270651
|
7.5 |
HIGH
|
anthill
|
anthill
|
Cross-site scripting vulnerabilities in Anthill allow remote attackers to execute script as other Anthill users.
|
NVD-CWE-Other
|
CVE-2002-0549
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270652
|
7.5 |
HIGH
|
gcf
|
dynamic_guestbook
|
Dynamic Guestbook 3.0 allows remote attackers to execute arbitrary code via shell metacharacters in the gbdaten parameter.
|
NVD-CWE-Other
|
CVE-2002-0550
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270653
|
7.5 |
HIGH
|
gcf
|
dynamic_guestbook
|
Cross-site scripting vulnerability in Dynamic Guestbook 3.0 allows remote attackers to execute code in clients who access guestbook pages via the parameters (1) name, (2) mail, or (3) kommentar.
|
NVD-CWE-Other
|
CVE-2002-0551
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270654
|
7.5 |
HIGH
|
melange
|
melange_chat_system
|
Multiple buffer overflows in Melange Chat server 2.02 allow remote or local attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long argument in the /yell com…
|
NVD-CWE-Other
|
CVE-2002-0552
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270655
|
7.5 |
HIGH
|
turnkey_solutions
|
sunshop_shopping_cart
|
Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by injecting the script into fields during new customer registration.
|
NVD-CWE-Other
|
CVE-2002-0553
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270656
|
7.5 |
HIGH
|
ibm
|
informix_web_datablade
|
webdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary files via a SQL injection attack in an HTTP request.
|
NVD-CWE-Other
|
CVE-2002-0554
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270657
|
7.5 |
HIGH
|
ibm
|
informix_web_datablade
|
IBM Informix Web DataBlade 4.12 unescapes user input even if an application has escaped it, which could allow remote attackers to execute SQL code in a web form even when the developer has attempted …
|
NVD-CWE-Other
|
CVE-2002-0555
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270658
|
5.0 |
MEDIUM
|
deep_forest_software
|
quik-serv_webserver
|
Directory traversal vulnerability in Quik-Serv HTTP server 1.1B allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.
|
NVD-CWE-Other
|
CVE-2002-0556
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270659
|
7.5 |
HIGH
|
openbsd
|
openbsd
|
Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, p…
|
NVD-CWE-Other
|
CVE-2002-0557
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270660
|
5.0 |
MEDIUM
|
typsoft
|
typsoft_ftp_server
|
Directory traversal vulnerability in TYPSoft FTP server 0.97.1 and earlier allows a remote authenticated user (possibly anonymous) to list arbitrary directories via a .. in a LIST (ls) command ending…
|
NVD-CWE-Other
|
CVE-2002-0558
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270661
|
7.5 |
HIGH
|
oracle
|
oracle9i
|
Oracle Oracle9i database server 9.0.1.x allows local users to access restricted data via a SQL query using ANSI outer join syntax.
|
NVD-CWE-Other
|
CVE-2002-0571
|
2008-09-6 05:28 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270662
|
5.0 |
MEDIUM
|
allaire
|
coldfusion_server
|
ColdFusion 5.0 and earlier on Windows systems allows remote attackers to determine the absolute pathname of .cfm or .dbm files via an HTTP request that contains an MS-DOS device name such as NUL, whi…
|
NVD-CWE-Other
|
CVE-2002-0576
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270663
|
7.5 |
HIGH
|
aci
|
4d_webserver
|
Buffer overflow in 4D WebServer 6.7.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP request with Basic Authentication containing a long (1) user…
|
NVD-CWE-Other
|
CVE-2002-0578
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270664
|
7.5 |
HIGH
|
workforceroi
|
xpede
|
WorkforceROI Xpede 4.1 allows remote attackers to gain privileges as an Xpede administrator via a direct HTTP request to the /admin/adminproc.asp script, which does not prompt for a password.
|
NVD-CWE-Other
|
CVE-2002-0579
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270665
|
7.5 |
HIGH
|
workforceroi
|
xpede
|
WorkforceROI Xpede 4.1 allows remote attackers to obtain the database username via a request to datasource.asp, which leaks the username in a form and allows the attacker to more easily conduct brute…
|
NVD-CWE-Other
|
CVE-2002-0580
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270666
|
7.5 |
HIGH
|
workforceroi
|
xpede
|
WorkforceROI Xpede 4.1 allows remote attackers to execute arbitrary SQL commands and read, modify, or steal credentials from the database via the Qry parameter in the sprc.asp script.
|
NVD-CWE-Other
|
CVE-2002-0581
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270667
|
5.0 |
MEDIUM
|
workforceroi
|
xpede
|
WorkforceROI Xpede 4.1 stores temporary expense claim reports in a world-readable and indexable /reports/temp directory, which allows remote attackers to read the reports by accessing the directory.
|
NVD-CWE-Other
|
CVE-2002-0582
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270668
|
5.0 |
MEDIUM
|
workforceroi
|
xpede
|
WorkforceROI Xpede 4.1 uses a small random namespace (5 alphanumeric characters) for temporary expense claim reports in the /reports/temp directory, which allows remote attackers to read the reports …
|
NVD-CWE-Other
|
CVE-2002-0583
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270669
|
5.0 |
MEDIUM
|
workforceroi
|
xpede
|
WorkforceROI Xpede 4.1 allows remote attackers to read user timesheets by modifying the TSN ID parameter to the ts_app_process.asp script, which is easily guessable because it is incremented by 1 for…
|
NVD-CWE-Other
|
CVE-2002-0584
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270670
|
7.5 |
HIGH
|
aol
|
aol_server
|
Format string vulnerability in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to execute arbitrary code via…
|
NVD-CWE-Other
|
CVE-2002-0586
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270671
|
7.5 |
HIGH
|
aol
|
aol_server
|
Buffer overflow in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to cause a denial of service or execute a…
|
NVD-CWE-Other
|
CVE-2002-0587
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270672
|
5.0 |
MEDIUM
|
steve_korbett
|
pvote
|
PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.
|
NVD-CWE-Other
|
CVE-2002-0588
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270673
|
7.5 |
HIGH
|
steve_korbett
|
pvote
|
PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with the newpass and confirm parameters both set to the new password.
|
NVD-CWE-Other
|
CVE-2002-0589
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270674
|
7.5 |
HIGH
|
icredibb
|
icredibb
|
Cross-site scripting (CSS) vulnerability in IcrediBB 1.1 Beta allows remote attackers to execute arbitrary script and steal cookies as other IcrediBB users via the (1) title or (2) body of posts.
|
NVD-CWE-Other
|
CVE-2002-0590
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270675
|
5.0 |
MEDIUM
|
aol
|
instant_messenger
|
Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute commands via a Direct Connection with an IMG tag wi…
|
NVD-CWE-Other
|
CVE-2002-0591
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270676
|
7.5 |
HIGH
|
mozilla netscape
|
mozilla communicator navigator
|
Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI.
|
NVD-CWE-Other
|
CVE-2002-0593
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270677
|
5.0 |
MEDIUM
|
galeon mozilla netscape
|
galeon_browser mozilla navigator
|
Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTT…
|
NVD-CWE-Other
|
CVE-2002-0594
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270678
|
7.5 |
HIGH
|
webtrends
|
reporting_center
|
Buffer overflow in WTRS_UI.EXE (WTX_REMOTE.DLL) for WebTrends Reporting Center 4.0d allows remote attackers to execute arbitrary code via a long HTTP GET request to the /reports/ directory.
|
NVD-CWE-Other
|
CVE-2002-0595
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270679
|
7.5 |
HIGH
|
foundstone
|
fscan
|
Format string vulnerability in Foundstone FScan 1.12 with banner grabbing enabled allows remote attackers to execute arbitrary code on the scanning system via format string specifiers in the server b…
|
NVD-CWE-Other
|
CVE-2002-0598
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270680
|
10.0 |
HIGH
|
blahz-dns
|
blahz-dns
|
Blahz-DNS 0.2 and earlier allows remote attackers to bypass authentication and modify configuration by directly requesting CGI programs such as dostuff.php instead of going through the login screen.
|
NVD-CWE-Other
|
CVE-2002-0599
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270681
|
5.0 |
MEDIUM
|
information_security_systems
|
realsecure_network_sensor
|
ISS RealSecure Network Sensor 5.x through 6.5 allows remote attackers to cause a denial of service (crash) via malformed DHCP packets that cause RealSecure to dereference a null pointer.
|
NVD-CWE-Other
|
CVE-2002-0601
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270682
|
7.5 |
HIGH
|
3com
|
3cdaemon
|
Buffer overflow in 3Cdaemon 2.0 FTP server allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long commands such as login.
|
NVD-CWE-Other
|
CVE-2002-0606
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270683
|
7.5 |
HIGH
|
snitz_communications
|
snitz_forums_2000
|
members.asp in Snitz Forums 2000 version 3.3.03 and earlier allows remote attackers to execute arbitrary code via a SQL injection attack on the parameters (1) M_NAME, (2) UserName, (3) FirstName, (4)…
|
NVD-CWE-Other
|
CVE-2002-0607
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270684
|
7.5 |
HIGH
|
matu
|
matu_ftp
|
Buffer overflow in Matu FTP client 1.74 allows remote FTP servers to execute arbitrary code via a long "220" banner.
|
NVD-CWE-Other
|
CVE-2002-0608
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270685
|
5.0 |
MEDIUM
|
hp
|
mpe_ix
|
Vulnerability in HP MPE/iX 6.0 through 7.0 allows attackers to cause a denial of service (system failure with "SA1457 out of i_port_timeout.fix_up_message_frame") via malformed IP packets.
|
NVD-CWE-Other
|
CVE-2002-0609
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270686
|
7.5 |
HIGH
|
hp
|
mpe_ix
|
Vulnerability in FTPSRVR in HP MPE/iX 6.0 through 7.0 does not properly validate certain FTP commands, which allows attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-0610
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270687
|
5.0 |
MEDIUM
|
craig_patchett
|
fileseek
|
Directory traversal vulnerability in FileSeek.cgi allows remote attackers to read arbitrary files via a ....// (modified dot dot) in the (1) head or (2) foot parameters, which are not properly filter…
|
NVD-CWE-Other
|
CVE-2002-0611
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270688
|
7.5 |
HIGH
|
craig_patchett
|
fileseek
|
FileSeek.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) head or (2) foot parameters.
|
NVD-CWE-Other
|
CVE-2002-0612
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270689
|
10.0 |
HIGH
|
dnstools_software
|
dnstools
|
dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user_logged_in or user_dnstools_administrator parameters.
|
NVD-CWE-Other
|
CVE-2002-0613
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270690
|
5.0 |
MEDIUM
|
php-survey
|
php-survey
|
PHP-Survey 20000615 and earlier stores the global.inc file under the web root, which allows remote attackers to obtain sensitive information, including database credentials, if .inc files are not pre…
|
NVD-CWE-Other
|
CVE-2002-0614
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270691
|
7.5 |
HIGH
|
trend_micro
|
interscan_viruswall
|
InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unex…
|
NVD-CWE-Other
|
CVE-2002-0637
|
2008-09-6 05:28 |
2002-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270692
|
5.0 |
MEDIUM
|
pingtel
|
xpressa
|
The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows administrators to cause a denial of service by modifying the SIP_AUTHENTICATE_SCHEME value to force au…
|
NVD-CWE-Other
|
CVE-2002-0669
|
2008-09-6 05:28 |
2003-02-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270693
|
7.5 |
HIGH
|
pingtel
|
xpressa
|
The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to s…
|
NVD-CWE-Other
|
CVE-2002-0670
|
2008-09-6 05:28 |
2002-07-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270694
|
4.6 |
MEDIUM
|
pingtel
|
xpressa
|
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to restore the phone to factory defaults without authentication via a menu option, which sets…
|
NVD-CWE-Other
|
CVE-2002-0672
|
2008-09-6 05:28 |
2002-07-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270695
|
4.6 |
MEDIUM
|
pingtel
|
xpressa
|
The enrollment process for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to the phone to log out the current user and re-register the phone…
|
NVD-CWE-Other
|
CVE-2002-0673
|
2008-09-6 05:28 |
2002-07-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270696
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via t…
|
NVD-CWE-Other
|
CVE-2002-0676
|
2008-09-6 05:28 |
2002-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270697
|
5.0 |
MEDIUM
|
zope
|
zope
|
The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers.
|
NVD-CWE-Other
|
CVE-2002-0687
|
2008-09-6 05:28 |
2002-07-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270698
|
7.5 |
HIGH
|
zope
|
zope
|
ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes.
|
NVD-CWE-Other
|
CVE-2002-0688
|
2008-09-6 05:28 |
2002-07-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270699
|
7.5 |
HIGH
|
gisle_aas
|
digest-md5
|
An interaction between the Perl MD5 module (perl-Digest-MD5) and Perl could produce incorrect MD5 checksums for UTF-8 data, which could prevent a system from properly verifying the integrity of the d…
|
NVD-CWE-Other
|
CVE-2002-0703
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270700
|
5.0 |
MEDIUM
|
greg_roelofs
|
libpng
|
Buffer overflow in the progressive reader for libpng 1.2.x before 1.2.4, and 1.0.x before 1.0.14, allows attackers to cause a denial of service (crash) via a PNG data stream that has more IDAT data t…
|
NVD-CWE-Other
|
CVE-2002-0728
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|