|
358951
|
7.5 |
HIGH
|
philip_chinery
|
philip_chinerys_guestbook
|
Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields such as (1) Name, (2) EMail, or (3) Homepage.
|
NVD-CWE-Other
|
CVE-2002-0730
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358952
|
7.5 |
HIGH
|
vqsoft
|
vqserver
|
Cross-site scripting vulnerability in demonstration scripts for vqServer allows remote attackers to execute arbitrary script via a link that contains the script in arguments to demo scripts such as r…
|
NVD-CWE-Other
|
CVE-2002-0731
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358953
|
7.5 |
HIGH
|
acme_labs
|
thttpd
|
Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 …
|
NVD-CWE-Other
|
CVE-2002-0733
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358954
|
7.5 |
HIGH
|
michel_valdrighi
|
b2
|
b2edit.showposts.php in B2 2.0.6pre2 and earlier does not properly load the b2config.php file in some configurations, which allows remote attackers to execute arbitrary PHP code via a URL that sets t…
|
NVD-CWE-Other
|
CVE-2002-0734
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358955
|
10.0 |
HIGH
|
microsoft
|
backoffice
|
Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with …
|
NVD-CWE-Other
|
CVE-2002-0736
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358956
|
6.4 |
MEDIUM
|
sambar
|
sambar_server
|
Sambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scripts, or cause a denial of service (resource exhaustion) via DOS devices, using a URL that ends wit…
|
NVD-CWE-Other
|
CVE-2002-0737
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358957
|
7.5 |
HIGH
|
mhonarc
|
mhonarc
|
MHonArc 2.5.2 and earlier does not properly filter Javascript from archived e-mail messages, which could allow remote attackers to execute script in web clients by (1) splitting the SCRIPT tag into s…
|
NVD-CWE-Other
|
CVE-2002-0738
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358958
|
7.5 |
HIGH
|
postnuke_software_foundation
|
postcalendar
|
Cross-site scripting in PostCalendar 3.02 allows remote attackers to insert arbitrary HTML and script, and steal cookies, by modifying a calendar entry in its preview page.
|
NVD-CWE-Other
|
CVE-2002-0739
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358959
|
7.2 |
HIGH
|
slrn_development_team
|
slrn
|
Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges via a long -d (SPOOLDIR) argument.
|
NVD-CWE-Other
|
CVE-2002-0740
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358960
|
5.0 |
MEDIUM
|
psychoid
|
psybnc
|
psyBNC 2.3 allows remote attackers to cause a denial of service (CPU consumption and resource exhaustion) by sending a PASS command with a long password argument and quickly killing the connection, w…
|
NVD-CWE-Other
|
CVE-2002-0741
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358961
|
10.0 |
HIGH
|
ibm
|
aix
|
Buffer overflow in pioout on AIX 4.3.3.
|
NVD-CWE-Other
|
CVE-2002-0742
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358962
|
10.0 |
HIGH
|
ibm
|
aix
|
mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow.
|
NVD-CWE-Other
|
CVE-2002-0743
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358963
|
10.0 |
HIGH
|
ibm
|
aix
|
namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow.
|
NVD-CWE-Other
|
CVE-2002-0744
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358964
|
10.0 |
HIGH
|
ibm
|
aix
|
Buffer overflow in uucp in AIX 4.3.3.
|
NVD-CWE-Other
|
CVE-2002-0745
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358965
|
10.0 |
HIGH
|
ibm
|
aix
|
Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument.
|
NVD-CWE-Other
|
CVE-2002-0746
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358966
|
10.0 |
HIGH
|
ibm
|
aix
|
Buffer overflow in lsmcode in AIX 4.3.3.
|
NVD-CWE-Other
|
CVE-2002-0747
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358967
|
5.0 |
MEDIUM
|
national_instruments
|
labview
|
LabVIEW Web Server 5.1.1 through 6.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request that ends in two newline characters, instead of the expected carriage return/…
|
NVD-CWE-Other
|
CVE-2002-0748
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358968
|
7.5 |
HIGH
|
cgiscript.net
|
csmailto
|
CGIscript.net csMailto.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the form-attachment field.
|
NVD-CWE-Other
|
CVE-2002-0749
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358969
|
5.0 |
MEDIUM
|
cgiscript.net
|
csmailto
|
CGIscript.net csMailto.cgi program allows remote attackers to read arbitrary files by specifying the target filename in the form-attachment field.
|
NVD-CWE-Other
|
CVE-2002-0750
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358970
|
7.5 |
HIGH
|
cgiscript.net
|
csmailto
|
CGIscript.net csMailto.cgi program allows remote attackers to use csMailto as a "spam proxy" and send mail to arbitrary users via modified (1) form-to, (2) form-from, and (3) form-results parameters.
|
NVD-CWE-Other
|
CVE-2002-0751
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358971
|
5.0 |
MEDIUM
|
cgiscript.net
|
csmailto
|
CGIscript.net csMailto.cgi program exports feedback to a file that is accessible from the web document root, which could allow remote attackers to obtain sensitive information by directly accessing t…
|
NVD-CWE-Other
|
CVE-2002-0752
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358972
|
10.0 |
HIGH
|
talentsoft
|
web\+_server
|
Buffer overflow in Talentsoft Web+ 5.0 allows remote attackers to execute arbitrary code via an HTTP request with a long cookie.
|
NVD-CWE-Other
|
CVE-2002-0753
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358973
|
7.2 |
HIGH
|
freebsd kth
|
heimdal freebsd
|
Kerberos 5 su (k5su) in FreeBSD 4.4 and earlier relies on the getlogin system call to determine if the user running k5su is root, which could allow a root-initiated process to regain its privileges a…
|
NVD-CWE-Other
|
CVE-2002-0754
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358974
|
7.2 |
HIGH
|
freebsd
|
freebsd
|
Kerberos 5 su (k5su) in FreeBSD 4.5 and earlier does not verify that a user is a member of the wheel group before granting superuser privileges, which could allow unauthorized users to execute comman…
|
NVD-CWE-Other
|
CVE-2002-0755
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358975
|
7.5 |
HIGH
|
usermin webmin
|
usermin webmin
|
Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert script into an error page and possibly steal cookies.
|
NVD-CWE-Other
|
CVE-2002-0756
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358976
|
7.5 |
HIGH
|
usermin webmin
|
usermin webmin
|
(1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and gain privileges via certain control characters in the authen…
|
NVD-CWE-Other
|
CVE-2002-0757
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358977
|
5.0 |
MEDIUM
|
bzip
|
bzip2
|
bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, does not use the O_EXCL flag to create files during decompression and does not warn the u…
|
NVD-CWE-Other
|
CVE-2002-0759
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358978
|
1.2 |
LOW
|
bzip
|
bzip2
|
Race condition in bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, decompresses files with world-readable permissions before setting the p…
|
NVD-CWE-Other
|
CVE-2002-0760
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358979
|
2.1 |
LOW
|
bzip
|
bzip2
|
bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links instead of the actual files when creating an archive, which could …
|
NVD-CWE-Other
|
CVE-2002-0761
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358980
|
7.5 |
HIGH
|
hp
|
virtualvault
|
Vulnerability in administration server for HP VirtualVault 4.5 on HP-UX 11.04 allows remote web servers or privileged external processes to bypass access restrictions and establish connections to the…
|
NVD-CWE-Other
|
CVE-2002-0763
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358981
|
7.5 |
HIGH
|
phorum
|
phorum
|
Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php that modifies the PHORUM[settings_dir] variable to point to a …
|
NVD-CWE-Other
|
CVE-2002-0764
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358982
|
7.2 |
HIGH
|
richard_gooch
|
simpleinit
|
simpleinit on Linux systems does not close a read/write FIFO file descriptor before creating a child process, which allows the child process to cause simpleinit to execute arbitrary programs with roo…
|
NVD-CWE-Other
|
CVE-2002-0767
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358983
|
7.5 |
HIGH
|
luke_mewburn suse
|
lukemftp suse_linux
|
Buffer overflow in lukemftp FTP client in SuSE 6.4 through 8.0, and possibly other operating systems, allows a malicious FTP server to execute arbitrary code via a long PASV command.
|
NVD-CWE-Other
|
CVE-2002-0768
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358984
|
6.4 |
MEDIUM
|
cisco
|
ata-186
|
The web-based configuration interface for the Cisco ATA 186 Analog Telephone Adaptor allows remote attackers to bypass authentication via an HTTP POST request with a single byte, which allows the att…
|
NVD-CWE-Other
|
CVE-2002-0769
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358985
|
5.0 |
MEDIUM
|
id_software
|
quake_2i_server
|
Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server admin commands via a client that does not expand …
|
NVD-CWE-Other
|
CVE-2002-0770
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358986
|
6.4 |
MEDIUM
|
hosting_controller
|
hosting_controller
|
Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories via a .. (dot dot) in the RootName parameter.
|
NVD-CWE-Other
|
CVE-2002-0772
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358987
|
10.0 |
HIGH
|
hosting_controller
|
hosting_controller
|
imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imp_rootdir.asp and modifying parameters such as (1) ftp, (2) …
|
NVD-CWE-Other
|
CVE-2002-0773
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358988
|
10.0 |
HIGH
|
hosting_controller
|
hosting_controller
|
Hosting Controller creates a default user AdvWebadmin with a default password, which could allow remote attackers to gain privileges if the password is not changed.
|
NVD-CWE-Other
|
CVE-2002-0774
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358989
|
5.0 |
MEDIUM
|
hosting_controller
|
hosting_controller
|
browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter.
|
NVD-CWE-Other
|
CVE-2002-0775
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358990
|
7.5 |
HIGH
|
hosting_controller
|
hosting_controller
|
getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the username parameter, as addressed by the "UpdateUser"…
|
NVD-CWE-Other
|
CVE-2002-0776
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358991
|
10.0 |
HIGH
|
ipswitch
|
imail
|
Buffer overflow in the LDAP component of Ipswitch IMail 7.1 and earlier allows remote attackers to execute arbitrary code via a long "bind DN" parameter.
|
NVD-CWE-Other
|
CVE-2002-0777
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358992
|
5.0 |
MEDIUM
|
novell
|
bordermanager
|
FTP proxy server for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service (network connectivity loss) via a connection to port 21 with a large amount of random data.
|
NVD-CWE-Other
|
CVE-2002-0779
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358993
|
5.0 |
MEDIUM
|
novell
|
bordermanager
|
IP/IPX gateway for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a connection to port 8225 with a large amount of random data, which causes ipipxgw.nlm to AB…
|
NVD-CWE-Other
|
CVE-2002-0780
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358994
|
5.0 |
MEDIUM
|
novell
|
bordermanager
|
RTSP proxy for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a GET request to port 9090 followed by a series of carriage returns, which causes proxy.nlm to A…
|
NVD-CWE-Other
|
CVE-2002-0781
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358995
|
5.0 |
MEDIUM
|
novell
|
bordermanager
|
Novell BorderManager 3.5 with PAT (Port-Address Translate) enabled allows remote attackers to cause a denial of service by filling the connection table with a large number of connection requests to h…
|
NVD-CWE-Other
|
CVE-2002-0782
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358996
|
7.5 |
HIGH
|
opera_software
|
opera_web_browser
|
Opera 6.01, 6.0, and 5.12 allows remote attackers to execute arbitrary JavaScript in the security context of other sites by setting the location of a frame or iframe to a Javascript: URL.
|
NVD-CWE-Other
|
CVE-2002-0783
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358997
|
5.0 |
MEDIUM
|
lysias
|
lidik_webserver
|
Directory traversal vulnerability in Lysias Lidik web server 0.7b allows remote attackers to list directories via an HTTP request with a ... (modified dot dot).
|
NVD-CWE-Other
|
CVE-2002-0784
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358998
|
5.0 |
MEDIUM
|
aol
|
instant_messenger
|
AOL Instant Messenger (AIM) allows remote attackers to cause a denial of service (crash) via an "AddBuddy" link with the ScreenName parameter set to a large number of comma-separated values, possibly…
|
NVD-CWE-Other
|
CVE-2002-0785
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358999
|
5.0 |
MEDIUM
|
critical_path
|
injoin_directory_server
|
iCon administrative web server for Critical Path inJoin Directory Server 4.0 allows authenticated inJoin administrators to read arbitrary files by specifying the target file in the LOG parameter.
|
NVD-CWE-Other
|
CVE-2002-0786
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
359000
|
7.5 |
HIGH
|
critical_path
|
injoin_directory_server
|
Cross-site scripting vulnerabilities in iCon administrative web server for Critical Path inJoin Directory Server 4.0 allow remote attackers to execute script as the administrator via administrator UR…
|
NVD-CWE-Other
|
CVE-2002-0787
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|