270601
|
5.1 |
MEDIUM
|
phpbb_group
|
phpbb
|
Cross-site scripting vulnerability in phpBB 1.4.4 and earlier allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within an IMG image tag while editing a me…
|
NVD-CWE-Other
|
CVE-2002-0475
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270602
|
5.0 |
MEDIUM
|
macromedia
|
flash_player
|
Standalone Macromedia Flash Player 5.0 allows remote attackers to save arbitrary files and programs via a .SWF file containing the undocumented "save" FSCommand.
|
NVD-CWE-Other
|
CVE-2002-0476
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270603
|
7.2 |
HIGH
|
gravity_storm_software
|
service_pack_manager_2000
|
Gravity Storm Service Pack Manager 2000 creates a hidden share (SPM2000c$) mapped to the C drive, which may allow local users to bypass access restrictions on certain directories in the C drive, such…
|
NVD-CWE-Other
|
CVE-2002-0479
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270604
|
5.1 |
MEDIUM
|
microsoft
|
outlook
|
An interaction between Windows Media Player (WMP) and Outlook 2002 allows remote attackers to bypass Outlook security settings and execute Javascript via an IFRAME in an HTML email message that refer…
|
NVD-CWE-Other
|
CVE-2002-0481
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270605
|
5.0 |
MEDIUM
|
newlog
|
netsupport_manager
|
Directory traversal vulnerability in PCI Netsupport Manager before version 7, when running web extensions, allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP GET request.
|
NVD-CWE-Other
|
CVE-2002-0482
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270606
|
5.0 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that l…
|
NVD-CWE-Other
|
CVE-2002-0483
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270607
|
4.6 |
MEDIUM
|
workforceroi
|
xpede
|
Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by…
|
NVD-CWE-Other
|
CVE-2002-0487
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270608
|
10.0 |
HIGH
|
instant_web_mail
|
instant_web_mail
|
Instant Web Mail before 0.60 does not properly filter CR/LF sequences, which allows remote attackers to (1) execute arbitrary POP commands via the id parameter in message.php, or (2) modify certain m…
|
NVD-CWE-Other
|
CVE-2002-0490
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270609
|
10.0 |
HIGH
|
alguest
|
alguest
|
admin.php in AlGuest 1.0 guestbook checks for the existence of the admin cookie to authenticate the AlGuest administrator, which allows remote attackers to bypass the authentication and gain privileg…
|
NVD-CWE-Other
|
CVE-2002-0491
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270610
|
5.0 |
MEDIUM
|
dcscripts
|
dcshop
|
dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.
|
NVD-CWE-Other
|
CVE-2002-0492
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270611
|
7.5 |
HIGH
|
websight_directory_system
|
websight_directory_system
|
Cross-site scripting vulnerability in WebSight Directory System 0.1 allows remote attackers to execute arbitrary Javascript and gain access to the WebSight administrator via a new link submission con…
|
NVD-CWE-Other
|
CVE-2002-0494
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270612
|
7.5 |
HIGH
|
websight_directory_system
|
websight_directory_system
|
This vulnerability is addressed in the following product release:
WebSight Directory System, WebSight Directory System, 0.1.1
|
NVD-CWE-Other
|
CVE-2002-0494
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270613
|
5.0 |
MEDIUM
|
southwest
|
southwest
|
The HTTP server for SouthWest Talker server 1.0.0 allows remote attackers to cause a denial of service (server crash) via a malformed URL to port 5002.
|
NVD-CWE-Other
|
CVE-2002-0496
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270614
|
2.1 |
LOW
|
mtr
|
mtr
|
Buffer overflow in mtr 0.46 and earlier, when installed setuid root, allows local users to access a raw socket via a long MTR_OPTIONS environment variable.
|
NVD-CWE-Other
|
CVE-2002-0497
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270615
|
4.6 |
MEDIUM
|
etnus
|
totalview
|
Etnus TotalView 5.0.0-4 installs certain files with UID 5039 and GID 59, which could allow local users with that UID or GID to modify the files and gain privileges as other TotalView users.
|
NVD-CWE-Other
|
CVE-2002-0498
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270616
|
2.1 |
LOW
|
linux
|
linux_kernel
|
The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappr…
|
NVD-CWE-Other
|
CVE-2002-0499
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270617
|
7.2 |
HIGH
|
posadis
|
posadis
|
Format string vulnerability in log_print() function of Posadis DNS server before version m5pre2 allows local users and possibly remote attackers to execute arbitrary code via format strings that are …
|
NVD-CWE-Other
|
CVE-2002-0501
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270618
|
5.0 |
MEDIUM
|
citrix
|
nfuse
|
Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter.
|
NVD-CWE-Other
|
CVE-2002-0503
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270619
|
7.5 |
HIGH
|
citrix
|
nfuse
|
Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_…
|
NVD-CWE-Other
|
CVE-2002-0504
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270620
|
5.0 |
MEDIUM
|
cisco
|
call_manager
|
Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.1(3) allows remote attackers to cause a denial of service (crash and reload) vi…
|
NVD-CWE-Other
|
CVE-2002-0505
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270621
|
7.2 |
HIGH
|
redhat
|
linux
|
Buffer overflow in newt.c of newt windowing library (libnewt) 0.50.33 and earlier may allow attackers to cause a denial of service or execute arbitrary code in setuid programs that use libnewt.
|
NVD-CWE-Other
|
CVE-2002-0506
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270622
|
10.0 |
HIGH
|
wwwisis
|
wwwisis
|
wwwisis 3.45 and earlier allows remote attackers to execute arbitrary commands and read files via the parameters (1) prolog or (2) epilog.
|
NVD-CWE-Other
|
CVE-2002-0508
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270623
|
5.0 |
MEDIUM
|
oracle
|
oracle9i
|
Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a single malformed TCP packet to port 1521.
|
NVD-CWE-Other
|
CVE-2002-0509
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270624
|
5.0 |
MEDIUM
|
linux
|
linux_kernel
|
The UDP implementation in Linux 2.4.x kernels keeps the IP Identification field at 0 for all non-fragmented packets, which could allow remote attackers to determine that a target system is running Li…
|
NVD-CWE-Other
|
CVE-2002-0510
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270625
|
7.5 |
HIGH
|
nscd
|
nscd
|
The default configuration of Name Service Cache Daemon (nscd) in Caldera OpenLinux 3.1 and 3.1.1 uses cached PTR records instead of consulting the authoritative DNS server for the A record, which cou…
|
NVD-CWE-Other
|
CVE-2002-0511
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270626
|
4.6 |
MEDIUM
|
caldera
|
openlinux_server openlinux_workstation
|
startkde in KDE for Caldera OpenLinux 2.3 through 3.1.1 sets the LD_LIBRARY_PATH environment variable to include the current working directory, which could allow local users to gain privileges of oth…
|
NVD-CWE-Other
|
CVE-2002-0512
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270627
|
10.0 |
HIGH
|
squirrelmail
|
squirrelmail
|
SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cookie.
|
NVD-CWE-Other
|
CVE-2002-0516
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270628
|
7.2 |
HIGH
|
caldera
|
unixware openunix
|
Buffer overflow in X11 library (libX11) on Caldera Open UNIX 8.0.0, UnixWare 7.1.1, and possibly other operating systems, allows local users to gain root privileges via a long -xrm argument to progra…
|
NVD-CWE-Other
|
CVE-2002-0517
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270629
|
5.0 |
MEDIUM
|
freebsd
|
freebsd
|
The SYN cache (syncache) and SYN cookie (syncookie) mechanism in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (crash) (1) via a SYN packet that is accepted using synco…
|
NVD-CWE-Other
|
CVE-2002-0518
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270630
|
7.5 |
HIGH
|
asp-nuke
|
asp-nuke
|
Cross-site scripting vulnerability in functions-inc.asp for ASP-Nuke RC1 allows remote attackers to execute script as other ASP-Nuke users by embedding it within an IMG tag.
|
NVD-CWE-Other
|
CVE-2002-0520
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270631
|
5.1 |
MEDIUM
|
asp-nuke
|
asp-nuke
|
Cross-site scripting vulnerabilities in ASP-Nuke RC2 and earlier allow remote attackers to execute script or gain privileges as other ASP-Nuke users via script in (1) the name parameter in downloads.…
|
NVD-CWE-Other
|
CVE-2002-0521
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270632
|
7.5 |
HIGH
|
asp-nuke
|
asp-nuke
|
ASP-Nuke RC2 and earlier allows remote attackers to bypass authentication and gain privileges by modifying the "pseudo" cookie.
|
NVD-CWE-Other
|
CVE-2002-0522
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270633
|
5.0 |
MEDIUM
|
asp-nuke
|
asp-nuke
|
ASP-Nuke RC2 and earlier allows remote attackers to list all logged-in users by submitting an invalid "pseudo" cookie.
|
NVD-CWE-Other
|
CVE-2002-0523
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270634
|
5.0 |
MEDIUM
|
asp-nuke
|
asp-nuke
|
ASP-Nuke RC2 and earlier allows remote attackers to determine the absolute path of the server by (1) calling database-inc.asp with incorrect cookies, or (2) calling Post.asp with certain arguments, w…
|
NVD-CWE-Other
|
CVE-2002-0524
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270635
|
10.0 |
HIGH
|
isc
|
inn
|
Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses.
|
NVD-CWE-Other
|
CVE-2002-0525
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270636
|
5.0 |
MEDIUM
|
watchguard
|
soho_firewall
|
Watchguard SOHO firewall before 5.0.35 allows remote attackers to cause a denial of service (crash and reboot) when SOHO forwards a packet with bad IP options.
|
NVD-CWE-Other
|
CVE-2002-0527
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270637
|
10.0 |
HIGH
|
watchguard
|
soho_firewall
|
Watchguard SOHO firewall 5.0.35 unpredictably disables certain IP restrictions for customized services that were set before the administrator upgrades to 5.0.35, which could allow remote attackers to…
|
NVD-CWE-Other
|
CVE-2002-0528
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270638
|
6.2 |
MEDIUM
|
hp
|
photosmart_print_driver
|
HP Photosmart printer driver for Mac OS X installs the hp_imaging_connectivity program and the hp_imaging_connectivity.app directory with world-writable permissions, which allows local users to gain …
|
NVD-CWE-Other
|
CVE-2002-0529
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270639
|
5.0 |
MEDIUM
|
emumail
|
emumail emumail_red_hat_linux emumail_unix
|
Directory traversal vulnerability in emumail.cgi in EMU Webmail 4.5.x and 5.1.0 allows remote attackers to read arbitrary files or list arbitrary directories via a .. (dot dot) in the type parameter.
|
NVD-CWE-Other
|
CVE-2002-0531
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270640
|
7.2 |
HIGH
|
emumail
|
emumail emumail_red_hat_linux emumail_unix
|
EMU Webmail allows local users to execute arbitrary programs via a .. (dot dot) in the HTTP Host header that points to a Trojan horse configuration file that contains a pageroot specifier that contai…
|
NVD-CWE-Other
|
CVE-2002-0532
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270641
|
5.0 |
MEDIUM
|
postboard
|
postboard
|
PostBoard 2.0.1 and earlier with BBcode allows remote attackers to cause a denial of service (CPU consumption) and corrupt the database via null \0 characters within [code] tags.
|
NVD-CWE-Other
|
CVE-2002-0534
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270642
|
7.5 |
HIGH
|
phpgroupware
|
phpgroupware
|
PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the database via a SQL injection attack.
|
NVD-CWE-Other
|
CVE-2002-0536
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270643
|
10.0 |
HIGH
|
stepweb
|
sws
|
The admin.html file in StepWeb Search Engine (SWS) 2.5 stores passwords in links to manager.pl, which allows remote attackers who can access the admin.html file to gain administrative privileges to S…
|
NVD-CWE-Other
|
CVE-2002-0537
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270644
|
10.0 |
HIGH
|
demarc_security
|
puresecure
|
Demarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session ID that is stored in the s_key cookie.
|
NVD-CWE-Other
|
CVE-2002-0539
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270645
|
7.5 |
HIGH
|
nortel
|
cvx_1800_multi-service_access_switch
|
Nortel CVX 1800 is installed with a default "public" community string, which allows remote attackers to read usernames and passwords and modify the CVX configuration.
|
NVD-CWE-Other
|
CVE-2002-0540
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270646
|
7.5 |
HIGH
|
ibm
|
tivoli_storage_manager
|
Buffer overflow in Tivoli Storage Manager TSM (1) Server or Storage Agents 3.1 through 5.1, and (2) the TSM Client Acceptor Service 4.2 and 5.1, allows remote attackers to cause a denial of service (…
|
NVD-CWE-Other
|
CVE-2002-0541
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270647
|
5.0 |
MEDIUM
|
aprelium_technologies
|
abyss_web_server
|
Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read files outside the web root, including the abyss.conf file, via URL-encoded .. (…
|
NVD-CWE-Other
|
CVE-2002-0543
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270648
|
7.2 |
HIGH
|
aprelium_technologies
|
abyss_web_server
|
Aprelium Abyss Web Server (abyssws) before 1.0.3 stores the administrative console password in plaintext in the abyss.conf file, which allows local users with access to the file to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-0544
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270649
|
5.0 |
MEDIUM
|
cisco
|
aironet_ap340 aironet_ap350
|
Cisco Aironet before 11.21 with Telnet enabled allows remote attackers to cause a denial of service (reboot) via a series of login attempts with invalid usernames and passwords.
|
NVD-CWE-Other
|
CVE-2002-0545
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270650
|
7.5 |
HIGH
|
nullsoft
|
winamp
|
Cross-site scripting vulnerability in the mini-browser for Winamp 2.78 and 2.79 allows remote attackers to execute script via an ID3v1 or ID3v2 tag in an MP3 file.
|
NVD-CWE-Other
|
CVE-2002-0546
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|