Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 149

Количество 371 149

nvd логотип

CVE-2002-1926

больше 23 лет назад

Directory traversal vulnerability in source.php in Aquonics File Manager 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP query string.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1925

больше 23 лет назад

Tiny Personal Firewall 3.0 through 3.0.6 allows remote attackers to cause a denial of service (crash) by via SYN, UDP, ICMP and TCP portscans when the administrator selects the Log tab of the Personal Firewall Agent module.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1924

больше 23 лет назад

PowerChute plus 5.0.2 creates a "Pwrchute" directory during installation that is shared and world writeable, which could allow remote attackers to modify or create files in that directory.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1923

больше 23 лет назад

The default configuration in MySQL 3.20.32 through 3.23.52, when running on Windows, does not have logging enabled, which could allow remote attackers to conduct activities without detection.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1922

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in global.php in Jelsoft vBulletin 2.0.0 through 2.2.8 allows remote attackers to inject arbitrary web script or HTML via the (1) $scriptpath or (2) $url variables.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-1921

больше 23 лет назад

The default configuration of MySQL 3.20.32 through 3.23.52, when running on Windows, does set the bind address to the loopback interface, which allows remote attackers to connect to the database.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1920

больше 23 лет назад

Buffer overflow in FtpXQ 2.5 allows remote attackers to cause a denial of service (crash) via a MKD command with a long directory name.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1919

больше 23 лет назад

SQL injection vulnerability in shopadmin.asp in VP-ASP 4.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password fields.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1918

больше 23 лет назад

Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown attack vectors. NOTE: due to the lack of details available regarding this issue, perhaps it should be REJECTED.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2002-1917

больше 23 лет назад

CRLF injection vulnerability in the "User Profile: Send Email" feature in Geeklog 1.35 and 1.3.5sr1 allows remote attackers to obtain e-mail addresses by injecting a CRLF into the Subject field and adding a BCC mail header.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1916

больше 23 лет назад

Pirch and RusPirch, when auto-log is enabled, allows remote attackers to cause a denial of service (crash) via a nickname containing an MS-DOS device name such as AUX, which is inserted into a filename for saving queries.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1915

больше 23 лет назад

tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2002-1914

больше 23 лет назад

dump 0.4 b10 through b29 allows local users to cause a denial of service (execution prevention) by using flock() to lock the /etc/dumpdates file.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2002-1913

больше 23 лет назад

phptonuke.php in myPHPNuke 1.8.8 allows remote attackers to read arbitrary files via a full pathname in the filnavn variable.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1912

больше 23 лет назад

SkyStream EMR5000 1.16 through 1.18 does not drop packets or disable the Ethernet interface when the buffers are full, which allows remote attackers to cause a denial of service (null pointer exception and kernel panic) via a large number of packets.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1911

больше 23 лет назад

ZoneAlarm Pro 3.0 and 3.1, when configured to block all traffic, allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of SYN packets (SYN flood). NOTE: the vendor was not able to reproduce the issue.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1910

больше 23 лет назад

Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtain passwords.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1909

больше 23 лет назад

Click2Learn Ingenium Learning Management System 5.1 and 6.1 stores the hashed administrative password in a config.txt file under the htdocs directory, which allows remote attackers to obtain the administrative password.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1908

больше 23 лет назад

Microsoft IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with a Host header that contains a large number of "/" (forward slash) characters.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1907

больше 23 лет назад

TelCondex SimpleWebServer 2.06.20817 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-1926

Directory traversal vulnerability in source.php in Aquonics File Manager 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP query string.

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1925

Tiny Personal Firewall 3.0 through 3.0.6 allows remote attackers to cause a denial of service (crash) by via SYN, UDP, ICMP and TCP portscans when the administrator selects the Log tab of the Personal Firewall Agent module.

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1924

PowerChute plus 5.0.2 creates a "Pwrchute" directory during installation that is shared and world writeable, which could allow remote attackers to modify or create files in that directory.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1923

The default configuration in MySQL 3.20.32 through 3.23.52, when running on Windows, does not have logging enabled, which could allow remote attackers to conduct activities without detection.

CVSS2: 7.5
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1922

Cross-site scripting (XSS) vulnerability in global.php in Jelsoft vBulletin 2.0.0 through 2.2.8 allows remote attackers to inject arbitrary web script or HTML via the (1) $scriptpath or (2) $url variables.

CVSS2: 4.3
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1921

The default configuration of MySQL 3.20.32 through 3.23.52, when running on Windows, does set the bind address to the loopback interface, which allows remote attackers to connect to the database.

CVSS2: 7.5
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1920

Buffer overflow in FtpXQ 2.5 allows remote attackers to cause a denial of service (crash) via a MKD command with a long directory name.

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1919

SQL injection vulnerability in shopadmin.asp in VP-ASP 4.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password fields.

CVSS2: 7.5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1918

Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown attack vectors. NOTE: due to the lack of details available regarding this issue, perhaps it should be REJECTED.

CVSS2: 10
16%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-1917

CRLF injection vulnerability in the "User Profile: Send Email" feature in Geeklog 1.35 and 1.3.5sr1 allows remote attackers to obtain e-mail addresses by injecting a CRLF into the Subject field and adding a BCC mail header.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1916

Pirch and RusPirch, when auto-log is enabled, allows remote attackers to cause a denial of service (crash) via a nickname containing an MS-DOS device name such as AUX, which is inserted into a filename for saving queries.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1915

tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file.

CVSS3: 5.5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1914

dump 0.4 b10 through b29 allows local users to cause a denial of service (execution prevention) by using flock() to lock the /etc/dumpdates file.

CVSS3: 5.5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1913

phptonuke.php in myPHPNuke 1.8.8 allows remote attackers to read arbitrary files via a full pathname in the filnavn variable.

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1912

SkyStream EMR5000 1.16 through 1.18 does not drop packets or disable the Ethernet interface when the buffers are full, which allows remote attackers to cause a denial of service (null pointer exception and kernel panic) via a large number of packets.

CVSS3: 7.5
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1911

ZoneAlarm Pro 3.0 and 3.1, when configured to block all traffic, allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of SYN packets (SYN flood). NOTE: the vendor was not able to reproduce the issue.

CVSS2: 5
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1910

Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtain passwords.

CVSS3: 7.5
6%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1909

Click2Learn Ingenium Learning Management System 5.1 and 6.1 stores the hashed administrative password in a config.txt file under the htdocs directory, which allows remote attackers to obtain the administrative password.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1908

Microsoft IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with a Host header that contains a large number of "/" (forward slash) characters.

CVSS2: 5
15%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-1907

TelCondex SimpleWebServer 2.06.20817 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.

CVSS2: 5
3%
Низкий
больше 23 лет назад

Уязвимостей на страницу