276551
|
10.0 |
HIGH
|
stefan_frings
|
sms_server_tools
|
Smsd in SMS Server Tools (SMStools) before 1.4.8 allows remote attackers to execute arbitrary commands via shell metacharacters (backquotes) in message text, as described with the term "string format…
|
NVD-CWE-Other
|
CVE-2002-0437
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276552
|
7.5 |
HIGH
|
caupo.net
|
cauposhop
|
Cross-site scripting vulnerability in CaupoShop 1.30a and earlier, and possibly CaupoShopPro, allows remote attackers to execute arbitrary Javascript and steal credit card numbers or delete items by …
|
NVD-CWE-Other
|
CVE-2002-0439
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276553
|
5.0 |
MEDIUM
|
jerrett_taylor
|
php_imglist
|
Directory traversal vulnerability in imlist.php for Php Imglist allows remote attackers to read arbitrary code via a .. (dot dot) in the cwd parameter.
|
NVD-CWE-Other
|
CVE-2002-0441
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276554
|
7.2 |
HIGH
|
caldera
|
openserver
|
Buffer overflow in dlvr_audit for Caldera OpenServer 5.0.5 and 5.0.6 allows local users to gain root privileges.
|
NVD-CWE-Other
|
CVE-2002-0442
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276555
|
7.5 |
HIGH
|
microsoft
|
windows_2000_terminal_services
|
Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL shar…
|
NVD-CWE-Other
|
CVE-2002-0444
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276556
|
5.0 |
MEDIUM
|
php_firstpost
|
php_firstpost
|
article.php in PHP FirstPost 0.1 allows allows remote attackers to obtain the full pathname of the server via an invalid post number in the post parameter, which leaks the pathname in an error messag…
|
NVD-CWE-Other
|
CVE-2002-0445
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276557
|
5.0 |
MEDIUM
|
black_tie_project
|
black_tie_project
|
categorie.php3 in Black Tie Project (BTP) 0.4b through 0.5b allows remote attackers to determine the absolute path of the web server via an invalid category ID (cid) parameter, which leaks the pathna…
|
NVD-CWE-Other
|
CVE-2002-0446
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276558
|
5.0 |
MEDIUM
|
xerver
|
xerver
|
Directory traversal vulnerability in Xerver Free Web Server 2.10 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in an HTTP GET request.
|
NVD-CWE-Other
|
CVE-2002-0447
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276559
|
5.0 |
MEDIUM
|
xerver
|
xerver
|
Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many "C:/" sequences.
|
NVD-CWE-Other
|
CVE-2002-0448
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276560
|
7.5 |
HIGH
|
phpprojekt
|
phpprojekt
|
filemanager_forms.php in PHProjekt 3.1 and 3.1a allows remote attackers to execute arbitrary PHP code by specifying the URL to the code in the lib_path parameter.
|
NVD-CWE-Other
|
CVE-2002-0451
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276561
|
7.5 |
HIGH
|
foundrynet
|
serveriron
|
Foundry Networks ServerIron switches do not decode URIs when applying "url-map" rules, which could make it easier for attackers to cause the switch to forward traffic to a different server than inten…
|
NVD-CWE-Other
|
CVE-2002-0452
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276562
|
7.5 |
HIGH
|
oblix
|
netpoint
|
The account lockout capability in Oblix NetPoint 5.2 and earlier only locks out users once for the specified lockout period, which makes it easier for remote attackers to conduct brute force password…
|
NVD-CWE-Other
|
CVE-2002-0453
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276563
|
5.0 |
MEDIUM
|
qualcomm
|
qpopper
|
Qpopper (aka in.qpopper or popper) 4.0.3 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a very large string, which causes an infinite loop.
|
NVD-CWE-Other
|
CVE-2002-0454
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276564
|
5.0 |
MEDIUM
|
incredimail
|
incredimail
|
IncrediMail stores attachments in a directory with a fixed name, which could make it easier for attackers to exploit vulnerabilities in other software that rely on installing and reading files from d…
|
NVD-CWE-Other
|
CVE-2002-0455
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276565
|
7.6 |
HIGH
|
bg_guestbook
|
bg_guestbook
|
Cross-site scripting vulnerability in signgbook.php for BG GuestBook 1.0 allows remote attackers to execute arbitrary Javascript via encoded tags such as <, >, and & in fields such as (1) n…
|
NVD-CWE-Other
|
CVE-2002-0457
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276566
|
7.6 |
HIGH
|
linux-sottises
|
news-tnk
|
Cross-site scripting vulnerability in News-TNK 1.2.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter.
|
NVD-CWE-Other
|
CVE-2002-0458
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276567
|
7.6 |
HIGH
|
linux-sottises
|
board-tnk news-tnk
|
Cross-site scripting vulnerability in Board-TNK 1.3.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter.
|
NVD-CWE-Other
|
CVE-2002-0459
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276568
|
5.0 |
MEDIUM
|
bitvise
|
winsshd
|
Bitvise WinSSHD before 2002-03-16 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of incomplete connections that are not properly terminated, which are n…
|
NVD-CWE-Other
|
CVE-2002-0460
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276569
|
6.4 |
MEDIUM
|
big_sam
|
big_sam
|
bigsam_guestbook.php for Big Sam (Built-In Guestbook Stand-Alone Module) 1.1.08 and earlier allows remote attackers to cause a denial of service (CPU consumption) or obtain the absolute path of the w…
|
NVD-CWE-Other
|
CVE-2002-0462
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276570
|
5.0 |
MEDIUM
|
arsc_really_simple_chat
|
arsc_really_simple_chat
|
home.php in ARSC (Really Simple Chat) 1.0.1 and earlier allows remote attackers to determine the full pathname of the web server via an invalid language in the arsc_language parameter, which leaks th…
|
NVD-CWE-Other
|
CVE-2002-0463
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276571
|
6.4 |
MEDIUM
|
hosting_controller
|
hosting_controller
|
Directory traversal vulnerability in Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files and directories via a .. (dot dot) in arguments to (1) file_editor…
|
NVD-CWE-Other
|
CVE-2002-0464
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276572
|
10.0 |
HIGH
|
ecartis listar
|
ecartis listar
|
Buffer overflows in Ecartis (formerly Listar) 1.0.0 before snapshot 20020125 allows remote attackers to execute arbitrary code via (1) address_match() of mystring.c or (2) other functions in tolist.c.
|
NVD-CWE-Other
|
CVE-2002-0467
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276573
|
7.2 |
HIGH
|
ecartis listar
|
ecartis listar
|
Ecartis (formerly Listar) 1.0.0 in snapshot 20020125 and earlier does not properly drop privileges when Ecartis is installed setuid-root, "lock-to-user" is not set, and ecartis is called by certain M…
|
NVD-CWE-Other
|
CVE-2002-0469
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276574
|
5.0 |
MEDIUM
|
microsoft
|
msn_messenger
|
MSN Messenger Service 3.6, and possibly other versions, uses weak authentication when exchanging messages between clients, which allows remote attackers to spoof messages from other users.
|
NVD-CWE-Other
|
CVE-2002-0472
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276575
|
5.1 |
MEDIUM
|
zeroforum
|
zeroforum
|
Cross-site scripting vulnerability in ZeroForum allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within IMG image tag.
|
NVD-CWE-Other
|
CVE-2002-0474
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276576
|
5.1 |
MEDIUM
|
phpbb_group
|
phpbb
|
Cross-site scripting vulnerability in phpBB 1.4.4 and earlier allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within an IMG image tag while editing a me…
|
NVD-CWE-Other
|
CVE-2002-0475
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276577
|
5.0 |
MEDIUM
|
macromedia
|
flash_player
|
Standalone Macromedia Flash Player 5.0 allows remote attackers to save arbitrary files and programs via a .SWF file containing the undocumented "save" FSCommand.
|
NVD-CWE-Other
|
CVE-2002-0476
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276578
|
7.2 |
HIGH
|
gravity_storm_software
|
service_pack_manager_2000
|
Gravity Storm Service Pack Manager 2000 creates a hidden share (SPM2000c$) mapped to the C drive, which may allow local users to bypass access restrictions on certain directories in the C drive, such…
|
NVD-CWE-Other
|
CVE-2002-0479
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276579
|
5.1 |
MEDIUM
|
microsoft
|
outlook
|
An interaction between Windows Media Player (WMP) and Outlook 2002 allows remote attackers to bypass Outlook security settings and execute Javascript via an IFRAME in an HTML email message that refer…
|
NVD-CWE-Other
|
CVE-2002-0481
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276580
|
5.0 |
MEDIUM
|
newlog
|
netsupport_manager
|
Directory traversal vulnerability in PCI Netsupport Manager before version 7, when running web extensions, allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP GET request.
|
NVD-CWE-Other
|
CVE-2002-0482
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276581
|
5.0 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that l…
|
NVD-CWE-Other
|
CVE-2002-0483
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276582
|
4.6 |
MEDIUM
|
workforceroi
|
xpede
|
Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by…
|
NVD-CWE-Other
|
CVE-2002-0487
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276583
|
10.0 |
HIGH
|
instant_web_mail
|
instant_web_mail
|
Instant Web Mail before 0.60 does not properly filter CR/LF sequences, which allows remote attackers to (1) execute arbitrary POP commands via the id parameter in message.php, or (2) modify certain m…
|
NVD-CWE-Other
|
CVE-2002-0490
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276584
|
10.0 |
HIGH
|
alguest
|
alguest
|
admin.php in AlGuest 1.0 guestbook checks for the existence of the admin cookie to authenticate the AlGuest administrator, which allows remote attackers to bypass the authentication and gain privileg…
|
NVD-CWE-Other
|
CVE-2002-0491
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276585
|
5.0 |
MEDIUM
|
dcscripts
|
dcshop
|
dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.
|
NVD-CWE-Other
|
CVE-2002-0492
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276586
|
7.5 |
HIGH
|
websight_directory_system
|
websight_directory_system
|
Cross-site scripting vulnerability in WebSight Directory System 0.1 allows remote attackers to execute arbitrary Javascript and gain access to the WebSight administrator via a new link submission con…
|
NVD-CWE-Other
|
CVE-2002-0494
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276587
|
7.5 |
HIGH
|
websight_directory_system
|
websight_directory_system
|
This vulnerability is addressed in the following product release:
WebSight Directory System, WebSight Directory System, 0.1.1
|
NVD-CWE-Other
|
CVE-2002-0494
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276588
|
5.0 |
MEDIUM
|
southwest
|
southwest
|
The HTTP server for SouthWest Talker server 1.0.0 allows remote attackers to cause a denial of service (server crash) via a malformed URL to port 5002.
|
NVD-CWE-Other
|
CVE-2002-0496
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276589
|
2.1 |
LOW
|
mtr
|
mtr
|
Buffer overflow in mtr 0.46 and earlier, when installed setuid root, allows local users to access a raw socket via a long MTR_OPTIONS environment variable.
|
NVD-CWE-Other
|
CVE-2002-0497
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276590
|
4.6 |
MEDIUM
|
etnus
|
totalview
|
Etnus TotalView 5.0.0-4 installs certain files with UID 5039 and GID 59, which could allow local users with that UID or GID to modify the files and gain privileges as other TotalView users.
|
NVD-CWE-Other
|
CVE-2002-0498
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276591
|
2.1 |
LOW
|
linux
|
linux_kernel
|
The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappr…
|
NVD-CWE-Other
|
CVE-2002-0499
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276592
|
7.2 |
HIGH
|
posadis
|
posadis
|
Format string vulnerability in log_print() function of Posadis DNS server before version m5pre2 allows local users and possibly remote attackers to execute arbitrary code via format strings that are …
|
NVD-CWE-Other
|
CVE-2002-0501
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276593
|
5.0 |
MEDIUM
|
citrix
|
nfuse
|
Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter.
|
NVD-CWE-Other
|
CVE-2002-0503
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276594
|
7.5 |
HIGH
|
citrix
|
nfuse
|
Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_…
|
NVD-CWE-Other
|
CVE-2002-0504
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276595
|
5.0 |
MEDIUM
|
cisco
|
call_manager
|
Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.1(3) allows remote attackers to cause a denial of service (crash and reload) vi…
|
NVD-CWE-Other
|
CVE-2002-0505
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276596
|
7.2 |
HIGH
|
redhat
|
linux
|
Buffer overflow in newt.c of newt windowing library (libnewt) 0.50.33 and earlier may allow attackers to cause a denial of service or execute arbitrary code in setuid programs that use libnewt.
|
NVD-CWE-Other
|
CVE-2002-0506
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276597
|
10.0 |
HIGH
|
wwwisis
|
wwwisis
|
wwwisis 3.45 and earlier allows remote attackers to execute arbitrary commands and read files via the parameters (1) prolog or (2) epilog.
|
NVD-CWE-Other
|
CVE-2002-0508
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276598
|
5.0 |
MEDIUM
|
oracle
|
oracle9i
|
Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a single malformed TCP packet to port 1521.
|
NVD-CWE-Other
|
CVE-2002-0509
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276599
|
5.0 |
MEDIUM
|
linux
|
linux_kernel
|
The UDP implementation in Linux 2.4.x kernels keeps the IP Identification field at 0 for all non-fragmented packets, which could allow remote attackers to determine that a target system is running Li…
|
NVD-CWE-Other
|
CVE-2002-0510
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276600
|
7.5 |
HIGH
|
nscd
|
nscd
|
The default configuration of Name Service Cache Daemon (nscd) in Caldera OpenLinux 3.1 and 3.1.1 uses cached PTR records instead of consulting the authoritative DNS server for the A record, which cou…
|
NVD-CWE-Other
|
CVE-2002-0511
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|