Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 316 770

Количество 316 770

nvd логотип

CVE-2001-1527

почти 24 года назад

easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtain the passwords and gain access.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1526

почти 24 года назад

Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the zeit parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2001-1525

почти 24 года назад

Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.dat and possibly other files via a ".." in the cid parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1524

почти 24 года назад

Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) uname parameter in user.php, (2) ttitle, letter and file parameters in modules.php, (3) subject, story and storyext parameters in submit.php, (4) upload parameter in admin.php and (5) fname parameter in friend.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2001-1523

почти 24 года назад

Cross-site scripting (XSS) vulnerability in the DMOZGateway module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the topic parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2001-1522

почти 24 года назад

Cross-site scripting (XSS) vulnerability in im.php in IMessenger for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via a message.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2001-1521

почти 24 года назад

Cross-site scripting (XSS) vulnerability in user.php in PostNuke 0.64 allows remote attackers to inject arbitrary web script or HTML via the uname parameter.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2001-1520

почти 24 года назад

Xircom REX 6000 allows local users to obtain the 10 digit PIN by starting a serial monitor, connecting to the personal digital assistant (PDA) via Rextools, and capturing the cleartext PIN.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1519

почти 24 года назад

RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then capture cleartext usernames and passwords when clients connect to the service. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2001-1518

почти 24 года назад

RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denial of service (RunAs hang) by creating a named pipe session with the authentication server without any request for service. NOTE: the vendor disputes this vulnerability, however the vendor also presents a scenario in which other users could be affected if running on a Terminal Server. Therefore this is a vulnerability.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1517

почти 24 года назад

RunAs (runas.exe) in Windows 2000 stores cleartext authentication information in memory, which could allow attackers to obtain usernames and passwords by executing a process that is allocated the same memory page after termination of a RunAs command. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it, and the original researcher did not respond to requests for additional information

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1516

почти 24 года назад

Cross-site scripting (XSS) vulnerability in phpReview 0.9.0 rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via user-submitted reviews.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2001-1515

почти 24 года назад

Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less restrictive permissions than intended.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1514

почти 24 года назад

ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with <CFEXECUTE> and (2) child processes that call the CreateProcess function and are executed with <CFOBJECT> or end with the CFX extension, which allows attackers to execute programs with the permissions of the System account.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2001-1513

почти 24 года назад

Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing '/' (slash), as demonstrated using ctx.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1512

почти 24 года назад

Unknown vulnerability in Allaire JRun 3.1 allows remote attackers to directly access the WEB-INF and META-INF directories and execute arbitrary JavaServer Pages (JSP), a variant of CVE-2000-1050.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2001-1511

почти 24 года назад

JRun 3.0 and 3.1 running on JRun Web Server (JWS) and IIS allows remote attackers to read arbitrary JavaServer Pages (JSP) source code via a request URL containing the source filename ending in (1) "jsp%00" or (2) "js%2570".

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1510

почти 24 года назад

Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1509

почти 24 года назад

geteuid in Itanium Architecture (IA) running on HP-UX 11.20 does not properly identify a user's effective user id, which could allow local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2001-1508

почти 24 года назад

Buffer overflow in lpstat in SCO OpenServer 5.0 through 5.0.6a allows local users to execute arbitrary code as group bin via a long command line argument.

CVSS2: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-1527

easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtain the passwords and gain access.

CVSS2: 2.1
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1526

Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the zeit parameter.

CVSS2: 4.3
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1525

Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.dat and possibly other files via a ".." in the cid parameter.

CVSS2: 5
4%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1524

Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) uname parameter in user.php, (2) ttitle, letter and file parameters in modules.php, (3) subject, story and storyext parameters in submit.php, (4) upload parameter in admin.php and (5) fname parameter in friend.php.

CVSS2: 4.3
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1523

Cross-site scripting (XSS) vulnerability in the DMOZGateway module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the topic parameter.

CVSS2: 4.3
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1522

Cross-site scripting (XSS) vulnerability in im.php in IMessenger for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via a message.

CVSS2: 4.3
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1521

Cross-site scripting (XSS) vulnerability in user.php in PostNuke 0.64 allows remote attackers to inject arbitrary web script or HTML via the uname parameter.

CVSS2: 2.6
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1520

Xircom REX 6000 allows local users to obtain the 10 digit PIN by starting a serial monitor, connecting to the personal digital assistant (PDA) via Rextools, and capturing the cleartext PIN.

CVSS2: 2.1
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1519

RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then capture cleartext usernames and passwords when clients connect to the service. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it

CVSS2: 3.6
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1518

RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denial of service (RunAs hang) by creating a named pipe session with the authentication server without any request for service. NOTE: the vendor disputes this vulnerability, however the vendor also presents a scenario in which other users could be affected if running on a Terminal Server. Therefore this is a vulnerability.

CVSS2: 2.1
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1517

RunAs (runas.exe) in Windows 2000 stores cleartext authentication information in memory, which could allow attackers to obtain usernames and passwords by executing a process that is allocated the same memory page after termination of a RunAs command. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it, and the original researcher did not respond to requests for additional information

CVSS2: 2.1
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1516

Cross-site scripting (XSS) vulnerability in phpReview 0.9.0 rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via user-submitted reviews.

CVSS2: 4.3
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1515

Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less restrictive permissions than intended.

CVSS3: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1514

ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with <CFEXECUTE> and (2) child processes that call the CreateProcess function and are executed with <CFOBJECT> or end with the CFX extension, which allows attackers to execute programs with the permissions of the System account.

CVSS2: 10
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1513

Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing '/' (slash), as demonstrated using ctx.

CVSS2: 7.5
8%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1512

Unknown vulnerability in Allaire JRun 3.1 allows remote attackers to directly access the WEB-INF and META-INF directories and execute arbitrary JavaServer Pages (JSP), a variant of CVE-2000-1050.

CVSS2: 6.4
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1511

JRun 3.0 and 3.1 running on JRun Web Server (JWS) and IIS allows remote attackers to read arbitrary JavaServer Pages (JSP) source code via a request URL containing the source filename ending in (1) "jsp%00" or (2) "js%2570".

CVSS2: 5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1510

Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL.

CVSS2: 5
4%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1509

geteuid in Itanium Architecture (IA) running on HP-UX 11.20 does not properly identify a user's effective user id, which could allow local users to gain privileges.

CVSS2: 4.6
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2001-1508

Buffer overflow in lpstat in SCO OpenServer 5.0 through 5.0.6a allows local users to execute arbitrary code as group bin via a long command line argument.

CVSS2: 4.6
0%
Низкий
почти 24 года назад

Уязвимостей на страницу