Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 149

Количество 371 149

nvd логотип

CVE-2002-1846

больше 23 лет назад

Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password, which allows remote attackers to modify passwords by stealing the cookie of another user, modifying the expiretime setting, and submitting the change in a profile2 action to index.php.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1845

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-1844

больше 23 лет назад

Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permissions, which allows local users to delete or modify the executables to gain privileges.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2002-1843

больше 23 лет назад

Perlbot 1.9.2 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the $text variable in SpelCheck.pm or (2) the $filename variable in HTMLPlog.pm.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1842

больше 23 лет назад

Perlbot 1.0 beta allows remote attackers to execute arbitrary commands via shell metacharacters in (1) a word that is being spell checked or (2) an e-mail address.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1841

больше 23 лет назад

The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to upload and execute arbitrary PHP files with extensions such as .php4.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1840

больше 23 лет назад

irssi IRC client 0.8.4, when downloaded after 14-March-2002, could contain a backdoor in the configuration file, which allows remote attackers to access the system.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-1839

больше 23 лет назад

Trend Micro InterScan VirusWall for Windows NT 3.52 does not record the sender's IP address in the headers for a mail message when it is passed from VirusWall to the MTA, which allows remote attackers to hide the origin of the message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1838

больше 23 лет назад

Charities.cron 1.0.2 through 1.6.0 allows local users to write to arbitrary files via a symlink attack on temporary files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1837

больше 23 лет назад

The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on whether the directory exists or not.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1836

больше 23 лет назад

The default configuration of Xerox DocuTech 6110 and DocuTech 6115 exports certain NFS shares to the world with world writable permissions, which may allow remote attackers to modify sensitive files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1835

больше 23 лет назад

The default configuration of Xerox DocuTech 6110 and DocuTech 6115 running Solaris 8.0 has a large number of unnecessary services enabled such as RPC and sprayd, which could allow remote attackers to obtain access to the device.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1834

больше 23 лет назад

The default configuration of Xerox DocuTech 6110 and DocuTech 6115 allows remote attackers to connect to the web server and (1) submit print jobs directly into the "print now" queue or (2) read the scanner job history.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2002-1833

больше 23 лет назад

The default configurations for DocuTech 6110 and DocuTech 6115 have a default administrative password of (1) "service!" on Solaris 8.0 or (2) "administ" on Windows NT, which allows remote attackers to gain privileges.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1832

больше 23 лет назад

Unknown vulnerability in the "ipopts decode" functionality in Firestorm IDS 0.4.0 through 0.4.2 allows remote attackers to cause a denial of service (crash) via certain IP options.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1831

больше 23 лет назад

Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1830

больше 23 лет назад

Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via a direct request to moderator.php with the action and ismod parameters.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1829

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in codeparse.php in Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to inject arbitrary web script or HTML via (1) myhome.php, (2) an onerror attribute in an IMG tag (a variant of CVE-2002-0330), or (3) a glow tag.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-1828

больше 23 лет назад

Savant Webserver 3.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request with a negative Content-Length value.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1827

больше 23 лет назад

Sendmail 8.9.0 through 8.12.3 allows local users to cause a denial of service by obtaining an exclusive lock on the (1) alias, (2) map, (3) statistics, and (4) pid files.

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-1846

Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password, which allows remote attackers to modify passwords by stealing the cookie of another user, modifying the expiretime setting, and submitting the change in a profile2 action to index.php.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1845

Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter.

CVSS2: 4.3
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1844

Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permissions, which allows local users to delete or modify the executables to gain privileges.

CVSS3: 7.8
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1843

Perlbot 1.9.2 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the $text variable in SpelCheck.pm or (2) the $filename variable in HTMLPlog.pm.

CVSS2: 7.5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1842

Perlbot 1.0 beta allows remote attackers to execute arbitrary commands via shell metacharacters in (1) a word that is being spell checked or (2) an e-mail address.

CVSS2: 7.5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1841

The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to upload and execute arbitrary PHP files with extensions such as .php4.

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1840

irssi IRC client 0.8.4, when downloaded after 14-March-2002, could contain a backdoor in the configuration file, which allows remote attackers to access the system.

CVSS2: 10
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1839

Trend Micro InterScan VirusWall for Windows NT 3.52 does not record the sender's IP address in the headers for a mail message when it is passed from VirusWall to the MTA, which allows remote attackers to hide the origin of the message.

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1838

Charities.cron 1.0.2 through 1.6.0 allows local users to write to arbitrary files via a symlink attack on temporary files.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1837

The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on whether the directory exists or not.

CVSS2: 5
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1836

The default configuration of Xerox DocuTech 6110 and DocuTech 6115 exports certain NFS shares to the world with world writable permissions, which may allow remote attackers to modify sensitive files.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1835

The default configuration of Xerox DocuTech 6110 and DocuTech 6115 running Solaris 8.0 has a large number of unnecessary services enabled such as RPC and sprayd, which could allow remote attackers to obtain access to the device.

CVSS2: 7.5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1834

The default configuration of Xerox DocuTech 6110 and DocuTech 6115 allows remote attackers to connect to the web server and (1) submit print jobs directly into the "print now" queue or (2) read the scanner job history.

CVSS2: 6.4
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1833

The default configurations for DocuTech 6110 and DocuTech 6115 have a default administrative password of (1) "service!" on Solaris 8.0 or (2) "administ" on Windows NT, which allows remote attackers to gain privileges.

CVSS2: 7.5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1832

Unknown vulnerability in the "ipopts decode" functionality in Firestorm IDS 0.4.0 through 0.4.2 allows remote attackers to cause a denial of service (crash) via certain IP options.

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1831

Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field.

CVSS2: 5
22%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-1830

Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via a direct request to moderator.php with the action and ismod parameters.

CVSS2: 5
7%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1829

Cross-site scripting (XSS) vulnerability in codeparse.php in Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to inject arbitrary web script or HTML via (1) myhome.php, (2) an onerror attribute in an IMG tag (a variant of CVE-2002-0330), or (3) a glow tag.

CVSS2: 4.3
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1828

Savant Webserver 3.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request with a negative Content-Length value.

CVSS2: 5
7%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1827

Sendmail 8.9.0 through 8.12.3 allows local users to cause a denial of service by obtaining an exclusive lock on the (1) alias, (2) map, (3) statistics, and (4) pid files.

CVSS2: 2.1
1%
Низкий
больше 23 лет назад

Уязвимостей на страницу