5
    Medium

    CVE-2002-1830

    Last Modified: 23 Sept 2012

    Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via a direct request to moderator.php with the action and ismod parameters.

    Source:frog
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1829

    Last Modified: 23 Sept 2012

    Cross-site scripting (XSS) vulnerability in codeparse.php in Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to inject arbitrary web script or HTML via (1) myhome.php, (2) an onerror attribute in an IMG tag (a variant of CVE-2002-0330), or (3) a glow tag.

    Source:frog
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1828

    Last Modified: 7 Oct 2012

    Savant Webserver 3.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request with a negative Content-Length value.

    Source:Auriemma Luigi
    Published:31 Dec 2002
    2.1
    Low

    CVE-2002-1827

    Last Modified: 15 Nov 2017

    Sendmail 8.9.0 through 8.12.3 allows local users to cause a denial of service by obtaining an exclusive lock on the (1) alias, (2) map, (3) statistics, and (4) pid files.

    Source:zillion
    Published:31 Dec 2002
    4.6
    Medium

    CVE-2002-1826

    Last Modified: 4 Sept 2016

    grsecurity 1.9.4 for Linux kernel 2.4.18 allows local users to bypass read-only permissions by using mmap to directly map /dev/mem or /dev/kmem to kernel memory.

    Source:Guillaume PELAT
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1823

    Last Modified: 16 Oct 2012

    Buffer overflow in the HttpGetRequest function in Zeroo HTTP server 1.5 allows remote attackers to execute arbitrary code via a long HTTP request.

    Source:dong-h0un U
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1818

    Last Modified: 16 Oct 2012

    ezhttpbench.php in eZ httpbench 1.1 allows remote attackers to read arbitrary files via a full pathname in the AnalyseSite parameter.

    Source:Tacettin Karadeniz
    Published:31 Dec 2002
    9.8
    Critical

    CVE-2002-1816

    Last Modified: 13 Oct 2012

    Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Source:thread
    Published:31 Dec 2002
    4.6
    Medium

    CVE-2002-1814

    Last Modified: 28 Sept 2012

    Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long command line arguments.

    Source:clorox
    Published:31 Dec 2002
    2.6
    Low

    CVE-2002-1813

    Last Modified: 14 Oct 2012

    Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8.2790 allows remote attackers to execute arbitrary programs by specifying the program in the href attribute of a link.

    Source:Blud Clot
    Published:31 Dec 2002
    7.2
    High

    CVE-2002-1812

    Last Modified: 6 Oct 2012

    Buffer overflow in gdam123 0.933 and 0.942 allows local users to execute arbitrary code via a long filename parameter.

    Source:Netric Security
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1811

    Last Modified: 6 Oct 2012

    Belkin F5D6130 Wireless Network Access Point running firmware AP14G8 allows remote attackers to cause a denial of service (connection loss) by sending several SNMP GetNextRequest requests.

    Source:wlanman
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1809

    Last Modified: 6 Sept 2016

    The default configuration of the Windows binary release of MySQL 3.23.2 through 3.23.52 has a NULL root password, which could allow remote attackers to gain unauthorized root access to the MySQL database.

    Source:g0thm0g
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1806

    Last Modified: 9 Oct 2012

    Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1805

    Last Modified: 9 Oct 2012

    Cross-site scripting (XSS) vulnerability in DaCode 1.2.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1804

    Last Modified: 9 Oct 2012

    Cross-site scripting (XSS) vulnerability in NPDS 4.8 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1803

    Last Modified: 9 Oct 2012

    Cross-site scripting (XSS) vulnerability in PHP-Nuke 6.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1802

    Last Modified: 9 Oct 2012

    Cross-site scripting (XSS) vulnerability in Xoops 1.0 RC3 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag when submitting news.

    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1799

    Last Modified: 10 Oct 2017

    Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) email parameter to add.php or (2) banurl parameter.

    Source:Jedi/Sector One
    Published:31 Dec 2002
    9.1
    Critical

    CVE-2002-1798

    Last Modified: 27 Oct 2016

    MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.php.

    Source:frog
    Published:31 Dec 2002
    10
    Critical

    CVE-2002-1792

    Last Modified: 2 Oct 2012

    Buffer overflow in Fake Identd 0.9 through 1.4 allows remote attackers to execute arbitrary code as root via a long request that is split into multiple packets.

    Source:Jedi/Sector
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1790

    Last Modified: 30 Sept 2012

    The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and send spam or spoofed messages via encapsulated SMTP addresses, a similar vulnerability to CVE-1999-0682.

    Source:JWC
    Published:31 Dec 2002
    1.9
    Low

    CVE-2002-1785

    Last Modified: 15 Oct 2012

    Cross-site scripting (XSS) vulnerability in Zeus Administration Server in Zeus Web Server 4.0 through 4.1r2 allows remote authenticated users to inject arbitrary web script or HTML via the section parameter to index.fcgi.

    Source:euronymous
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1773

    Last Modified: 12 Sept 2012

    Buffer overflow in ICQ 2.6x for MacOS X 10.0 through 10.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long request.

    Source:Stephen
    Published:31 Dec 2002
    7.2
    High

    CVE-2002-1767

    Last Modified: 20 Oct 2017

    Buffer overflow in tnslsnr of Oracle 8i Database Server 8.1.5 for Linux allows local users to execute arbitrary code as the oracle user via a long command line argument.

    Source:the itch
    Published:31 Dec 2002
    4.6
    Medium

    CVE-2002-1766

    Last Modified: 26 Sept 2012

    Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code via a font tag with a long face attribute.

    Source:S[h]iff
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1757

    Last Modified: 21 Sept 2012

    PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for scripts via a request to a .php file with "sms" in the URL, which is included in the PATH_INFO portion of the $PHP_SELF variable, as demonstrated using "mail_send.php/sms".

    Source:Ulf Harnhammar
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1744

    Last Modified: 19 Sept 2012

    Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and determine the existence of arbitrary files via a hex-encoded "%c0%ae%c0%ae" string, which is the Unicode representation for ".." (dot dot).

    Source:H D Moore
    Published:31 Dec 2002
    7.2
    High

    CVE-2002-1741

    Last Modified: 21 Sept 2012

    Directory traversal vulnerability in WorldClient.cgi in WorldClient for Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to delete arbitrary files via a ".." (dot dot) in the Attachments parameter.

    Source:Obscure
    Published:31 Dec 2002
    2.1
    Low

    CVE-2002-1740

    Last Modified: 22 Sept 2012

    Buffer overflow in WorldClient.cgi in WorldClient in Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to execute arbitrary code via a long folder name (NewFolder parameter).

    Source:Obscure
    Published:31 Dec 2002
    2.1
    Low

    CVE-2002-1731

    Last Modified: 12 Sept 2012

    The System Request menu in IBM AS/400 allows local users to list valid user accounts by viewing the object names that are type USRPRF.

    Source:ken@FTU
    Published:31 Dec 2002
    6.8
    Medium

    CVE-2002-1727

    Last Modified: 21 Sept 2012

    Cross-site scripting vulnerability (XSS) in (1) as_web.exe and (2) as_web4.exe in askSam Web Publisher 1 and 4 allows remote attackers to execute arbitrary script as other users via a URL.

    Source:frog
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1720

    Last Modified: 21 Sept 2012

    SQL injection vulnerability in Spooky Login 2.0 through 2.5 allows remote attackers to bypass authentication and gain privileges via the password field.

    Source:anonymous
    Published:31 Dec 2002
    7.2
    High

    CVE-2002-1715

    Last Modified: 26 Aug 2018

    SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable directory, then executing that script to gain normal shell access.

    Source:A.Dimitrov
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1714

    Last Modified: 20 Sept 2012

    Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object of type "text/html" with the DATA field that identifies the HTML document that contains the object, which may cause infinite recursion.

    Source:Matthew Murphy
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1712

    Last Modified: 11 Sept 2012

    Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FIN bits set to the NetBIOS port (TCP/139), as demonstrated by stream3.

    Source:3APA3A
    Published:31 Dec 2002
    6.8
    Medium

    CVE-2002-1708

    Last Modified: 28 Sept 2012

    Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting script into the (1) subject or (2) message fields.

    Source:Ulf Harnhammar
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1705

    Last Modified: 27 Sept 2012

    Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading Style Sheet (CSS) with the p{cssText} element declared and a bold font weight.

    Source:Oleg A. Cheremisin
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1704

    Last Modified: 27 Sept 2012

    Zeroboard 4.1, when the "allow_url_fopen" and "register_globals" variables are enabled, allows remote attackers to execute arbitrary PHP code by modifying the _zb_path parameter to reference a URL on a remote web server that contains the code.

    Source:onlooker
    Published:31 Dec 2002
    6.8
    Medium

    CVE-2002-1703

    Last Modified: 27 Sept 2012

    Cross-site scripting vulnerability (XSS) in auction.cgi for Mewsoft NetAuction 3.0 allows remote attackers to execute arbitrary script as other users via the Term parameter.

    Source:windows-1256
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1702

    Last Modified: 27 Sept 2012

    Cross-site scripting vulnerability (XSS) in DeltaScripts PHP Classifieds 6.0.5 allows remote attackers to execute arbitrary script as other users via the URL parameter.

    Source:windows-1256
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1700

    Last Modified: 27 Sept 2012

    Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.

    Source:Macromedia
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1688

    Last Modified: 19 Sept 2012

    The browser history feature in Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to execute arbitrary script as other users and steal authentication information via cookies by injecting JavaScript into the URL, which is executed when the user hits the Back button.

    Source:Andreas Sandblad
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1685

    Last Modified: 28 Sept 2012

    Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into ext.dll ISAPI.

    Source:Matthew Murphy
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-1683

    Last Modified: 29 Sept 2012

    Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function.

    Source:Matthew Murphy
    Published:31 Dec 2002
    3.6
    Low

    CVE-2002-1673

    Last Modified: 17 Sept 2012

    The web interface for Webmin 0.92 does not properly quote or filter script code in files that are displayed to the interface, which allows local users to execute script and possibly steal cookies by inserting the script into certain files or fields, such as a real user name entry in the passwd file.

    Source:prophecy
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-1663

    Last Modified: 14 Oct 2012

    The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a POST request with an invalid or missing Content-Length header value.

    Source:anonymous
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1660

    Last Modified: 10 Oct 2012

    calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.

    Source:gosper
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1656

    Last Modified: 20 Sept 2016

    X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the password, e.g. via sniffing or the users.txt data file, and providing it in a cookie.

    Source:bd0rk
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-1652

    Last Modified: 15 Oct 2012

    Buffer overflow in cgicso.c for cgiemail 1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long query parameter.

    Source:isox
    Published:31 Dec 2002