTP request to the /admin/adminproc.asp script, which does not prompt for a password.
|
NVD-CWE-Other
|
CVE-2002-0579
|
2008-09-6 05:28 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276642
|
7.5 |
HIGH
|
workforceroi
|
xpede
|
WorkforceROI Xpede 4.1 allows remote attackers to obtain the database username via a request to datasource.asp, which leaks the username in a form and allows the attacker to more easily conduct brute…
|
NVD-CWE-Other
|
CVE-2002-0580
|
2008-09-6 05:28 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276643
|
7.5 |
HIGH
|
workforceroi
|
xpede
|
WorkforceROI Xpede 4.1 allows remote attackers to execute arbitrary SQL commands and read, modify, or steal credentials from the database via the Qry parameter in the sprc.asp script.
|
NVD-CWE-Other
|
CVE-2002-0581
|
2008-09-6 05:28 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276644
|
5.0 |
MEDIUM
|
workforceroi
|
xpede
|
WorkforceROI Xpede 4.1 stores temporary expense claim reports in a world-readable and indexable /reports/temp directory, which allows remote attackers to read the reports by accessing the directory.
|
NVD-CWE-Other
|
CVE-2002-0582
|
2008-09-6 05:28 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276645
|
5.0 |
MEDIUM
|
workforceroi
|
xpede
|
WorkforceROI Xpede 4.1 uses a small random namespace (5 alphanumeric characters) for temporary expense claim reports in the /reports/temp directory, which allows remote attackers to read the reports …
|
NVD-CWE-Other
|
CVE-2002-0583
|
2008-09-6 05:28 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276646
|
5.0 |
MEDIUM
|
workforceroi
|
xpede
|
WorkforceROI Xpede 4.1 allows remote attackers to read user timesheets by modifying the TSN ID parameter to the ts_app_process.asp script, which is easily guessable because it is incremented by 1 for…
|
NVD-CWE-Other
|
CVE-2002-0584
|
2008-09-6 05:28 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276647
|
7.5 |
HIGH
|
aol
|
aol_server
|
Format string vulnerability in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to execute arbitrary code via…
|
NVD-CWE-Other
|
CVE-2002-0586
|
2008-09-6 05:28 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276648
|
7.5 |
HIGH
|
aol
|
aol_server
|
Buffer overflow in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to cause a denial of service or execute a…
|
NVD-CWE-Other
|
CVE-2002-0587
|
2008-09-6 05:28 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276649
|
5.0 |
MEDIUM
|
steve_korbett
|
pvote
|
PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.
|
NVD-CWE-Other
|
CVE-2002-0588
|
2008-09-6 05:28 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276650
|
7.5 |
HIGH
|
steve_korbett
|
pvote
|
PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with the newpass and confirm parameters both set to the new password.
|
NVD-CWE-Other
|
CVE-2002-0589
|
2008-09-6 05:28 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|