267311
|
- |
|
acd_incorporated
|
cwpapi
|
GetRelativePath in ACD Incorporated CwpAPI 1.1 only verifies if the server root is somewhere within the path, which could allow remote attackers to read or write files outside of the web root, in oth…
|
NVD-CWE-Other
|
CVE-2002-0196
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267312
|
- |
|
paintbbs
|
paintbbs
|
PaintBBS 1.2 installs certain files and directories with insecure permissions, which allows local users to (1) obtain the encrypted server password via the world-readable oekakibbs.conf file, or (2) …
|
NVD-CWE-Other
|
CVE-2002-0202
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267313
|
- |
|
nortel
|
alteon_acedirector
|
Nortel Alteon ACEdirector WebOS 9.0, with the Server Load Balancing (SLB) and Cookie-Based Persistence features enabled, allows remote attackers to determine the real IP address of a web server with …
|
NVD-CWE-Other
|
CVE-2002-0209
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267314
|
- |
|
tolis_group
|
bru
|
setlicense for TOLIS Group Backup and Restore Utility (BRU) 17.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/brutest.$$ temporary file.
|
NVD-CWE-Other
|
CVE-2002-0210
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267315
|
- |
|
intel
|
intel_pro_wireless_2011b_lan_usb_device_driver
|
Compaq Intel PRO/Wireless 2011B LAN USB Device Driver 1.5.16.0 through 1.5.18.0 stores the 128-bit WEP (Wired Equivalent Privacy) key in plaintext in a registry key with weak permissions, which allow…
|
NVD-CWE-Other
|
CVE-2002-0214
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267316
|
- |
|
steve_kneizys
|
agora.cgi
|
Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting a non-existent .html file, which leaks the pathname in an err…
|
NVD-CWE-Other
|
CVE-2002-0215
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267317
|
- |
|
xoops
|
xoops
|
userinfo.php in XOOPS 1.0 RC1 allows remote attackers to obtain sensitive information via a SQL injection attack in the "uid" parameter.
|
NVD-CWE-Other
|
CVE-2002-0216
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267318
|
- |
|
xoops
|
xoops
|
Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on other web clients via (1) the Title field or a Private Messa…
|
NVD-CWE-Other
|
CVE-2002-0217
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267319
|
- |
|
sas
|
sas_base sas_integration_technologies
|
Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via format specifiers in a …
|
NVD-CWE-Other
|
CVE-2002-0218
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267320
|
- |
|
sas
|
sas_base sas_integration_technologies
|
Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via large command line argument.
|
NVD-CWE-Other
|
CVE-2002-0219
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|