|
314501
|
7.5 |
HIGH
|
workforceroi
|
xpede
|
WorkforceROI Xpede 4.1 allows remote attackers to gain privileges as an Xpede administrator via a direct HTTP request to the /admin/adminproc.asp script, which does not prompt for a password.
|
NVD-CWE-Other
|
CVE-2002-0579
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314502
|
7.5 |
HIGH
|
workforceroi
|
xpede
|
WorkforceROI Xpede 4.1 allows remote attackers to obtain the database username via a request to datasource.asp, which leaks the username in a form and allows the attacker to more easily conduct brute…
|
NVD-CWE-Other
|
CVE-2002-0580
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314503
|
7.5 |
HIGH
|
workforceroi
|
xpede
|
WorkforceROI Xpede 4.1 allows remote attackers to execute arbitrary SQL commands and read, modify, or steal credentials from the database via the Qry parameter in the sprc.asp script.
|
NVD-CWE-Other
|
CVE-2002-0581
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314504
|
5.0 |
MEDIUM
|
workforceroi
|
xpede
|
WorkforceROI Xpede 4.1 stores temporary expense claim reports in a world-readable and indexable /reports/temp directory, which allows remote attackers to read the reports by accessing the directory.
|
NVD-CWE-Other
|
CVE-2002-0582
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314505
|
5.0 |
MEDIUM
|
workforceroi
|
xpede
|
WorkforceROI Xpede 4.1 uses a small random namespace (5 alphanumeric characters) for temporary expense claim reports in the /reports/temp directory, which allows remote attackers to read the reports …
|
NVD-CWE-Other
|
CVE-2002-0583
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314506
|
5.0 |
MEDIUM
|
workforceroi
|
xpede
|
WorkforceROI Xpede 4.1 allows remote attackers to read user timesheets by modifying the TSN ID parameter to the ts_app_process.asp script, which is easily guessable because it is incremented by 1 for…
|
NVD-CWE-Other
|
CVE-2002-0584
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314507
|
7.5 |
HIGH
|
aol
|
aol_server
|
Format string vulnerability in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to execute arbitrary code via…
|
NVD-CWE-Other
|
CVE-2002-0586
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314508
|
7.5 |
HIGH
|
aol
|
aol_server
|
Buffer overflow in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to cause a denial of service or execute a…
|
NVD-CWE-Other
|
CVE-2002-0587
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314509
|
5.0 |
MEDIUM
|
steve_korbett
|
pvote
|
PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.
|
NVD-CWE-Other
|
CVE-2002-0588
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314510
|
7.5 |
HIGH
|
steve_korbett
|
pvote
|
PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with the newpass and confirm parameters both set to the new password.
|
NVD-CWE-Other
|
CVE-2002-0589
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314511
|
7.5 |
HIGH
|
icredibb
|
icredibb
|
Cross-site scripting (CSS) vulnerability in IcrediBB 1.1 Beta allows remote attackers to execute arbitrary script and steal cookies as other IcrediBB users via the (1) title or (2) body of posts.
|
NVD-CWE-Other
|
CVE-2002-0590
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314512
|
5.0 |
MEDIUM
|
aol
|
instant_messenger
|
Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute commands via a Direct Connection with an IMG tag wi…
|
NVD-CWE-Other
|
CVE-2002-0591
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314513
|
7.5 |
HIGH
|
mozilla netscape
|
mozilla communicator navigator
|
Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI.
|
NVD-CWE-Other
|
CVE-2002-0593
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314514
|
5.0 |
MEDIUM
|
galeon mozilla netscape
|
galeon_browser mozilla navigator
|
Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTT…
|
NVD-CWE-Other
|
CVE-2002-0594
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314515
|
7.5 |
HIGH
|
webtrends
|
reporting_center
|
Buffer overflow in WTRS_UI.EXE (WTX_REMOTE.DLL) for WebTrends Reporting Center 4.0d allows remote attackers to execute arbitrary code via a long HTTP GET request to the /reports/ directory.
|
NVD-CWE-Other
|
CVE-2002-0595
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314516
|
7.5 |
HIGH
|
foundstone
|
fscan
|
Format string vulnerability in Foundstone FScan 1.12 with banner grabbing enabled allows remote attackers to execute arbitrary code on the scanning system via format string specifiers in the server b…
|
NVD-CWE-Other
|
CVE-2002-0598
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314517
|
10.0 |
HIGH
|
blahz-dns
|
blahz-dns
|
Blahz-DNS 0.2 and earlier allows remote attackers to bypass authentication and modify configuration by directly requesting CGI programs such as dostuff.php instead of going through the login screen.
|
NVD-CWE-Other
|
CVE-2002-0599
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314518
|
5.0 |
MEDIUM
|
information_security_systems
|
realsecure_network_sensor
|
ISS RealSecure Network Sensor 5.x through 6.5 allows remote attackers to cause a denial of service (crash) via malformed DHCP packets that cause RealSecure to dereference a null pointer.
|
NVD-CWE-Other
|
CVE-2002-0601
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314519
|
7.5 |
HIGH
|
3com
|
3cdaemon
|
Buffer overflow in 3Cdaemon 2.0 FTP server allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long commands such as login.
|
NVD-CWE-Other
|
CVE-2002-0606
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314520
|
7.5 |
HIGH
|
snitz_communications
|
snitz_forums_2000
|
members.asp in Snitz Forums 2000 version 3.3.03 and earlier allows remote attackers to execute arbitrary code via a SQL injection attack on the parameters (1) M_NAME, (2) UserName, (3) FirstName, (4)…
|
NVD-CWE-Other
|
CVE-2002-0607
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314521
|
7.5 |
HIGH
|
matu
|
matu_ftp
|
Buffer overflow in Matu FTP client 1.74 allows remote FTP servers to execute arbitrary code via a long "220" banner.
|
NVD-CWE-Other
|
CVE-2002-0608
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314522
|
5.0 |
MEDIUM
|
hp
|
mpe_ix
|
Vulnerability in HP MPE/iX 6.0 through 7.0 allows attackers to cause a denial of service (system failure with "SA1457 out of i_port_timeout.fix_up_message_frame") via malformed IP packets.
|
NVD-CWE-Other
|
CVE-2002-0609
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314523
|
7.5 |
HIGH
|
hp
|
mpe_ix
|
Vulnerability in FTPSRVR in HP MPE/iX 6.0 through 7.0 does not properly validate certain FTP commands, which allows attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-0610
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314524
|
5.0 |
MEDIUM
|
craig_patchett
|
fileseek
|
Directory traversal vulnerability in FileSeek.cgi allows remote attackers to read arbitrary files via a ....// (modified dot dot) in the (1) head or (2) foot parameters, which are not properly filter…
|
NVD-CWE-Other
|
CVE-2002-0611
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314525
|
7.5 |
HIGH
|
craig_patchett
|
fileseek
|
FileSeek.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) head or (2) foot parameters.
|
NVD-CWE-Other
|
CVE-2002-0612
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314526
|
10.0 |
HIGH
|
dnstools_software
|
dnstools
|
dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user_logged_in or user_dnstools_administrator parameters.
|
NVD-CWE-Other
|
CVE-2002-0613
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314527
|
5.0 |
MEDIUM
|
php-survey
|
php-survey
|
PHP-Survey 20000615 and earlier stores the global.inc file under the web root, which allows remote attackers to obtain sensitive information, including database credentials, if .inc files are not pre…
|
NVD-CWE-Other
|
CVE-2002-0614
|
2008-09-6 05:28 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314528
|
7.5 |
HIGH
|
trend_micro
|
interscan_viruswall
|
InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unex…
|
NVD-CWE-Other
|
CVE-2002-0637
|
2008-09-6 05:28 |
2002-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314529
|
5.0 |
MEDIUM
|
pingtel
|
xpressa
|
The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows administrators to cause a denial of service by modifying the SIP_AUTHENTICATE_SCHEME value to force au…
|
NVD-CWE-Other
|
CVE-2002-0669
|
2008-09-6 05:28 |
2003-02-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314530
|
7.5 |
HIGH
|
pingtel
|
xpressa
|
The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to s…
|
NVD-CWE-Other
|
CVE-2002-0670
|
2008-09-6 05:28 |
2002-07-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314531
|
4.6 |
MEDIUM
|
pingtel
|
xpressa
|
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to restore the phone to factory defaults without authentication via a menu option, which sets…
|
NVD-CWE-Other
|
CVE-2002-0672
|
2008-09-6 05:28 |
2002-07-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314532
|
4.6 |
MEDIUM
|
pingtel
|
xpressa
|
The enrollment process for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to the phone to log out the current user and re-register the phone…
|
NVD-CWE-Other
|
CVE-2002-0673
|
2008-09-6 05:28 |
2002-07-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314533
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via t…
|
NVD-CWE-Other
|
CVE-2002-0676
|
2008-09-6 05:28 |
2002-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314534
|
5.0 |
MEDIUM
|
zope
|
zope
|
The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers.
|
NVD-CWE-Other
|
CVE-2002-0687
|
2008-09-6 05:28 |
2002-07-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314535
|
7.5 |
HIGH
|
zope
|
zope
|
ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes.
|
NVD-CWE-Other
|
CVE-2002-0688
|
2008-09-6 05:28 |
2002-07-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314536
|
7.5 |
HIGH
|
gisle_aas
|
digest-md5
|
An interaction between the Perl MD5 module (perl-Digest-MD5) and Perl could produce incorrect MD5 checksums for UTF-8 data, which could prevent a system from properly verifying the integrity of the d…
|
NVD-CWE-Other
|
CVE-2002-0703
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314537
|
5.0 |
MEDIUM
|
greg_roelofs
|
libpng
|
Buffer overflow in the progressive reader for libpng 1.2.x before 1.2.4, and 1.0.x before 1.0.14, allows attackers to cause a denial of service (crash) via a PNG data stream that has more IDAT data t…
|
NVD-CWE-Other
|
CVE-2002-0728
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314538
|
7.5 |
HIGH
|
philip_chinery
|
philip_chinerys_guestbook
|
Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields such as (1) Name, (2) EMail, or (3) Homepage.
|
NVD-CWE-Other
|
CVE-2002-0730
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314539
|
7.5 |
HIGH
|
vqsoft
|
vqserver
|
Cross-site scripting vulnerability in demonstration scripts for vqServer allows remote attackers to execute arbitrary script via a link that contains the script in arguments to demo scripts such as r…
|
NVD-CWE-Other
|
CVE-2002-0731
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314540
|
7.5 |
HIGH
|
acme_labs
|
thttpd
|
Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 …
|
NVD-CWE-Other
|
CVE-2002-0733
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314541
|
7.5 |
HIGH
|
michel_valdrighi
|
b2
|
b2edit.showposts.php in B2 2.0.6pre2 and earlier does not properly load the b2config.php file in some configurations, which allows remote attackers to execute arbitrary PHP code via a URL that sets t…
|
NVD-CWE-Other
|
CVE-2002-0734
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314542
|
10.0 |
HIGH
|
microsoft
|
backoffice
|
Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with …
|
NVD-CWE-Other
|
CVE-2002-0736
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314543
|
6.4 |
MEDIUM
|
sambar
|
sambar_server
|
Sambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scripts, or cause a denial of service (resource exhaustion) via DOS devices, using a URL that ends wit…
|
NVD-CWE-Other
|
CVE-2002-0737
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314544
|
7.5 |
HIGH
|
mhonarc
|
mhonarc
|
MHonArc 2.5.2 and earlier does not properly filter Javascript from archived e-mail messages, which could allow remote attackers to execute script in web clients by (1) splitting the SCRIPT tag into s…
|
NVD-CWE-Other
|
CVE-2002-0738
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314545
|
7.5 |
HIGH
|
postnuke_software_foundation
|
postcalendar
|
Cross-site scripting in PostCalendar 3.02 allows remote attackers to insert arbitrary HTML and script, and steal cookies, by modifying a calendar entry in its preview page.
|
NVD-CWE-Other
|
CVE-2002-0739
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314546
|
7.2 |
HIGH
|
slrn_development_team
|
slrn
|
Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges via a long -d (SPOOLDIR) argument.
|
NVD-CWE-Other
|
CVE-2002-0740
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314547
|
5.0 |
MEDIUM
|
psychoid
|
psybnc
|
psyBNC 2.3 allows remote attackers to cause a denial of service (CPU consumption and resource exhaustion) by sending a PASS command with a long password argument and quickly killing the connection, w…
|
NVD-CWE-Other
|
CVE-2002-0741
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314548
|
10.0 |
HIGH
|
ibm
|
aix
|
Buffer overflow in pioout on AIX 4.3.3.
|
NVD-CWE-Other
|
CVE-2002-0742
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314549
|
10.0 |
HIGH
|
ibm
|
aix
|
mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow.
|
NVD-CWE-Other
|
CVE-2002-0743
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314550
|
10.0 |
HIGH
|
ibm
|
aix
|
namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow.
|
NVD-CWE-Other
|
CVE-2002-0744
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|