Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 863

Количество 371 863

nvd логотип

CVE-2001-1235

почти 25 лет назад

pSlash PHP script 0.7 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir variable.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1234

почти 25 лет назад

Bharat Mediratta Gallery PHP script before 1.2.1 allows remote attackers to execute arbitrary code by including files from remote web sites via an HTTP request that modifies the includedir variable.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1233

почти 25 лет назад

Netware Enterprise Web Server 5.1 running GroupWise WebAccess 5.5 with Novell Directory Services (NDS) enabled allows remote attackers to enumerate user names, group names and other system information by accessing ndsobj.nlm.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1232

почти 25 лет назад

GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary directory contents via an HTTP request with a lowercase "get".

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1231

почти 25 лет назад

GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1230

больше 25 лет назад

Buffer overflows in Icecast before 1.3.10 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1229

больше 25 лет назад

Buffer overflows in (1) Icecast before 1.3.9 and (2) libshout before 1.0.4 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1228

больше 24 лет назад

Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1227

почти 25 лет назад

Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1226

больше 24 лет назад

AdCycle 1.17 and earlier allow remote attackers to modify SQL queries, which are not properly sanitized before being passed to the MySQL database.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1225

больше 24 лет назад

Hughes Technology Mini SQL 2.0.10 through 2.0.12 allows local users to cause a denial of service by creating a very large array in a table, which causes miniSQL to crash when the table is queried.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1224

больше 24 лет назад

get_input in adrotate.pm for Les VanBrunt AdRotate Pro 2.0 allows remote attackers to modify the database and possibly execute arbitrary commands via a SQL code injection attack.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2001-1223

больше 24 лет назад

The web administration server for ELSA Lancom 1100 Office does not require authentication, which allows arbitrary remote attackers to gain administrative privileges by connecting to the server.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2001-1222

больше 24 лет назад

Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP address and a valid account name for the domain.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1221

больше 24 лет назад

D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point uses a default SNMP community string of 'public' which allows remote attackers to gain sensitive information.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1220

больше 24 лет назад

D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point stores the administrative password in plaintext in the default Management Information Base (MIB), which allows remote attackers to gain administrative privileges.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2001-1219

больше 24 лет назад

Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via self.location.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2001-1218

больше 24 лет назад

Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2001-1217

больше 24 лет назад

Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2001-1216

больше 24 лет назад

Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2001-1235

pSlash PHP script 0.7 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir variable.

CVSS2: 7.5
5%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1234

Bharat Mediratta Gallery PHP script before 1.2.1 allows remote attackers to execute arbitrary code by including files from remote web sites via an HTTP request that modifies the includedir variable.

CVSS2: 7.5
4%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1233

Netware Enterprise Web Server 5.1 running GroupWise WebAccess 5.5 with Novell Directory Services (NDS) enabled allows remote attackers to enumerate user names, group names and other system information by accessing ndsobj.nlm.

CVSS2: 5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1232

GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary directory contents via an HTTP request with a lowercase "get".

CVSS2: 5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1231

GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix.

CVSS2: 5
2%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1230

Buffer overflows in Icecast before 1.3.10 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.

CVSS2: 7.5
3%
Низкий
больше 25 лет назад
nvd логотип
CVE-2001-1229

Buffer overflows in (1) Icecast before 1.3.9 and (2) libshout before 1.0.4 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.

CVSS2: 7.5
3%
Низкий
больше 25 лет назад
nvd логотип
CVE-2001-1228

Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server.

CVSS2: 7.5
3%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1227

Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.

CVSS2: 7.5
1%
Низкий
почти 25 лет назад
nvd логотип
CVE-2001-1226

AdCycle 1.17 and earlier allow remote attackers to modify SQL queries, which are not properly sanitized before being passed to the MySQL database.

CVSS2: 5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1225

Hughes Technology Mini SQL 2.0.10 through 2.0.12 allows local users to cause a denial of service by creating a very large array in a table, which causes miniSQL to crash when the table is queried.

CVSS2: 2.1
0%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1224

get_input in adrotate.pm for Les VanBrunt AdRotate Pro 2.0 allows remote attackers to modify the database and possibly execute arbitrary commands via a SQL code injection attack.

CVSS2: 7.5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1223

The web administration server for ELSA Lancom 1100 Office does not require authentication, which allows arbitrary remote attackers to gain administrative privileges by connecting to the server.

CVSS2: 10
3%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1222

Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP address and a valid account name for the domain.

CVSS2: 5
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1221

D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point uses a default SNMP community string of 'public' which allows remote attackers to gain sensitive information.

CVSS2: 5
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1220

D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point stores the administrative password in plaintext in the default Management Information Base (MIB), which allows remote attackers to gain administrative privileges.

CVSS2: 10
2%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1219

Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via self.location.

CVSS2: 5
6%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1218

Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window.

CVSS2: 2.1
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2001-1217

Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.

CVSS2: 5
54%
Средний
больше 24 лет назад
nvd логотип
CVE-2001-1216

Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.

CVSS2: 7.5
9%
Низкий
больше 24 лет назад

Уязвимостей на страницу