7.5
    High

    CVE-2002-2029

    Last Modified: 19 Dec 2016

    PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.

    Source:Paul Brereton
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2026

    Last Modified: 9 Sept 2012

    Buffer overflow in BrowseFTP 1.62 client allows remote FTP servers to execute arbitrary code via a long FTP "220" message reply.

    Source:Kanatoko
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2021

    Last Modified: 19 Sept 2012

    Cross-site scripting (XSS) vulnerability in WoltLab Burning Board (wbboard) 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Source:SeazoN
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2019

    Last Modified: 27 Sept 2012

    PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote attackers to execute arbitrary PHP code via the include_file parameter.

    Source:Tim Vandermeerch
    Published:31 Dec 2002
    7.2
    High

    CVE-2002-2016

    Last Modified: 4 Sept 2016

    User-mode Linux (UML) 2.4.17-8 does not restrict access to kernel address space, which allows local users to execute arbitrary code.

    Source:Andrew Griffiths
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2015

    Last Modified: 18 Sept 2012

    PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute code via the caselist parameter.

    Source:pokleyzz sakamaniaka
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2011

    Last Modified: 20 Sept 2012

    Cross-site scripting (XSS) vulnerability in the fom CGI program (fom.cgi) in Faq-O-Matic 2.711 and 2.712 allows remote attackers to inject arbitrary web script or HTML via the file parameter.

    Source:BrainRawt
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2007

    Last Modified: 11 Jul 2017

    The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.

    Source:Richard Brain
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2006

    Last Modified: 20 Sept 2012

    The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.

    Source:CHINANSL Security Team
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1995

    Last Modified: 9 Sept 2012

    Cross-site scripting (XSS) vulnerability in phptonuke.php for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the filnavn parameter.

    Source:frog
    Published:31 Dec 2002
    10
    Critical

    CVE-2002-1993

    Last Modified: 28 Sept 2012

    webbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the followup parameter.

    Source:NERF Security
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1991

    Last Modified: 27 Sept 2012

    PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.

    Source:Tim Vandermeerch
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1986

    Last Modified: 16 Oct 2012

    Perception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP request with a trailing dot (".").

    Source:mattmurphy
    Published:31 Dec 2002
    2.1
    Low

    CVE-2002-1983

    Last Modified: 6 Nov 2017

    The timer implementation in QNX RTOS 6.1.0 allows local users to cause a denial of service (hang) and possibly execute arbitrary code by creating multiple timers with a 1-ms tick.

    Source:Pawel Pisarczyk
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1982

    Last Modified: 29 Sept 2012

    Directory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote attackers to determine if a directory exists via a .. (dot dot) in the GET request, which returns different error messages depending on whether the directory exists or not.

    Source:glaive
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1973

    Last Modified: 29 Sept 2012

    Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote attackers to cause a denial of service (access violation and crash) and possibly execute arbitrary code via a long query string that causes a parsing error.

    Source:Matthew Murphy
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1966

    Last Modified: 21 Nov 2016

    Directory traversal vulnerability in magiccard.cgi in My Postcards Platinum 5.0 and 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.

    Source:cult
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1965

    Last Modified: 27 Sept 2012

    Cross-site scripting (XSS) vulnerability in Errors.gsl in Imatix Xitami 2.5b4 and 2.5b5 allows remote attackers to inject arbitrary web script or HTML via the (1) Javascript events, as demonstrated via an onerror event in an IMG SRC tag or (2) User-Agent field in an HTTP GET request.

    Source:Matthew Murphy
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1958

    Last Modified: 14 Oct 2012

    Cross-site scripting (XSS) vulnerability in kmMail 1.0, 1.0a, and 1.0b allows remote attackers to inject arbitrary web script or HTML via (1) javascript in onmouseover or other attributes in "safe" HTML tags such as the "b" tag, or (2) the Subject field.

    Source:Ulf Harnhammar
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1954

    Last Modified: 12 Oct 2017

    Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php.

    Source:Matthew Murphy
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1951

    Last Modified: 3 Oct 2012

    Buffer overflow in GoAhead WebServer 2.1 allows remote attackers to execute arbitrary code via a long HTTP GET request with a large number of subdirectories.

    Source:anonymous
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1945

    Last Modified: 14 Oct 2012

    Buffer overflow in SmartMail Server 1.0 Beta 10 allows remote attackers to cause a denial of service (crash) via a long request to (1) TCP port 25 (SMTP) or (2) TCP port 110 (POP3).

    Source:securma massine
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1943

    Last Modified: 10 Oct 2012

    SafeTP 1.46, when network address translation (NAT) is being used, leaks the internal IP address of the FTP server in a response to a passive mode (PASV) file transfer request.

    Source:Jonathan G. Lampe
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1930

    Last Modified: 11 Jul 2017

    Buffer overflow in AN HTTPd 1.38 through 1.4.1c allows remote attackers to execute arbitrary code via a SOCKS4 request with a long username.

    Source:Kanatoko
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1929

    Last Modified: 14 Oct 2012

    Cross-site scripting (XSS) vulnerability in pafiledb.php in PHP Arena paFileDB 1.1.3 through 3.0 allows remote attackers to inject arbitrary web script or HTML via the query string in the (1) rate, (2) email, or (3) download actions.

    Source:ersatz
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1922

    Last Modified: 13 Oct 2012

    Cross-site scripting (XSS) vulnerability in global.php in Jelsoft vBulletin 2.0.0 through 2.2.8 allows remote attackers to inject arbitrary web script or HTML via the (1) $scriptpath or (2) $url variables.

    Source:Sp.IC
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1911

    Last Modified: 13 Oct 2012

    ZoneAlarm Pro 3.0 and 3.1, when configured to block all traffic, allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of SYN packets (SYN flood). NOTE: the vendor was not able to reproduce the issue.

    Source:Abraham Lincoln
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1910

    Last Modified: 13 Oct 2012

    Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtain passwords.

    Source:Brian Enigma
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1907

    Last Modified: 13 Oct 2012

    TelCondex SimpleWebServer 2.06.20817 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.

    Source:Marc Ruef
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1906

    Last Modified: 13 Oct 2012

    The web server for Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (CPU consumption) by sending incomplete HTTP requests and leaving the connections open.

    Source:prophecy.net.nz
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1905

    Last Modified: 13 Oct 2012

    Buffer overflow in the web server of Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.

    Source:prophecy.net.nz
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1904

    Last Modified: 30 Aug 2012

    Buffer overflow in the Log function in util.c in GazTek ghttpd 1.4 through 1.4.3 allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Source:qitest1
    Published:31 Dec 2002
    7.2
    High

    CVE-2002-1898

    Last Modified: 9 Oct 2012

    Terminal 1.3 in Apple Mac OS X 10.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a telnet:// link, which is executed by Terminal.app window.

    Source:Taiyo Fujii
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1897

    Last Modified: 29 Sept 2016

    MyWebServer LLC MyWebServer 1.0.2 allows remote attackers to cause a denial of service (crash) via a long HTTP request, possibly triggering a buffer overflow.

    Source:Marc Ruef
    Published:31 Dec 2002
    7.2
    High

    CVE-2002-1896

    Last Modified: 8 Oct 2012

    Buffer overflow in Alsaplayer 0.99.71, when installed setuid root, allows local users to execute arbitrary code via a long (1) -f or (2) -o command line argument.

    Source:zillion
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1891

    Last Modified: 26 Sept 2012

    Buffer overflow in IRCIT 0.3.1 IRC client allows remote attackers to execute arbitrary code via a long invite request.

    Source:gobbles
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1887

    Last Modified: 15 Nov 2016

    PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l parameter.

    Source:frog-m@n
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1886

    Last Modified: 11 Oct 2012

    TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain the database username and password.

    Source:frog
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1885

    Last Modified: 5 Dec 2016

    PHP remote file inclusion vulnerability in showhits.php3 for PowerPhlogger (PPhlogger) 2.0.9 through 2.2.2 allows remote attackers to execute arbitrary PHP code via the rel_path parameter.

    Source:x_w0x
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1884

    Last Modified: 11 Oct 2012

    index.php in Py-Membres 3.1 allows remote attackers to log in as an administrator by setting the pymembs parameter to "admin".

    Source:frog
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1878

    Last Modified: 26 Sept 2012

    PHP remote file inclusion vulnerability in w-Agora 4.1.3 allows remote attackers to execute arbitrary PHP code via the inc_dir parameter.

    Source:frog
    Published:31 Dec 2002
    10
    Critical

    CVE-2002-1868

    Last Modified: 3 Oct 2012

    Dispair 0.1 and 0.2 allows remote attackers to execute arbitrary shell commands via certain form fields.

    Source:anonymous
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1865

    Last Modified: 14 Oct 2012

    Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (2) Linksys Etherfast BEFW11S4 Wireless AP + Cable/DSL Router 1.37.2 through 1.42.7 and Linksys WAP11 1.3 and 1.4, allows remote attackers to cause a denial of service (crash) via a long header, as demonstrated using the Host header.

    Source:Mark Litchfield
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1862

    Last Modified: 14 Oct 2012

    SmartMail Server 2.0 allows remote attackers to cause a denial of service (crash) by sending data and closing the connection before all the data has been sent.

    Source:securma massine
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1852

    Last Modified: 10 Oct 2012

    Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) a parameter to test2.pl.

    Source:DownBload
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1850

    Last Modified: 9 Oct 2012

    mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.

    Source:K.C. Wong
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1847

    Last Modified: 2 Oct 2012

    Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a long mp3 filename command line argument. NOTE: since the only known attack vector requires command line access, this may not be a vulnerability.

    Source:ken@FTU
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1845

    Last Modified: 14 Oct 2012

    Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter.

    Source:Nir Adar
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1837

    Last Modified: 23 Sept 2012

    The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on whether the directory exists or not.

    Source:isox
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1831

    Last Modified: 23 Sept 2012

    Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field.

    Source:Beck Mr.R
    Published:31 Dec 2002