Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 343 490

Количество 343 490

nvd логотип

CVE-2002-1466

почти 23 года назад

CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-1465

почти 23 года назад

SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1464

почти 23 года назад

Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2002-1463

почти 23 года назад

Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor Models 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 generate easily predictable initial sequence numbers (ISN), which allows remote attackers to spoof connections.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-1462

почти 23 года назад

details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1461

почти 23 года назад

Web Shop Manager 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search box.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1460

почти 23 года назад

L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1459

почти 23 года назад

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1458

почти 23 года назад

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, (3) Subject and (4) Body.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1457

почти 23 года назад

SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements via the search parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1456

почти 23 года назад

Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-1455

почти 23 года назад

Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-1454

почти 23 года назад

MyWebServer 1.0.2 allows remote attackers to determine the absolute path of the web document root via a request for a directory that does not exist, which leaks the pathname in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1453

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in MyWebServer 1.0.2 allows remote attackers to insert script and HTML via a long request followed by the malicious script, which is echoed back to the user in an error message.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-1452

больше 23 лет назад

Buffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a long searchTarget parameter.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-1451

больше 23 лет назад

Blazix before 1.2.2 allows remote attackers to read source code of JSP scripts or list restricted web directories via an HTTP request that ends in a (1) "+" or (2) "\" (backslash) character.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1450

больше 23 лет назад

IBM UniVerse with UV/ODBC allows attackers to cause a denial of service (client crash or server CPU consumption) via a query with an invalid link between tables, possibly via a buffer overflow.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1449

больше 23 лет назад

eUpload 1.0 stores the password.txt password file in plaintext under the web document root, which allows remote attackers to overwrite arbitrary files by reading password.txt.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1448

почти 24 года назад

An undocumented SNMP read/write community string ('NoGaH$@!') in Avaya P330, P130, and M770-ATM Cajun products allows remote attackers to gain administrative privileges.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1447

почти 24 года назад

Buffer overflow in the vpnclient program for UNIX VPN Client before 3.5.2 allows local users to gain administrative privileges via a long profile name in a connect argument.

CVSS2: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-1466

CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable.

CVSS2: 10
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1465

SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable.

CVSS2: 7.5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1464

Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable.

CVSS2: 6.8
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1463

Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor Models 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 generate easily predictable initial sequence numbers (ISN), which allows remote attackers to spoof connections.

CVSS2: 7.5
11%
Средний
почти 23 года назад
nvd логотип
CVE-2002-1462

details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields.

CVSS2: 5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1461

Web Shop Manager 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search box.

CVSS2: 7.5
2%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1460

L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files.

CVSS2: 5
2%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1459

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject.

CVSS2: 7.5
2%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1458

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, (3) Subject and (4) Body.

CVSS2: 7.5
2%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1457

SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements via the search parameter.

CVSS2: 7.5
2%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1456

Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.

CVSS2: 7.5
18%
Средний
почти 23 года назад
nvd логотип
CVE-2002-1455

Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.

CVSS2: 4.3
0%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1454

MyWebServer 1.0.2 allows remote attackers to determine the absolute path of the web document root via a request for a directory that does not exist, which leaks the pathname in an error message.

CVSS2: 5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1453

Cross-site scripting (XSS) vulnerability in MyWebServer 1.0.2 allows remote attackers to insert script and HTML via a long request followed by the malicious script, which is echoed back to the user in an error message.

CVSS2: 4.3
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1452

Buffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a long searchTarget parameter.

CVSS2: 7.5
16%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-1451

Blazix before 1.2.2 allows remote attackers to read source code of JSP scripts or list restricted web directories via an HTTP request that ends in a (1) "+" or (2) "\" (backslash) character.

CVSS2: 5
6%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1450

IBM UniVerse with UV/ODBC allows attackers to cause a denial of service (client crash or server CPU consumption) via a query with an invalid link between tables, possibly via a buffer overflow.

CVSS2: 5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1449

eUpload 1.0 stores the password.txt password file in plaintext under the web document root, which allows remote attackers to overwrite arbitrary files by reading password.txt.

CVSS2: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1448

An undocumented SNMP read/write community string ('NoGaH$@!') in Avaya P330, P130, and M770-ATM Cajun products allows remote attackers to gain administrative privileges.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1447

Buffer overflow in the vpnclient program for UNIX VPN Client before 3.5.2 allows local users to gain administrative privileges via a long profile name in a connect argument.

CVSS2: 7.2
1%
Низкий
почти 24 года назад

Уязвимостей на страницу