270301
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Unknown vulnerability in NetInfo Manager application in Mac OS X 10.2.2 allows local users to access restricted parts of a filesystem.
|
NVD-CWE-Other
|
CVE-2002-1269
|
2008-09-6 05:30 |
2002-12-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270302
|
4.3 |
MEDIUM
|
squirrelmail
|
squirrelmail
|
An incomplete fix for a cross-site scripting (XSS) vulnerability in SquirrelMail 1.2.8 calls the strip_tags function on the PHP_SELF value but does not save the result back to that variable, leaving …
|
NVD-CWE-Other
|
CVE-2002-1276
|
2008-09-6 05:30 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270303
|
7.5 |
HIGH
|
windowmaker
|
windowmaker
|
Buffer overflow in Window Maker (wmaker) 0.80.0 and earlier may allow remote attackers to execute arbitrary code via a certain image file that is not properly handled when Window Maker uses width and…
|
NVD-CWE-Other
|
CVE-2002-1277
|
2008-09-6 05:30 |
2002-11-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270304
|
7.2 |
HIGH
|
hp
|
hp-ux
|
Unknown vulnerability in passwd for VVOS HP-UX 11.04, with unknown impact, related to "Unexpected behavior."
|
NVD-CWE-Other
|
CVE-2002-1406
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270305
|
7.5 |
HIGH
|
hp
|
openview_emanate_snmp_agent vvos
|
Unknown vulnerability or vulnerabilities in HP OpenView EMANATE 14.2 snmpModules allow the SNMP read-write community name to be exposed, related to (1) "'read-only' community access," and/or (2) an e…
|
NVD-CWE-Other
|
CVE-2002-1408
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270306
|
7.5 |
HIGH
|
ben_chivers easy_scripts_archive
|
ben_chivers_guestbook easy_guestbook
|
Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access o…
|
NVD-CWE-Other
|
CVE-2002-1410
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270307
|
5.0 |
MEDIUM
|
duma
|
photo_gallery_system
|
Directory traversal vulnerability in update.dpgs in Duma Photo Gallery System (DPGS) 0.99.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the id parameter.
|
NVD-CWE-Other
|
CVE-2002-1411
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270308
|
7.5 |
HIGH
|
novell
|
netware
|
RCONAG6 for Novell Netware SP2, while running RconJ in secure mode, allows remote attackers to bypass authentication using the RconJ "Secure IP" (SSL) option during a connection.
|
NVD-CWE-Other
|
CVE-2002-1413
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270309
|
5.0 |
MEDIUM
|
webeasymail
|
webeasymail
|
Format string vulnerability in SMTP service for WebEasyMail 3.4.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in …
|
NVD-CWE-Other
|
CVE-2002-1415
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270310
|
5.0 |
MEDIUM
|
webeasymail
|
webeasymail
|
The POP3 service for WebEasyMail 3.4.2.2 and earlier generates diffferent error messages for valid and invalid usernames during authentication, which makes it easier for remote attackers to conduct b…
|
NVD-CWE-Other
|
CVE-2002-1416
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270311
|
5.0 |
MEDIUM
|
novell
|
small_business_suite netware
|
Directory traversal vulnerability in Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to read arbitrary files via a URL…
|
NVD-CWE-Other
|
CVE-2002-1417
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270312
|
5.0 |
MEDIUM
|
novell
|
small_business_suite netware
|
Buffer overflow in the interpreter for Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to cause a denial of service (A…
|
NVD-CWE-Other
|
CVE-2002-1418
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270313
|
7.5 |
HIGH
|
sgi
|
irix
|
The upgrade of IRIX on Origin 3000 to 6.5.13 through 6.5.16 changes the MAC address of the system, which could modify intended access restrictions that are based on a MAC address.
|
NVD-CWE-Other
|
CVE-2002-1419
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270314
|
7.5 |
HIGH
|
ilia_alshanetsky
|
fudforum
|
SQL injection vulnerabilities in FUDforum before 2.2.0 allow remote attackers to perform unauthorized database operations via (1) report.php, (2) selmsg.php, and (3) showposts.php.
|
NVD-CWE-Other
|
CVE-2002-1421
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270315
|
5.0 |
MEDIUM
|
ilia_alshanetsky
|
fudforum
|
admbrowse.php in FUDforum before 2.2.0 allows remote attackers to create or delete files via URL-encoded pathnames in the cur and dest parameters.
|
NVD-CWE-Other
|
CVE-2002-1422
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270316
|
5.0 |
MEDIUM
|
ilia_alshanetsky
|
fudforum
|
tmp_view.php in FUDforum before 2.2.0 allows remote attackers to read arbitrary files via an absolute pathname in the file parameter.
|
NVD-CWE-Other
|
CVE-2002-1423
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270317
|
5.0 |
MEDIUM
|
john_g._myers
|
mpack
|
Buffer overflow in munpack in mpack 1.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2002-1424
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270318
|
6.4 |
MEDIUM
|
john_g._myers
|
mpack
|
Directory traversal vulnerability in munpack in mpack 1.5 and earlier allows remote attackers to create new files in the parent directory via a ../ (dot-dot) sequence in the filename to be extracted.
|
NVD-CWE-Other
|
CVE-2002-1425
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270319
|
7.8 |
HIGH
|
hp
|
procurve_switch_4000m
|
HP ProCurve Switch 4000M C.07.23 allows remote attackers to cause a denial of service (crash) via an SNMP write request containing 85 characters, possibly triggering a buffer overflow.
|
NVD-CWE-Other
|
CVE-2002-1426
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270320
|
7.5 |
HIGH
|
easy_scripts_archive
|
advanced_easy_homepage_creator easy_homepage_creator
|
The print_html_to_file function in edit.cgi for Easy Homepage Creator 1.0 does not check user credentials, which allows remote attackers to modify home pages of other users.
|
NVD-CWE-Other
|
CVE-2002-1427
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270321
|
10.0 |
HIGH
|
dotproject
|
dotproject
|
index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1.
|
NVD-CWE-Other
|
CVE-2002-1428
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270322
|
5.0 |
MEDIUM
|
synthetic_reality
|
sympoll
|
Unknown vulnerability in Sympoll 1.2 allows remote attackers to read arbitrary files when register_globals is enabled, possibly by modifying certain PHP variables through URL parameters.
|
NVD-CWE-Other
|
CVE-2002-1430
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270323
|
7.5 |
HIGH
|
belkin
|
f5d5230-4_4-port_cable_dsl_gateway_router
|
Belkin F5D5230-4 4-Port Cable/DSL Gateway Router 1.20.000 modifies the source IP address of internal packets to that of the router's external interface when forwarding a request from an internal host…
|
NVD-CWE-Other
|
CVE-2002-1431
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270324
|
5.0 |
MEDIUM
|
kerio
|
kerio_mailserver
|
Kerio MailServer 5.0 allows remote attackers to cause a denial of service (hang) via SYN packets to the supported network services.
|
NVD-CWE-Other
|
CVE-2002-1433
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270325
|
6.8 |
MEDIUM
|
kerio
|
kerio_mailserver
|
Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML script as other users via certain URLs.
|
NVD-CWE-Other
|
CVE-2002-1434
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270326
|
7.5 |
HIGH
|
achievo
|
achievo
|
class.atkdateattribute.js.php in Achievo 0.7.0 through 0.9.1, except 0.8.2, allows remote attackers to execute arbitrary PHP code when the 'allow_url_fopen' setting is enabled via a URL in the config…
|
NVD-CWE-Other
|
CVE-2002-1435
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270327
|
7.5 |
HIGH
|
novell
|
netware
|
The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary Perl code via an HTTP POST request.
|
NVD-CWE-Other
|
CVE-2002-1436
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270328
|
5.0 |
MEDIUM
|
novell
|
netware
|
Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-enc…
|
NVD-CWE-Other
|
CVE-2002-1437
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270329
|
5.0 |
MEDIUM
|
novell
|
netware
|
The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to obtain Perl version information via the -v option.
|
NVD-CWE-Other
|
CVE-2002-1438
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270330
|
4.6 |
MEDIUM
|
hp
|
virtualvault vvos
|
Unknown vulnerability related to stack corruption in the TGA daemon for HP-UX 11.04 (VVOS) Virtualvault 4.0, 4.5, and 4.6 may allow attackers to obtain access to system files.
|
NVD-CWE-Other
|
CVE-2002-1439
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270331
|
10.0 |
HIGH
|
gateway
|
gs-400
|
The Gateway GS-400 server has a default root password of "0001n" that can not be changed via the administrative interface, which can allow attackers to gain root privileges.
|
NVD-CWE-Other
|
CVE-2002-1440
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270332
|
7.5 |
HIGH
|
tomahawk_technologies
|
steelarrow
|
Multiple buffer overflows in Tomahawk SteelArrow before 4.5 allow remote attackers to execute arbitrary code via (1) the Steelarrow Service (Steelarrow.exe) using a long UserIdent Cookie header, (2) …
|
NVD-CWE-Other
|
CVE-2002-1441
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270333
|
7.5 |
HIGH
|
google
|
toolbar
|
The Google toolbar 1.1.58 and earlier allows remote web sites to perform unauthorized toolbar operations including script execution and file reading in other zones such as "My Computer" by opening a …
|
NVD-CWE-Other
|
CVE-2002-1442
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270334
|
4.3 |
MEDIUM
|
w3c
|
cern_httpd
|
Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-existent page whose name contains the script, which is inser…
|
NVD-CWE-Other
|
CVE-2002-1445
|
2008-09-6 05:30 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270335
|
5.0 |
MEDIUM
|
ncipher
|
pkcs_11_library
|
The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects an invalid signatur…
|
NVD-CWE-Other
|
CVE-2002-1446
|
2008-09-6 05:30 |
2002-08-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270336
|
7.2 |
HIGH
|
cisco
|
vpn_client
|
Buffer overflow in the vpnclient program for UNIX VPN Client before 3.5.2 allows local users to gain administrative privileges via a long profile name in a connect argument.
|
NVD-CWE-Other
|
CVE-2002-1447
|
2008-09-6 05:30 |
2002-05-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270337
|
7.5 |
HIGH
|
avaya
|
cajun_m770-atm cajun_p130 cajun_p330
|
An undocumented SNMP read/write community string ('NoGaH$@!') in Avaya P330, P130, and M770-ATM Cajun products allows remote attackers to gain administrative privileges.
|
NVD-CWE-Other
|
CVE-2002-1448
|
2008-09-6 05:30 |
2002-07-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270338
|
5.0 |
MEDIUM
|
ibm
|
u2_universe
|
IBM UniVerse with UV/ODBC allows attackers to cause a denial of service (client crash or server CPU consumption) via a query with an invalid link between tables, possibly via a buffer overflow.
|
NVD-CWE-Other
|
CVE-2002-1450
|
2008-09-6 05:30 |
2002-07-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270339
|
5.0 |
MEDIUM
|
desiderata_software
|
blazix
|
Blazix before 1.2.2 allows remote attackers to read source code of JSP scripts or list restricted web directories via an HTTP request that ends in a (1) "+" or (2) "\" (backslash) character.
|
NVD-CWE-Other
|
CVE-2002-1451
|
2008-09-6 05:30 |
2002-08-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270340
|
4.3 |
MEDIUM
|
omnicron
|
omnihttpd
|
Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.
|
NVD-CWE-Other
|
CVE-2002-1455
|
2008-09-6 05:30 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270341
|
7.5 |
HIGH
|
leszek_krupinski
|
l-forum
|
SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements via the search parameter.
|
NVD-CWE-Other
|
CVE-2002-1457
|
2008-09-6 05:30 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270342
|
7.5 |
HIGH
|
leszek_krupinski
|
l-forum
|
Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields includin…
|
NVD-CWE-Other
|
CVE-2002-1458
|
2008-09-6 05:30 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270343
|
7.5 |
HIGH
|
leszek_krupinski
|
l-forum
|
Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields includi…
|
NVD-CWE-Other
|
CVE-2002-1459
|
2008-09-6 05:30 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270344
|
5.0 |
MEDIUM
|
leszek_krupinski
|
l-forum
|
L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which…
|
NVD-CWE-Other
|
CVE-2002-1460
|
2008-09-6 05:30 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270345
|
7.5 |
HIGH
|
webscriptworld
|
web_shop_manager
|
Web Shop Manager 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search box.
|
NVD-CWE-Other
|
CVE-2002-1461
|
2008-09-6 05:30 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270346
|
5.0 |
MEDIUM
|
organicphp
|
php-affiliate
|
details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields.
|
NVD-CWE-Other
|
CVE-2002-1462
|
2008-09-6 05:30 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270347
|
6.8 |
MEDIUM
|
cafelog
|
b2
|
Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable.
|
NVD-CWE-Other
|
CVE-2002-1464
|
2008-09-6 05:30 |
2003-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270348
|
7.5 |
HIGH
|
cafelog
|
b2
|
SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable.
|
NVD-CWE-Other
|
CVE-2002-1465
|
2008-09-6 05:30 |
2003-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270349
|
10.0 |
HIGH
|
cafelog
|
b2
|
CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable.
|
NVD-CWE-Other
|
CVE-2002-1466
|
2008-09-6 05:30 |
2003-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270350
|
5.0 |
MEDIUM
|
macromedia
|
flash_player shockwave
|
Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3)…
|
NVD-CWE-Other
|
CVE-2002-1467
|
2008-09-6 05:30 |
2003-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|