Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 863

Количество 371 863

nvd логотип

CVE-2002-0477

почти 24 года назад

Standalone Macromedia Flash Player 5.0 before 5,0,30,2 allows remote attackers to execute arbitrary programs via a .SWF file containing the "exec" FSCommand.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0476

почти 24 года назад

Standalone Macromedia Flash Player 5.0 allows remote attackers to save arbitrary files and programs via a .SWF file containing the undocumented "save" FSCommand.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0475

почти 24 года назад

Cross-site scripting vulnerability in phpBB 1.4.4 and earlier allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within an IMG image tag while editing a message.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2002-0474

почти 24 года назад

Cross-site scripting vulnerability in ZeroForum allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within IMG image tag.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2002-0473

почти 24 года назад

db.php in phpBB 2.0 (aka phpBB2) RC-3 and earlier allows remote attackers to execute arbitrary code from remote servers via the phpbb_root_path parameter.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0472

почти 24 года назад

MSN Messenger Service 3.6, and possibly other versions, uses weak authentication when exchanging messages between clients, which allows remote attackers to spoof messages from other users.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-0471

почти 24 года назад

PHPNetToolpack 0.1 allows remote attackers to execute arbitrary code via shell metacharacters in the a_query variable.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0470

почти 24 года назад

PHPNetToolpack 0.1 relies on its environment's PATH to find and execute the traceroute program, which could allow local users to gain privileges by inserting a Trojan horse program into the search path.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0469

почти 24 года назад

Ecartis (formerly Listar) 1.0.0 in snapshot 20020125 and earlier does not properly drop privileges when Ecartis is installed setuid-root, "lock-to-user" is not set, and ecartis is called by certain MTA's, which could allow local users to gain privileges.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0468

почти 24 года назад

Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privileges via (1) a long command line argument, which is not properly handled in core.c, or possibly via bad uses of sprintf() in (2) moderate.c, (3) lcgi.c, (4) fileapi.c, (5) cookie.c, (6) codes.c, or other files.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-0467

почти 24 года назад

Buffer overflows in Ecartis (formerly Listar) 1.0.0 before snapshot 20020125 allows remote attackers to execute arbitrary code via (1) address_match() of mystring.c or (2) other functions in tolist.c.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0466

почти 24 года назад

Hosting Controller 1.4.1 and earlier allows remote attackers to browse arbitrary directories via a full C: style pathname in the filepath arguments to (1) Statsbrowse.asp, (2) servubrowse.asp, (3) browsedisk.asp, (4) browsewebalizerexe.asp, or (5) sqlbrowse.asp.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0465

почти 24 года назад

Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files, and execute commands, via a .. (dot dot) in the OpenPath parameter.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0464

почти 24 года назад

Directory traversal vulnerability in Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files and directories via a .. (dot dot) in arguments to (1) file_editor.asp, (2) folderactions.asp, or (3) editoractions.asp.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2002-0463

почти 24 года назад

home.php in ARSC (Really Simple Chat) 1.0.1 and earlier allows remote attackers to determine the full pathname of the web server via an invalid language in the arsc_language parameter, which leaks the pathname in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0462

почти 24 года назад

bigsam_guestbook.php for Big Sam (Built-In Guestbook Stand-Alone Module) 1.1.08 and earlier allows remote attackers to cause a denial of service (CPU consumption) or obtain the absolute path of the web server via a displayBegin parameter with a very large number, which leaks the web path in an error message when PHP safe_mode is enabled, or consumes resources when safe_mode is not enabled.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2002-0461

почти 24 года назад

Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript in a web page that calls location.replace on itself, causing a loop.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-0460

почти 24 года назад

Bitvise WinSSHD before 2002-03-16 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of incomplete connections that are not properly terminated, which are not properly freed by SSHd.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0459

почти 24 года назад

Cross-site scripting vulnerability in Board-TNK 1.3.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter.

CVSS2: 7.6
EPSS: Низкий
nvd логотип

CVE-2002-0458

почти 24 года назад

Cross-site scripting vulnerability in News-TNK 1.2.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter.

CVSS2: 7.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-0477

Standalone Macromedia Flash Player 5.0 before 5,0,30,2 allows remote attackers to execute arbitrary programs via a .SWF file containing the "exec" FSCommand.

CVSS2: 7.5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0476

Standalone Macromedia Flash Player 5.0 allows remote attackers to save arbitrary files and programs via a .SWF file containing the undocumented "save" FSCommand.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0475

Cross-site scripting vulnerability in phpBB 1.4.4 and earlier allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within an IMG image tag while editing a message.

CVSS2: 5.1
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0474

Cross-site scripting vulnerability in ZeroForum allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within IMG image tag.

CVSS2: 5.1
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0473

db.php in phpBB 2.0 (aka phpBB2) RC-3 and earlier allows remote attackers to execute arbitrary code from remote servers via the phpbb_root_path parameter.

CVSS2: 10
5%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0472

MSN Messenger Service 3.6, and possibly other versions, uses weak authentication when exchanging messages between clients, which allows remote attackers to spoof messages from other users.

CVSS2: 5
12%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0471

PHPNetToolpack 0.1 allows remote attackers to execute arbitrary code via shell metacharacters in the a_query variable.

CVSS2: 10
8%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0470

PHPNetToolpack 0.1 relies on its environment's PATH to find and execute the traceroute program, which could allow local users to gain privileges by inserting a Trojan horse program into the search path.

CVSS2: 7.2
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0469

Ecartis (formerly Listar) 1.0.0 in snapshot 20020125 and earlier does not properly drop privileges when Ecartis is installed setuid-root, "lock-to-user" is not set, and ecartis is called by certain MTA's, which could allow local users to gain privileges.

CVSS2: 7.2
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0468

Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privileges via (1) a long command line argument, which is not properly handled in core.c, or possibly via bad uses of sprintf() in (2) moderate.c, (3) lcgi.c, (4) fileapi.c, (5) cookie.c, (6) codes.c, or other files.

CVSS2: 4.6
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0467

Buffer overflows in Ecartis (formerly Listar) 1.0.0 before snapshot 20020125 allows remote attackers to execute arbitrary code via (1) address_match() of mystring.c or (2) other functions in tolist.c.

CVSS2: 10
6%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0466

Hosting Controller 1.4.1 and earlier allows remote attackers to browse arbitrary directories via a full C: style pathname in the filepath arguments to (1) Statsbrowse.asp, (2) servubrowse.asp, (3) browsedisk.asp, (4) browsewebalizerexe.asp, or (5) sqlbrowse.asp.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0465

Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files, and execute commands, via a .. (dot dot) in the OpenPath parameter.

CVSS2: 10
4%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0464

Directory traversal vulnerability in Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files and directories via a .. (dot dot) in arguments to (1) file_editor.asp, (2) folderactions.asp, or (3) editoractions.asp.

CVSS2: 6.4
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0463

home.php in ARSC (Really Simple Chat) 1.0.1 and earlier allows remote attackers to determine the full pathname of the web server via an invalid language in the arsc_language parameter, which leaks the pathname in an error message.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0462

bigsam_guestbook.php for Big Sam (Built-In Guestbook Stand-Alone Module) 1.1.08 and earlier allows remote attackers to cause a denial of service (CPU consumption) or obtain the absolute path of the web server via a displayBegin parameter with a very large number, which leaks the web path in an error message when PHP safe_mode is enabled, or consumes resources when safe_mode is not enabled.

CVSS2: 6.4
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0461

Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript in a web page that calls location.replace on itself, causing a loop.

CVSS2: 5
23%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0460

Bitvise WinSSHD before 2002-03-16 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of incomplete connections that are not properly terminated, which are not properly freed by SSHd.

CVSS2: 5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0459

Cross-site scripting vulnerability in Board-TNK 1.3.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter.

CVSS2: 7.6
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0458

Cross-site scripting vulnerability in News-TNK 1.2.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter.

CVSS2: 7.6
2%
Низкий
почти 24 года назад

Уязвимостей на страницу