Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 863

Количество 371 863

nvd логотип

CVE-2002-1085

почти 24 года назад

Multiple cross-site scripting vulnerabilities in ezContents 1.41 and earlier allow remote attackers to execute script and steal cookies via the diary and other capabilities.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1084

почти 24 года назад

The VerifyLogin function in ezContents 1.41 and earlier does not properly halt program execution if a user fails to log in properly, which allows remote attackers to modify and view restricted information via HTTP POST requests.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2002-1083

почти 24 года назад

Directory traversal vulnerabilities in ezContents 1.41 and earlier allow remote attackers to cause ezContents to (1) create directories using the Maintain Images:Add New:Create Subdirectory item, or (2) list directories using the Maintain Images file listing, via .. (dot dot) sequences.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1082

почти 24 года назад

The Image Upload capability for ezContents 1.40 and earlier allows remote attackers to cause ezContents to perform operations on local files as if they were uploaded.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1081

почти 24 года назад

The Administration console for Abyss Web Server 1.0.3 allows remote attackers to read files without providing login credentials via an HTTP request to a target file that ends in a "+" character.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1080

почти 24 года назад

The Administration console for Abyss Web Server 1.0.3 before Patch 2 allows remote attackers to gain privileges and modify server configuration via direct requests to CHL files such as (1) srvstatus.chl, (2) consport.chl, (3) general.chl, (4) srvparam.chl, and (5) advanced.chl.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1079

почти 24 года назад

Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in an HTTP GET request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1078

почти 24 года назад

Abyss Web Server 1.0.3 allows remote attackers to list directory contents via an HTTP GET request that ends in a large number of / (slash) characters.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1077

почти 24 года назад

IPSwitch IMail Web Calendaring service (iwebcal) allows remote attackers to cause a denial of service (crash) via an HTTP POST request without a Content-Length field.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1076

почти 24 года назад

Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HTTP/1.0.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-1075

почти 24 года назад

Buffer overflow in Pegasus mail client 4.01 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) To or (2) From headers.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1073

почти 24 года назад

Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1072

почти 24 года назад

ZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized, fragmented "jolt" style ICMP packet.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1071

почти 24 года назад

ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet with both the SYN and ACK flags set.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1070

почти 24 года назад

Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1069

почти 24 года назад

The remote administration capability for the D-Link DI-804 router 4.68 allows remote attackers to bypass authentication and release DHCP addresses or obtain sensitive information via a direct web request to the pages (1) release.htm, (2) Device Status, or (3) Device Information.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1068

почти 24 года назад

The web server for D-Link DP-300 print server allows remote attackers to cause a denial of service (hang) via a large HTTP POST request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1067

почти 24 года назад

Administrative web interface for IC9 Pocket Print Server Firmware 7.1.30 and 7.1.36f allows remote attackers to cause a denial of service (reboot and reset) via a long password, possibly due to a buffer overflow.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1066

почти 24 года назад

Thomas Hauck Jana Server 1.4.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large message index value in a (1) RETR or (2) DELE command to the POP3 server, which exceeds the array limits and allows a buffer overflow attack.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1065

почти 24 года назад

Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, does not restrict the number of unsuccessful login attempts, which makes it easier for remote attackers to gain privileges via brute force username and password guessing.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-1085

Multiple cross-site scripting vulnerabilities in ezContents 1.41 and earlier allow remote attackers to execute script and steal cookies via the diary and other capabilities.

CVSS2: 7.5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1084

The VerifyLogin function in ezContents 1.41 and earlier does not properly halt program execution if a user fails to log in properly, which allows remote attackers to modify and view restricted information via HTTP POST requests.

CVSS2: 6.4
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1083

Directory traversal vulnerabilities in ezContents 1.41 and earlier allow remote attackers to cause ezContents to (1) create directories using the Maintain Images:Add New:Create Subdirectory item, or (2) list directories using the Maintain Images file listing, via .. (dot dot) sequences.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1082

The Image Upload capability for ezContents 1.40 and earlier allows remote attackers to cause ezContents to perform operations on local files as if they were uploaded.

CVSS2: 5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1081

The Administration console for Abyss Web Server 1.0.3 allows remote attackers to read files without providing login credentials via an HTTP request to a target file that ends in a "+" character.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1080

The Administration console for Abyss Web Server 1.0.3 before Patch 2 allows remote attackers to gain privileges and modify server configuration via direct requests to CHL files such as (1) srvstatus.chl, (2) consport.chl, (3) general.chl, (4) srvparam.chl, and (5) advanced.chl.

CVSS2: 7.5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1079

Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in an HTTP GET request.

CVSS2: 5
5%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1078

Abyss Web Server 1.0.3 allows remote attackers to list directory contents via an HTTP GET request that ends in a large number of / (slash) characters.

CVSS2: 5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1077

IPSwitch IMail Web Calendaring service (iwebcal) allows remote attackers to cause a denial of service (crash) via an HTTP POST request without a Content-Length field.

CVSS2: 5
11%
Средний
почти 24 года назад
nvd логотип
CVE-2002-1076

Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HTTP/1.0.

CVSS2: 7.5
14%
Средний
почти 24 года назад
nvd логотип
CVE-2002-1075

Buffer overflow in Pegasus mail client 4.01 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) To or (2) From headers.

CVSS2: 7.5
6%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1073

Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password.

CVSS2: 7.5
6%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1072

ZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized, fragmented "jolt" style ICMP packet.

CVSS2: 5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1071

ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet with both the SYN and ACK flags set.

CVSS2: 5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1070

Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter.

CVSS2: 7.5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1069

The remote administration capability for the D-Link DI-804 router 4.68 allows remote attackers to bypass authentication and release DHCP addresses or obtain sensitive information via a direct web request to the pages (1) release.htm, (2) Device Status, or (3) Device Information.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1068

The web server for D-Link DP-300 print server allows remote attackers to cause a denial of service (hang) via a large HTTP POST request.

CVSS2: 5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1067

Administrative web interface for IC9 Pocket Print Server Firmware 7.1.30 and 7.1.36f allows remote attackers to cause a denial of service (reboot and reset) via a long password, possibly due to a buffer overflow.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1066

Thomas Hauck Jana Server 1.4.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large message index value in a (1) RETR or (2) DELE command to the POP3 server, which exceeds the array limits and allows a buffer overflow attack.

CVSS2: 7.5
4%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1065

Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, does not restrict the number of unsuccessful login attempts, which makes it easier for remote attackers to gain privileges via brute force username and password guessing.

CVSS2: 7.5
1%
Низкий
почти 24 года назад

Уязвимостей на страницу