|
313651
|
5.0 |
MEDIUM
|
awstats canonical debian
|
awstats ubuntu_linux debian_linux
|
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $u…
|
CWE-94
Code Injection
|
CVE-2005-1527
|
2024-02-15 01:58 |
2005-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313652
|
7.5 |
HIGH
Network
|
netsourcecommerce
|
productcart
|
EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via a chosen plaintext attack.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2004-2172
|
2024-02-15 01:58 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313653
|
7.5 |
HIGH
|
cgiscript
|
csguestbook
|
csGuestbook.cgi in CGISCRIPT.NET csGuestbook 1.0 allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.
|
CWE-94
Code Injection
|
CVE-2002-1750
|
2024-02-15 01:57 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313654
|
7.5 |
HIGH
|
cgiscript
|
cschat-r-box
|
csChatRBox.cgi in CGIScript.net csChat-R-Box allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.
|
CWE-94
Code Injection
|
CVE-2002-1752
|
2024-02-15 01:57 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313655
|
7.5 |
HIGH
|
cgiscript
|
csnews_professional
|
csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.
|
CWE-94
Code Injection
|
CVE-2002-1753
|
2024-02-15 01:56 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313656
|
5.5 |
MEDIUM
Local
|
daansystems
|
newsreactor
|
NewsReactor 1.0 uses a weak encryption scheme, which could allow local users to decrypt the passwords and gain access to other users' newsgroup accounts.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2002-1682
|
2024-02-15 01:55 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313657
|
7.8 |
HIGH
Local
|
mckesson
|
pathways_homecare
|
Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwords from the pwhc.ini file.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2001-1546
|
2024-02-15 01:55 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313658
|
9.8 |
CRITICAL
Network
|
arkeia
|
arkeia
|
Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct brute force password g…
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2001-0967
|
2024-02-15 01:55 |
2001-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313659
|
7.8 |
HIGH
Local
|
spectrumcu
|
cash_receipting_system
|
Spectrum Cash Receipting System before 6.504 uses weak cryptography (static substitution) in the PASSFILE password file, which makes it easier for local users to gain privileges by decrypting a passw…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2005-4860
|
2024-02-15 01:54 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313660
|
7.5 |
HIGH
|
plainblack
|
webgui
|
Multiple eval injection vulnerabilities in PlainBlack Software WebGUI before 6.7.3 allow remote attackers to execute arbitrary Perl code via (1) Help.pm, (2) International.pm, or (3) WebGUI.pm.
|
CWE-94
Code Injection
|
CVE-2005-2837
|
2024-02-15 01:53 |
2005-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313661
|
7.5 |
HIGH
Network
|
vtun_project
|
vtun
|
Electronic Code Book (ECB) mode in VTun 2.0 through 2.5 uses a weak encryption algorithm that produces the same ciphertext from the same plaintext blocks, which could allow remote attackers to gain s…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2002-1697
|
2024-02-15 00:51 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313662
|
5.5 |
MEDIUM
Local
|
mdaemon
|
mdaemon
|
Alt-N Technologies Mdaemon 5.0 through 5.0.6 uses a weak encryption algorithm to store user passwords, which allows local users to crack passwords.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2002-1739
|
2024-02-15 00:50 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313663
|
7.5 |
HIGH
Network
|
microsoft
|
sql_server
|
Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2002-1872
|
2024-02-15 00:50 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313664
|
7.5 |
HIGH
Network
|
click-2
|
ingenium_learning_management_system
|
Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtain passwords.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2002-1910
|
2024-02-15 00:50 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313665
|
5.5 |
MEDIUM
Local
|
tata
|
integrated_dialer
|
Videsh Sanchar Nigam Limited (VSNL) Integrated Dialer Software 1.2.000, when the "Save Password" option is used, stores the password with a weak encryption scheme (one-to-one mapping) in a registry k…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2002-1946
|
2024-02-15 00:50 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313666
|
5.5 |
MEDIUM
Local
|
sharp
|
zaurus_sl-5000d_firmware zaurus_sl-5500_firmware
|
Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via b…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2002-1975
|
2024-02-15 00:50 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313667
|
7.5 |
HIGH
|
blender debian
|
blender debian_linux
|
Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.
|
CWE-94
Code Injection
|
CVE-2005-3302
|
2024-02-15 00:47 |
2005-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313668
|
7.5 |
HIGH
|
gggeek debian
|
phpxmlrpc debian_linux
|
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote…
|
CWE-94
Code Injection
|
CVE-2005-2498
|
2024-02-15 00:47 |
2005-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313669
|
7.5 |
HIGH
Network
|
juvare
|
webeoc
|
WebEOC before 6.0.2 uses a weak encryption scheme for passwords, which makes it easier for attackers to crack passwords.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2005-2281
|
2024-02-15 00:47 |
2005-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313670
|
7.5 |
HIGH
|
php gggeek drupal tiki debian
|
xml_rpc phpxmlrpc drupal tikiwiki_cms\/groupware debian_linux
|
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2…
|
CWE-94
Code Injection
|
CVE-2005-1921
|
2024-02-15 00:41 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313671
|
5.0 |
MEDIUM
|
nrl.navy
|
one-time_passwords_in_everything
|
One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and st…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2001-1483
|
2024-02-15 00:17 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313672
|
5.0 |
MEDIUM
|
amtote
|
homebet
|
AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid accoun…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2001-1528
|
2024-02-15 00:17 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313673
|
2.1 |
LOW
|
netfilter
|
iptables
|
iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes iptables to generate different responses than specified by the …
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2001-1387
|
2024-02-15 00:17 |
2001-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313674
|
7.5 |
HIGH
|
php
|
php
|
PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell…
|
CWE-88
Argument Injection
|
CVE-2001-1246
|
2024-02-15 00:17 |
2001-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313675
|
5.0 |
MEDIUM
|
ibm
|
lotus_notes
|
The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring d…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2000-1117
|
2024-02-15 00:16 |
2001-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313676
|
5.0 |
MEDIUM
|
gnu
|
cvs
|
CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which caus…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2004-0778
|
2024-02-15 00:07 |
2004-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313677
|
5.0 |
MEDIUM
|
openssl openbsd freebsd
|
openssl openbsd freebsd
|
ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2003-0078
|
2024-02-15 00:07 |
2003-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313678
|
5.0 |
MEDIUM
|
joetesta
|
hellbent
|
Joe Testa hellbent 01 allows remote attackers to determine the full path of the web root directory via a GET request with a relative path that includes the root's parent, which generates a 403 error …
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2002-2094
|
2024-02-15 00:07 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313679
|
5.0 |
MEDIUM
|
openbsd
|
openbsd
|
PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to determine if a port is being filtered because the TTL is different than the default …
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2002-0514
|
2024-02-15 00:07 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313680
|
5.0 |
MEDIUM
|
phildev
|
ipfilter
|
IPFilter 3.4.25 and earlier sets a different TTL when a port is being filtered than when it is not being filtered, which allows remote attackers to identify filtered ports by comparing TTLs.
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2002-0515
|
2024-02-15 00:07 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313681
|
5.0 |
MEDIUM
|
network.associates
|
pgpfire
|
PGP Security PGPfire 7.1 for Windows alters the system's TCP/IP stack and modifies packets in ICMP error messages in a way that allows remote attackers to determine that the system is running PGPfire.
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2002-0208
|
2024-02-15 00:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313682
|
5.0 |
MEDIUM
|
woppoware
|
postmaster
|
The web mail service in Woppoware PostMaster 4.2.2 (build 3.2.5) generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernam…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2005-1650
|
2024-02-14 23:43 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313683
|
5.0 |
MEDIUM
|
yabbforumsoftware
|
yet_another_bulletin_board
|
YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2004-0294
|
2024-02-14 23:32 |
2004-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313684
|
5.0 |
MEDIUM
|
ibm
|
aix
|
AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2004-0243
|
2024-02-14 23:30 |
2004-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313685
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Rejected reason: Do not use this CVE as it is duplicate of CVE-2023-6932
|
-
|
CVE-2024-0584
|
2024-02-14 15:15 |
2024-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313686
|
7.8 |
HIGH
Local
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2023-42915
|
2024-02-14 12:15 |
2024-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313687
|
7.5 |
HIGH
|
jvehicles
|
com_jvehicles
|
SQL injection vulnerability in the Jvehicles (com_jvehicles) component 1.0, 2.0, and 2.1111 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlist…
|
CWE-89
SQL Injection
|
CVE-2010-1873
|
2024-02-14 10:17 |
2010-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313688
|
5.0 |
MEDIUM
|
vmware
|
player ace workstation server
|
VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 bef…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2009-4811
|
2024-02-14 10:17 |
2010-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313689
|
9.3 |
HIGH
|
hp
|
operations_manager
|
Multiple stack-based buffer overflows in a certain Tetradyne ActiveX control in HP Operations Manager 7.5, 8.10, and 8.16 might allow remote attackers to execute arbitrary code via a long string argu…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-1033
|
2024-02-14 10:17 |
2010-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313690
|
7.2 |
HIGH
|
tukeva
|
password_reminder
|
TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover credentials via a DBI connection.
|
CWE-255
Credentials Management
|
CVE-2009-4781
|
2024-02-14 10:17 |
2010-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313691
|
7.1 |
HIGH
|
microsoft
|
windows_xp windows_vista
|
The ANI parser in Microsoft Windows before 7 on the x86 platform, as used in Internet Explorer and other applications, allows remote attackers to cause a denial of service (memory and CPU consumption…
|
CWE-399
Resource Management Errors
|
CVE-2010-1098
|
2024-02-14 10:17 |
2010-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313692
|
7.5 |
HIGH
|
kiss-software
|
com_ksadvertiser
|
SQL injection vulnerability in the Keep It Simple Stupid (KISS) Software Advertiser (com_ksadvertiser) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid para…
|
CWE-89
SQL Injection
|
CVE-2010-0946
|
2024-02-14 10:17 |
2010-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313693
|
7.5 |
HIGH
|
visualizationlibrary
|
visualization_library
|
Multiple unspecified vulnerabilities in Visualization Library before 2009.08.812 have unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2010-0937
|
2024-02-14 10:17 |
2010-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313694
|
10.0 |
HIGH
|
apache
|
http_server
|
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request proces…
|
NVD-CWE-noinfo
|
CVE-2010-0425
|
2024-02-14 10:17 |
2010-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313695
|
7.5 |
HIGH
|
commodityrentals
|
cd_rental_software
|
SQL injection vulnerability in index.php in CommodityRentals CD Rental Software allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action.
|
CWE-89
SQL Injection
|
CVE-2010-0762
|
2024-02-14 10:17 |
2010-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313696
|
7.5 |
HIGH
|
commodityrentals
|
books\/ebooks_rentals_script
|
SQL injection vulnerability in index.php in CommodityRentals Books/eBooks Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a gamecatalog action.
|
CWE-89
SQL Injection
|
CVE-2010-0761
|
2024-02-14 10:17 |
2010-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313697
|
9.3 |
HIGH
|
thegreenbow
|
ipsec_vpn_client
|
Stack-based buffer overflow in vpnconf.exe in TheGreenBow IPSec VPN Client 4.51.001, 4.65.003, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via a long …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-0392
|
2024-02-14 10:17 |
2010-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313698
|
7.5 |
HIGH
|
chumpsoft
|
phpquestionnaire
|
PHP remote file inclusion vulnerability in inc/ifunctions.php in chumpsoft phpQuestionnaire (phpQ) 3.12 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[phpQRootDir] par…
|
NVD-CWE-Other
|
CVE-2006-4966
|
2024-02-14 10:17 |
2006-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313699
|
6.8 |
MEDIUM
|
maxdev
|
md-pro
|
Cross-site scripting (XSS) vulnerability in MAXdev MDPro 1.0.76 before 20060918 allows remote attackers to inject arbitrary web script or HTML via (1) vectors that bypass the XSS protection mechanism…
|
NVD-CWE-Other
|
CVE-2006-4964
|
2024-02-14 10:17 |
2006-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313700
|
7.5 |
HIGH
|
phpbb_xs
|
phpbb_xs
|
PHP remote file inclusion vulnerability in bb_usage_stats/includes/bb_usage_stats.php in phpBB XS 0.58 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_pa…
|
NVD-CWE-Other
|
CVE-2006-4893
|
2024-02-14 10:17 |
2006-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|