|
363101
|
7.5 |
HIGH
|
avengers_news_system
|
avengers_news_system
|
Directory traversal vulnerability in ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to determine the existence of arbitrary files or execute any Perl program on the sy…
|
NVD-CWE-Other
|
CVE-2002-0307
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363102
|
5.0 |
MEDIUM
|
symantec
|
enterprise_firewall
|
SMTP proxy in Symantec Enterprise Firewall (SEF) 6.5.x includes the firewall's physical interface name and address in an SMTP protocol exchange when NAT translation is made to an address other than t…
|
NVD-CWE-Other
|
CVE-2002-0309
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363103
|
5.0 |
MEDIUM
|
essen
|
essentia_web_server
|
Directory traversal vulnerability in Essentia Web Server 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.
|
NVD-CWE-Other
|
CVE-2002-0312
|
2016-10-18 11:18 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363104
|
7.5 |
HIGH
|
essen
|
essentia_web_server
|
Buffer overflow in Essentia Web Server 2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long URL.
|
NVD-CWE-Other
|
CVE-2002-0313
|
2016-10-18 11:18 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363105
|
5.0 |
MEDIUM
|
fasttrack grokster music_city_networks
|
kazaa grokster morpheus
|
fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, whic…
|
NVD-CWE-Other
|
CVE-2002-0314
|
2016-10-18 11:18 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363106
|
7.5 |
HIGH
|
fasttrack grokster music_city_networks
|
kazaa grokster morpheus
|
fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header.
|
NVD-CWE-Other
|
CVE-2002-0315
|
2016-10-18 11:18 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363107
|
7.5 |
HIGH
|
nullsoft
|
shoutcast_server
|
Buffer overflow in admin.cgi for Nullsoft Shoutcast Server 1.8.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an argument with a large number of backsl…
|
NVD-CWE-Other
|
CVE-2002-0199
|
2016-10-18 11:17 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363108
|
5.0 |
MEDIUM
|
cyberstop
|
cyberstop_web_server
|
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service via an HTTP request for an MS-DOS device name.
|
NVD-CWE-Other
|
CVE-2002-0200
|
2016-10-18 11:17 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363109
|
5.0 |
MEDIUM
|
cyberstop
|
cyberstop_web_server
|
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflo…
|
NVD-CWE-Other
|
CVE-2002-0201
|
2016-10-18 11:17 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363110
|
7.5 |
HIGH
|
gnu
|
chess
|
Buffer overflow in GNU Chess (gnuchess) 5.02 and earlier, if modified or used in a networked capacity contrary to its own design as a single-user application, may allow local or remote attackers to e…
|
NVD-CWE-Other
|
CVE-2002-0204
|
2016-10-18 11:17 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363111
|
7.5 |
HIGH
|
plumtree
|
plumtree_corporate_portal
|
Cross-site scripting (CSS) vulnerability in error.asp for Plumtree Corporate Portal 3.5 through 4.5 allows remote attackers to execute arbitrary script on other clients via the "Description" paramete…
|
NVD-CWE-Other
|
CVE-2002-0205
|
2016-10-18 11:17 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363112
|
7.5 |
HIGH
|
hosting_controller
|
hosting_controller
|
The login for Hosting Controller 1.1 through 1.4.1 returns different error messages when a valid or invalid user is provided, which allows remote attackers to determine the existence of valid usernam…
|
NVD-CWE-Other
|
CVE-2002-0212
|
2016-10-18 11:17 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363113
|
2.1 |
LOW
|
xinet sgi
|
k-ashare irix
|
xkas in Xinet K-AShare 0.011.01 for IRIX allows local users to read arbitrary files via a symlink attack on the VOLICON file, which is copied to the .HSicon file in a shared directory.
|
NVD-CWE-Other
|
CVE-2002-0213
|
2016-10-18 11:17 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363114
|
7.5 |
HIGH
|
dcscripts
|
dcforum
|
retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to request a new password on behalf of another user and use the se…
|
NVD-CWE-Other
|
CVE-2002-0226
|
2016-10-18 11:17 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363115
|
5.0 |
MEDIUM
|
kicq kde
|
kicq kde
|
KICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message.
|
NVD-CWE-Other
|
CVE-2002-0227
|
2016-10-18 11:17 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363116
|
7.5 |
HIGH
|
php
|
php
|
Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCA…
|
NVD-CWE-Other
|
CVE-2002-0229
|
2016-10-18 11:17 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363117
|
5.0 |
MEDIUM
|
faq-o-matic
|
faq-o-matic
|
Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cmd parameter, which causes the script to be insert…
|
NVD-CWE-Other
|
CVE-2002-0230
|
2016-10-18 11:17 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363118
|
7.5 |
HIGH
|
khaled_mardam-bey
|
mirc
|
Buffer overflow in mIRC 5.91 and earlier allows a remote server to execute arbitrary code on the client via a long nickname.
|
NVD-CWE-Other
|
CVE-2002-0231
|
2016-10-18 11:17 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363119
|
5.0 |
MEDIUM
|
mrtg
|
multi_router_traffic_grapher_cgi
|
Directory traversal vulnerability in Multi Router Traffic Grapher (MRTG) allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the cfg parameter for (1) 14all.cgi, (2) 14a…
|
NVD-CWE-Other
|
CVE-2002-0232
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363120
|
5.0 |
MEDIUM
|
eshare_communications_inc.
|
eshare_expressions
|
Directory traversal vulnerability in eshare Expressions 4 Web server allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.
|
NVD-CWE-Other
|
CVE-2002-0233
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363121
|
2.1 |
LOW
|
juniper
|
netscreen_screenos
|
NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustio…
|
NVD-CWE-Other
|
CVE-2002-0234
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363122
|
7.5 |
HIGH
|
lucent
|
vitalanalysis vitalevent vitalhelp vitalnet vitalsuite
|
Lucent VitalSuite 8.0 through 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis, allows remote attackers to bypass authentication via a direct HTTP request to the VsSetCookie.exe progr…
|
NVD-CWE-Other
|
CVE-2002-0236
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363123
|
7.5 |
HIGH
|
iss
|
blackice_agent blackice_defender realsecure_server_sensor
|
Buffer overflow in ISS BlackICE Defender 2.9 and earlier, BlackICE Agent 3.0 and 3.1, and RealSecure Server Sensor 6.0.1 and 6.5 allow remote attackers to cause a denial of service (crash) and possib…
|
NVD-CWE-Other
|
CVE-2002-0237
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363124
|
7.5 |
HIGH
|
netgear
|
rt314
|
Cross-site scripting vulnerability in web administration interface for NetGear RT314 and RT311 Gateway Routers allows remote attackers to execute arbitrary script on another client via a URL that con…
|
NVD-CWE-Other
|
CVE-2002-0238
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363125
|
7.2 |
HIGH
|
hanterm
|
hanterm
|
Buffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -fn, (2) -hfb, or (3) -hfn argument.
|
NVD-CWE-Other
|
CVE-2002-0239
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363126
|
5.0 |
MEDIUM
|
apache
|
http_server
|
PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reve…
|
NVD-CWE-Other
|
CVE-2002-0240
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363127
|
7.5 |
HIGH
|
opera_software
|
opera_web_browser
|
Cross-site scripting vulnerability in Opera 6.0 and earlier allows remote attackers to execute arbitrary script via an Extended HTML Form, whose output from the remote server is not properly cleansed.
|
NVD-CWE-Other
|
CVE-2002-0243
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363128
|
7.5 |
HIGH
|
lotus
|
domino
|
Lotus Domino server 5.0.8 with NoBanner enabled allows remote attackers to (1) determine the physical path of the server via a request for a nonexistent file with a .pl (Perl) extension, which leaks …
|
NVD-CWE-Other
|
CVE-2002-0245
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363129
|
5.0 |
MEDIUM
|
apache
|
http_server
|
PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /12…
|
NVD-CWE-Other
|
CVE-2002-0249
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363130
|
7.5 |
HIGH
|
hp
|
advancestack_10base-t_switching_hub_j3200a advancestack_10base-t_switching_hub_j3201a advancestack_10base-t_switching_hub_j3202a advancestack_10base-t_switching_hub_j3203a advancestack_10…
|
Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allows unauthorized users to bypass authentication via a direct HTTP request to the …
|
NVD-CWE-Other
|
CVE-2002-0250
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363131
|
7.5 |
HIGH
|
licq
|
licq
|
Buffer overflow in licq 1.0.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string of format string characters such as "%d".
|
NVD-CWE-Other
|
CVE-2002-0251
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363132
|
5.0 |
MEDIUM
|
php
|
php
|
PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote attackers to obtain the physical path for an include file via a trailing slash in a request to a directly ac…
|
NVD-CWE-Other
|
CVE-2002-0253
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363133
|
5.0 |
MEDIUM
|
mirabilis
|
icq
|
ICQ 2001b Build 3659 allows remote attackers to cause a denial of service (crash) via a malformed picture that contains large height and width values, which causes the crash when viewed in Userdetail…
|
NVD-CWE-Other
|
CVE-2002-0254
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363134
|
10.0 |
HIGH
|
arescom
|
netdsl
|
The default configuration of Arescom NetDSL 800 does not require authentication, which allows remote attackers to cause a denial of service or reconfigure the router.
|
NVD-CWE-Other
|
CVE-2002-0255
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363135
|
5.0 |
MEDIUM
|
arescom
|
netdsl
|
The telnet port in Arescom NetDSL 1000 router allows remote attackers to cause a denial of service via a series of connections with long strings, which causes a large number of login failures and cau…
|
NVD-CWE-Other
|
CVE-2002-0256
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363136
|
7.5 |
HIGH
|
apache usanet_creations
|
http_server makebid_auction_deluxe
|
Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4…
|
NVD-CWE-Other
|
CVE-2002-0257
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363137
|
7.5 |
HIGH
|
icewarp merak
|
web_mail mail_server
|
Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access to the ID to gain privileges as that use…
|
NVD-CWE-Other
|
CVE-2002-0258
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363138
|
4.6 |
MEDIUM
|
instantservers_inc.
|
miniportal
|
InstantServers MiniPortal 1.1.5 and earlier stores sensitive login and account data in plaintext in (1) .pwd files in the miniportal/apache directory, or (2) mplog.txt, which could allow local users …
|
NVD-CWE-Other
|
CVE-2002-0259
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363139
|
7.5 |
HIGH
|
instantservers_inc.
|
miniportal
|
Buffer overflow in InstantServers MiniPortal 1.1.5 and earlier allows remote attackers to execute arbitrary code via a long login name, which is not properly handled by the logging utility.
|
NVD-CWE-Other
|
CVE-2002-0260
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363140
|
7.5 |
HIGH
|
instantservers_inc.
|
miniportal
|
Directory traversal vulnerability in InstantServers MiniPortal 1.1.5 and earlier allows remote authenticated users to read arbitrary files via a ... (modified dot dot) in the GET command.
|
NVD-CWE-Other
|
CVE-2002-0261
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363141
|
5.0 |
MEDIUM
|
sybex
|
e-trainer
|
Directory traversal vulnerability in netget for Sybex E-Trainer web server allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
|
NVD-CWE-Other
|
CVE-2002-0262
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363142
|
7.5 |
HIGH
|
ezne.net
|
ezboard_2000
|
Buffer overflow in EasyBoard 2000 1.27 (aka EZboard) allows remote attackers to execute arbitrary code via a long boundary value in a multipart Content-Type header to (1) ezboard.cgi, (2) ezman.cgi, …
|
NVD-CWE-Other
|
CVE-2002-0263
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363143
|
7.5 |
HIGH
|
cooolsoft
|
powerftp
|
PowerFTP Personal FTP Server 2.03 through 2.10 stores sensitive account information in plaintext in the ftpserver.ini file, which allows attackers with access to the file to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-0264
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363144
|
4.6 |
MEDIUM
|
sawmill
|
sawmill
|
Sawmill for Solaris 6.2.14 and earlier creates the AdminPassword file with world-writable permissions, which allows local users to gain privileges by modifying the file.
|
NVD-CWE-Other
|
CVE-2002-0265
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363145
|
5.0 |
MEDIUM
|
thunderstone_software
|
texis
|
Thunderstone Texis CGI script allows remote attackers to obtain the full path of the web root via a request for a nonexistent file, which generates an error message that includes the full pathname.
|
NVD-CWE-Other
|
CVE-2002-0266
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363146
|
10.0 |
HIGH
|
sips
|
sips
|
preferences.php in Simple Internet Publishing System (SIPS) before 0.3.1 allows remote attackers to gain administrative privileges via a linebreak in the "theme" field followed by the Status::admin c…
|
NVD-CWE-Other
|
CVE-2002-0267
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363147
|
7.2 |
HIGH
|
identix
|
biologon
|
Identix BioLogon 3 allows users with physical access to the system to gain administrative privileges by using CTRL-ALT-DEL and running a "Browse" function, which runs Explorer with SYSTEM privileges.
|
NVD-CWE-Other
|
CVE-2002-0268
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363148
|
7.5 |
HIGH
|
apache-ssl mod_ssl
|
apache-ssl mod_ssl
|
The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attac…
|
NVD-CWE-Other
|
CVE-2002-0082
|
2016-10-18 11:16 |
2002-03-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363149
|
5.0 |
MEDIUM
|
cvs
|
cvs
|
CVS before 1.10.8 does not properly initialize a global variable, which allows remote attackers to cause a denial of service (server crash) via the diff capability.
|
NVD-CWE-Other
|
CVE-2002-0092
|
2016-10-18 11:16 |
2002-03-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363150
|
7.5 |
HIGH
|
boozt
|
boozt_standard
|
Buffer overflow in index.cgi administration interface for Boozt! Standard 0.9.8 allows local users to execute arbitrary code via a long name field when creating a new banner.
|
NVD-CWE-Other
|
CVE-2002-0098
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|