|
344501
|
6.8 |
MEDIUM
|
mambo
|
mambo_site_server
|
Multiple cross-site scripting (XSS) vulnerabilities in Mambo Site Server 4.0.11 allow remote attackers to execute arbitrary script on other clients via (1) search.php and (2) the "Your name" field du…
|
NVD-CWE-Other
|
CVE-2002-1662
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344502
|
5.0 |
MEDIUM
|
oracle
|
e-business_suite
|
Unknown vulnerability in Oracle E-Business Suite 11i.1 through 11i.6 allows remote attackers to execute unauthorized PL/SQL procedures by modifying the Oracle Applications URL.
|
NVD-CWE-Other
|
CVE-2002-1666
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344503
|
2.1 |
LOW
|
freebsd
|
freebsd
|
The virtual memory management system in FreeBSD 4.5-RELEASE and earlier does not properly check the existence of a VM object during page invalidation, which allows local users to cause a denial of se…
|
NVD-CWE-Other
|
CVE-2002-1667
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344504
|
2.1 |
LOW
|
hp
|
hp-ux hp-ux_series_700 hp-ux_series_800
|
HP-UX 11.11 and earlier allows local users to cause a denial of service (kernel deadlock), due to a "file system weakness" that is possibly via an mmap() system call and performing an I/O operation u…
|
NVD-CWE-Other
|
CVE-2002-1668
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344505
|
2.1 |
LOW
|
freebsd
|
freebsd
|
pkg_add in FreeBSD 4.2 through 4.4 creates a temporary directory with world-searchable permissions, which may allow local users to modify world-writable parts of the package during installation.
|
NVD-CWE-Other
|
CVE-2002-1669
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344506
|
2.1 |
LOW
|
webmin
|
webmin
|
Webmin 0.92, when installed from an RPM, creates /var/webmin with insecure permissions (world readable), which could allow local users to read the root user's cookie-based authentication credentials …
|
NVD-CWE-Other
|
CVE-2002-1672
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344507
|
3.6 |
LOW
|
webmin
|
webmin
|
The web interface for Webmin 0.92 does not properly quote or filter script code in files that are displayed to the interface, which allows local users to execute script and possibly steal cookies by …
|
NVD-CWE-Other
|
CVE-2002-1673
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344508
|
1.2 |
LOW
|
freebsd
|
freebsd
|
procfs on FreeBSD before 4.5 allows local users to cause a denial of service (kernel panic) by removing a file that the fstatfs function refers to.
|
NVD-CWE-Other
|
CVE-2002-1674
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344509
|
6.4 |
MEDIUM
|
unreal
|
unrealircd
|
Format string vulnerability in the Cio_PrintF function of cio_main.c in Unreal IRCd 3.1.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format s…
|
NVD-CWE-Other
|
CVE-2002-1675
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344510
|
2.1 |
LOW
|
bindview
|
netinventory netrc
|
BindView NetInventory 1.0, when used with NetRC 1.0, allows local users to read sensitive information (passwords) by deleting the HOSTCFG._NI file and forcing an audit, which rewrites the HOSTCFG._NI…
|
NVD-CWE-Other
|
CVE-2002-1676
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344511
|
5.0 |
MEDIUM
|
mrtg
|
mrtgconfig
|
14all.cgi 1.1p15 in mrtgconfig allows remote attackers to determine the physical path to the web root directory via a request with an invalid cfg parameter, which generates an error message that reve…
|
NVD-CWE-Other
|
CVE-2002-1677
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344512
|
4.3 |
MEDIUM
|
jelsoft
|
vbulletin
|
Cross-site scripting (XSS) vulnerability in memberlist.php in Jelsoft vBulletin 2.0 rc 2 through 2.2.4 allows remote attackers to steal authentication credentials by injecting script into $letterbits.
|
NVD-CWE-Other
|
CVE-2002-1678
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344513
|
4.3 |
MEDIUM
|
jelsoft
|
vbulletin
|
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 2.2.0 allows remote attackers to execute arbitrary script as other users by injecting script into a bulletin board message.
|
NVD-CWE-Other
|
CVE-2002-1679
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344514
|
4.3 |
MEDIUM
|
cows
|
cgi_online_worldweb_shopping
|
Cross-site scripting (XSS) vulnerability in CGI Online Worldweb Shopping 1.1 (a.k.a. COWS) allows remote attackers to execute arbitrary script as other users by injecting script into (1) diagnose.cgi…
|
NVD-CWE-Other
|
CVE-2002-1680
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344515
|
6.8 |
MEDIUM
|
open_source_development_network
|
slashcode
|
Cross-site scripting (XSS) vulnerability in Slashcode CVS releases June 17 through July 1 2002 allows remote attackers to execute arbitrary script as other users by injecting script into the paragrap…
|
NVD-CWE-Other
|
CVE-2002-1681
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344516
|
4.3 |
MEDIUM
|
working_resources_inc.
|
badblue
|
Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function.
|
NVD-CWE-Other
|
CVE-2002-1683
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344517
|
5.0 |
MEDIUM
|
deerfield working_resources_inc.
|
d2gfx badblue
|
Directory traversal vulnerability in (1) Deerfield D2Gfx 1.0.2 or (2) BadBlue Enterprise Edition 1.5.x and BadBlue Personal Edition 1.5.6 allows remote attackers to read arbitrary files via a ../ (do…
|
NVD-CWE-Other
|
CVE-2002-1684
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344518
|
4.3 |
MEDIUM
|
working_resources_inc.
|
badblue
|
Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into e…
|
NVD-CWE-Other
|
CVE-2002-1685
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344519
|
10.0 |
HIGH
|
alcatel-lucent
|
omnipcx
|
Alcatel OmniPCX 4400 installs known user accounts and passwords in the /etc/password file by default, which allows remote attackers to gain unauthorized access.
|
NVD-CWE-Other
|
CVE-2002-1691
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344520
|
3.6 |
LOW
|
microsoft
|
windows_95
|
Buffer overflow in backup utility of Microsoft Windows 95 allows attackers to execute arbitrary code by causing a filename with a long extension to be placed in a folder to be backed up.
|
NVD-CWE-Other
|
CVE-2002-1692
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344521
|
5.0 |
MEDIUM
|
microsoft
|
msn_messenger
|
Buffer overflow in Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via a long FN (font) argument in the message header.
|
NVD-CWE-Other
|
CVE-2002-1698
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344522
|
10.0 |
HIGH
|
pascal_michaud
|
asp_client_check
|
SQL injection vulnerability in ASP Client Check (ASPCC) 1.3 and 1.5 allows remote attackers to bypass authentication and gain unauthorized access via the password field.
|
NVD-CWE-Other
|
CVE-2002-1699
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344523
|
4.3 |
MEDIUM
|
deltascripts
|
php_classifieds
|
Cross-site scripting vulnerability (XSS) in DeltaScripts PHP Classifieds 6.0.5 allows remote attackers to execute arbitrary script as other users via the URL parameter.
|
NVD-CWE-Other
|
CVE-2002-1702
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344524
|
6.8 |
MEDIUM
|
mewsoft
|
netauction
|
Cross-site scripting vulnerability (XSS) in auction.cgi for Mewsoft NetAuction 3.0 allows remote attackers to execute arbitrary script as other users via the Term parameter.
|
NVD-CWE-Other
|
CVE-2002-1703
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344525
|
5.0 |
MEDIUM
|
zeroboard
|
zeroboard
|
Zeroboard 4.1, when the "allow_url_fopen" and "register_globals" variables are enabled, allows remote attackers to execute arbitrary PHP code by modifying the _zb_path parameter to reference a URL on…
|
NVD-CWE-Other
|
CVE-2002-1704
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344526
|
5.0 |
MEDIUM
|
phpbb_group
|
phpbb
|
install.php in phpBB 2.0 through 2.0.1, when "allow_url_fopen" and "register_globals" variables are set to "on", allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_dir …
|
NVD-CWE-Other
|
CVE-2002-1707
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344527
|
6.8 |
MEDIUM
|
basilix
|
basilix_webmail
|
Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting script into the (1) subject or (2) message fields.
|
NVD-CWE-Other
|
CVE-2002-1708
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344528
|
6.4 |
MEDIUM
|
basilix
|
basilix_webmail
|
SQL injection vulnerability in BasiliX Webmail 1.10 allows remote attackers to obtain sensitive information or possibly modify data via the id variable.
|
NVD-CWE-Other
|
CVE-2002-1709
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344529
|
3.6 |
LOW
|
basilix
|
basilix_webmail
|
The attachment capability in Compose Mail in BasiliX Webmail 1.1.0 does not check whether the attachment was uploaded by the user or came from a HTTP POST, which could allow local users to steal sens…
|
NVD-CWE-Other
|
CVE-2002-1710
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344530
|
2.1 |
LOW
|
basilix
|
basilix_webmail
|
BasiliX 1.1.0 saves attachments in a world readable /tmp/BasiliX directory, which allows local users to read other users' attachments.
|
NVD-CWE-Other
|
CVE-2002-1711
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344531
|
7.2 |
HIGH
|
ssh
|
ssh ssh2
|
SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable directory, then executing that script to …
|
NVD-CWE-Other
|
CVE-2002-1715
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344532
|
5.0 |
MEDIUM
|
bavo
|
bavo
|
Unknown vulnerability in Bavo 0.3 allows remote attackers to modify posted messages.
|
NVD-CWE-Other
|
CVE-2002-1719
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344533
|
7.5 |
HIGH
|
outfront
|
spooky_login
|
SQL injection vulnerability in Spooky Login 2.0 through 2.5 allows remote attackers to bypass authentication and gain privileges via the password field.
|
NVD-CWE-Other
|
CVE-2002-1720
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344534
|
4.6 |
MEDIUM
|
logitech
|
cordless_freedom_itouch_keyboard cordless_itouch_keyboard itouch_keyboard
|
Logitech iTouch keyboards allows attackers with physical access to the system to bypass the screen locking function and execute user-defined commands that have been assigned to a button.
|
NVD-CWE-Other
|
CVE-2002-1722
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344535
|
5.0 |
MEDIUM
|
powerboards
|
powerboards
|
Powerboards 2.2b allows remote attackers to view the full path to the backend database by sending a cookie containing a non-existent username to profiles.php, which displays the full path in the erro…
|
NVD-CWE-Other
|
CVE-2002-1723
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344536
|
6.8 |
MEDIUM
|
onlinetools.org
|
phpimageview
|
Cross-site scripting vulnerability (XSS) in phpimageview.php for PHPImageView 1.0 allows remote attackers to execute arbitrary script as other users via the pic parameter.
|
NVD-CWE-Other
|
CVE-2002-1724
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344537
|
5.0 |
MEDIUM
|
onlinetools.org
|
phpimageview
|
phpimageview.php in PHPImageView 1.0 allows remote attackers to obtain sensitive information via the pw=show option, which invokes the phpinfo function.
|
NVD-CWE-Other
|
CVE-2002-1725
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344538
|
7.5 |
HIGH
|
brokenbytes
|
photodb
|
secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter, non-empty rmtusername and rmtpassword parameter, and an accesslevel parameter tha…
|
NVD-CWE-Other
|
CVE-2002-1726
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344539
|
6.8 |
MEDIUM
|
asksam_systems
|
asksam_web_publisher
|
Cross-site scripting vulnerability (XSS) in (1) as_web.exe and (2) as_web4.exe in askSam Web Publisher 1 and 4 allows remote attackers to execute arbitrary script as other users via a URL.
|
NVD-CWE-Other
|
CVE-2002-1727
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344540
|
5.0 |
MEDIUM
|
asksam_systems
|
asksam_web_publisher
|
askSam Web Publisher 1.0 and 4.0 allows remote attackers to determine the full path to the web root directory via a request for a file that does not exist, which generates an error message that revea…
|
NVD-CWE-Other
|
CVE-2002-1728
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344541
|
6.8 |
MEDIUM
|
aspjar
|
aspjar_guestbook
|
Cross-site scripting vulnerability (XSS) in ASPjar Guestbook 1.00 allows remote attackers to execute arbitrary script as other users via the "web site" parameter in a guestbook message.
|
NVD-CWE-Other
|
CVE-2002-1729
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344542
|
5.0 |
MEDIUM
|
aspjar
|
aspjar_guestbook
|
ASPjar Guestbook 1.00 allows remote attackers to delete arbitrary messages accessing the delete.asp administrative script with certain cookie values set to "true".
|
NVD-CWE-Other
|
CVE-2002-1730
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344543
|
2.1 |
LOW
|
ibm
|
os_400
|
The System Request menu in IBM AS/400 allows local users to list valid user accounts by viewing the object names that are type USRPRF.
|
NVD-CWE-Other
|
CVE-2002-1731
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344544
|
4.3 |
MEDIUM
|
actinic
|
actinic_catalog
|
Multiple cross-site scripting (XSS) vulnerabilities in Actinic Catalog 4.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string argument to certain .pl files, (2) …
|
NVD-CWE-Other
|
CVE-2002-1732
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344545
|
4.3 |
MEDIUM
|
prospero_technologies
|
prospero_message_board
|
Cross-site scripting (XSS) vulnerability in the web-based message board in Prospero Technologies allows remote attackers to inject arbitrary web script or HTML via a message board post.
|
NVD-CWE-Other
|
CVE-2002-1733
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344546
|
10.0 |
HIGH
|
aspbin
|
newspro
|
NewsPro 1.01 allows remote attackers to gain unauthorized administrator access by setting their authentication cookie to "logged,true".
|
NVD-CWE-Other
|
CVE-2002-1734
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344547
|
7.2 |
HIGH
|
davin_mccall
|
dlogin
|
Buffer overflow in dlogin 1.0a could allow local users to gain privileges via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2002-1735
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344548
|
5.0 |
MEDIUM
|
markus_triska
|
cginews
|
Unknown vulnerability in CGINews before 1.06 allow remote attackers to read arbitrary files via "unfiltered user input."
|
NVD-CWE-Other
|
CVE-2002-1736
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344549
|
2.1 |
LOW
|
astaro
|
security_linux
|
Astaro Security Linux 2.016 creates world-writable files and directories, which allows local users to overwrite arbitrary files.
|
NVD-CWE-Other
|
CVE-2002-1737
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344550
|
5.0 |
MEDIUM
|
alt-n
|
mdaemon
|
Alt-N Technologies MDaemon 5.0.5.0 and earlier creates a default MDaemon mail account with a password of MServer, which could allow remote attackers to send anonymous email.
|
NVD-CWE-Other
|
CVE-2002-1738
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|