Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 614

Количество 367 614

nvd логотип

CVE-2002-1469

больше 23 лет назад

scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs and modifying the PATH variable in $HOME/.ssh/environment to locate those programs.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1468

больше 23 лет назад

Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-1467

больше 23 лет назад

Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3) a relative URL from a web archive (mht file).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1466

больше 23 лет назад

CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-1465

больше 23 лет назад

SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1464

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2002-1463

около 23 лет назад

Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor Models 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 generate easily predictable initial sequence numbers (ISN), which allows remote attackers to spoof connections.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1462

около 23 лет назад

details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1461

около 23 лет назад

Web Shop Manager 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search box.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1460

около 23 лет назад

L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1459

около 23 лет назад

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1458

около 23 лет назад

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, (3) Subject and (4) Body.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1457

около 23 лет назад

SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements via the search parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1456

около 23 лет назад

Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-1455

около 23 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-1454

около 23 лет назад

MyWebServer 1.0.2 allows remote attackers to determine the absolute path of the web document root via a request for a directory that does not exist, which leaks the pathname in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1453

почти 24 года назад

Cross-site scripting (XSS) vulnerability in MyWebServer 1.0.2 allows remote attackers to insert script and HTML via a long request followed by the malicious script, which is echoed back to the user in an error message.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-1452

почти 24 года назад

Buffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a long searchTarget parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1451

почти 24 года назад

Blazix before 1.2.2 allows remote attackers to read source code of JSP scripts or list restricted web directories via an HTTP request that ends in a (1) "+" or (2) "\" (backslash) character.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1450

около 24 лет назад

IBM UniVerse with UV/ODBC allows attackers to cause a denial of service (client crash or server CPU consumption) via a query with an invalid link between tables, possibly via a buffer overflow.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-1469

scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs and modifying the PATH variable in $HOME/.ssh/environment to locate those programs.

CVSS2: 7.5
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1468

Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.

CVSS2: 10
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1467

Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3) a relative URL from a web archive (mht file).

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1466

CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable.

CVSS2: 10
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1465

SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable.

CVSS2: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1464

Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable.

CVSS2: 6.8
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1463

Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor Models 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 generate easily predictable initial sequence numbers (ISN), which allows remote attackers to spoof connections.

CVSS2: 7.5
7%
Низкий
около 23 лет назад
nvd логотип
CVE-2002-1462

details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields.

CVSS2: 5
1%
Низкий
около 23 лет назад
nvd логотип
CVE-2002-1461

Web Shop Manager 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search box.

CVSS2: 7.5
2%
Низкий
около 23 лет назад
nvd логотип
CVE-2002-1460

L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files.

CVSS2: 5
2%
Низкий
около 23 лет назад
nvd логотип
CVE-2002-1459

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject.

CVSS2: 7.5
2%
Низкий
около 23 лет назад
nvd логотип
CVE-2002-1458

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, (3) Subject and (4) Body.

CVSS2: 7.5
2%
Низкий
около 23 лет назад
nvd логотип
CVE-2002-1457

SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements via the search parameter.

CVSS2: 7.5
1%
Низкий
около 23 лет назад
nvd логотип
CVE-2002-1456

Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.

CVSS2: 7.5
12%
Средний
около 23 лет назад
nvd логотип
CVE-2002-1455

Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.

CVSS2: 4.3
4%
Низкий
около 23 лет назад
nvd логотип
CVE-2002-1454

MyWebServer 1.0.2 allows remote attackers to determine the absolute path of the web document root via a request for a directory that does not exist, which leaks the pathname in an error message.

CVSS2: 5
2%
Низкий
около 23 лет назад
nvd логотип
CVE-2002-1453

Cross-site scripting (XSS) vulnerability in MyWebServer 1.0.2 allows remote attackers to insert script and HTML via a long request followed by the malicious script, which is echoed back to the user in an error message.

CVSS2: 4.3
4%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1452

Buffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a long searchTarget parameter.

CVSS2: 7.5
5%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1451

Blazix before 1.2.2 allows remote attackers to read source code of JSP scripts or list restricted web directories via an HTTP request that ends in a (1) "+" or (2) "\" (backslash) character.

CVSS2: 5
8%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1450

IBM UniVerse with UV/ODBC allows attackers to cause a denial of service (client crash or server CPU consumption) via a query with an invalid link between tables, possibly via a buffer overflow.

CVSS2: 5
1%
Низкий
около 24 лет назад

Уязвимостей на страницу