10
    Critical

    CVE-2002-0613

    Last Modified: 21 Sept 2012

    dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user_logged_in or user_dnstools_administrator parameters.

    Source:ppp-design
    Published:18 Jun 2002
    7.5
    High

    CVE-2002-0612

    Last Modified: 25 Oct 2012

    FileSeek.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) head or (2) foot parameters.

    Source:Thijs Bosschert
    Published:11 Jun 2002
    5
    Medium

    CVE-2002-0611

    Last Modified: 25 Oct 2012

    Directory traversal vulnerability in FileSeek.cgi allows remote attackers to read arbitrary files via a ....// (modified dot dot) in the (1) head or (2) foot parameters, which are not properly filtered.

    Source:Thijs Bosschert
    Published:11 Jun 2002
    7.5
    High

    CVE-2002-0608

    Last Modified: 20 Sept 2012

    Buffer overflow in Matu FTP client 1.74 allows remote FTP servers to execute arbitrary code via a long "220" banner.

    Source:Kanatoko
    Published:11 Jun 2002
    7.5
    High

    CVE-2002-0607

    Last Modified: 19 Sept 2012

    members.asp in Snitz Forums 2000 version 3.3.03 and earlier allows remote attackers to execute arbitrary code via a SQL injection attack on the parameters (1) M_NAME, (2) UserName, (3) FirstName, (4) LastName, or (5) INITIAL.

    Source:acemi
    Published:11 Jun 2002
    7.5
    High

    CVE-2002-0606

    Last Modified: 21 Sept 2012

    Buffer overflow in 3Cdaemon 2.0 FTP server allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long commands such as login.

    Source:MaD SKiLL
    Published:11 Jun 2002
    10
    Critical

    CVE-2002-0599

    Last Modified: 21 Sept 2012

    Blahz-DNS 0.2 and earlier allows remote attackers to bypass authentication and modify configuration by directly requesting CGI programs such as dostuff.php instead of going through the login screen.

    Source:ppp-design
    Published:18 Jun 2002
    5
    Medium

    CVE-2002-0597

    Last Modified: 19 Sept 2012

    LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of malformed data to microsoft-ds port 445.

    Source:Daniel Nystrom
    Published:18 Jun 2002
    7.5
    High

    CVE-2002-0595

    Last Modified: 19 Sept 2012

    Buffer overflow in WTRS_UI.EXE (WTX_REMOTE.DLL) for WebTrends Reporting Center 4.0d allows remote attackers to execute arbitrary code via a long HTTP GET request to the /reports/ directory.

    Source:Mark Litchfield
    Published:11 Jun 2002
    5
    Medium

    CVE-2002-0591

    Last Modified: 19 Sept 2012

    Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute commands via a Direct Connection with an IMG tag with a SRC attribute that specifies the target filename.

    Source:Noah Johnson
    Published:11 Jun 2002
    7.5
    High

    CVE-2002-0590

    Last Modified: 19 Sept 2012

    Cross-site scripting (CSS) vulnerability in IcrediBB 1.1 Beta allows remote attackers to execute arbitrary script and steal cookies as other IcrediBB users via the (1) title or (2) body of posts.

    Source:Daniel Nyström
    Published:11 Jun 2002
    7.5
    High

    CVE-2002-0589

    Last Modified: 19 Sept 2012

    PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with the newpass and confirm parameters both set to the new password.

    Source:Daniel Nyström
    Published:11 Jun 2002
    5
    Medium

    CVE-2002-0588

    Last Modified: 19 Sept 2012

    PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.

    Source:Daniel Nyström
    Published:11 Jun 2002
    7.5
    High

    CVE-2002-0575

    Last Modified: 23 Sept 2012

    Buffer overflow in OpenSSH before 2.9.9, and 3.x before 3.2.1, with Kerberos/AFS support and KerberosTgtPassing or AFSTokenPassing enabled, allows remote and local authenticated users to gain privileges.

    Source:Marcell Fodor
    Published:18 Jun 2002
    7.2
    High

    CVE-2002-0572

    Last Modified: 20 Sept 2012

    FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.

    Source:phased
    Published:11 Jun 2002
    7.5
    High

    CVE-2002-0554

    Last Modified: 18 Sept 2012

    webdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary files via a SQL injection attack in an HTTP request.

    Source:Simon Lodal
    Published:11 Jun 2002
    7.5
    High

    CVE-2002-0553

    Last Modified: 19 Sept 2012

    Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by injecting the script into fields during new customer registration.

    Source:ppp-design
    Published:3 Jul 2002
    7.5
    High

    CVE-2002-0552

    Last Modified: 19 Sept 2012

    Multiple buffer overflows in Melange Chat server 2.02 allow remote or local attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long argument in the /yell command, (2) long lines in the /etc/melange.conf configuration file, (3) long file names, or possibly other attacks.

    Source:DVDMAN
    Published:11 Jun 2002
    7.2
    High

    CVE-2002-0544

    Last Modified: 18 Sept 2012

    Aprelium Abyss Web Server (abyssws) before 1.0.3 stores the administrative console password in plaintext in the abyss.conf file, which allows local users with access to the file to gain privileges.

    Source:Jeremy Roberts
    Published:11 Jun 2002
    5
    Medium

    CVE-2002-0543

    Last Modified: 18 Sept 2012

    Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read files outside the web root, including the abyss.conf file, via URL-encoded .. (dot dot) sequences in the HTTP request.

    Source:Jeremy Roberts
    Published:3 Jul 2002
    7.2
    High

    CVE-2002-0542

    Last Modified: 2 Nov 2017

    mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow local users to gain root privileges via calls to mail in cron.

    Source:Przemyslaw Frasunek
    Published:3 Jul 2002
    7.5
    High

    CVE-2002-0540

    Last Modified: 19 Sept 2012

    Nortel CVX 1800 is installed with a default "public" community string, which allows remote attackers to read usernames and passwords and modify the CVX configuration.

    Source:Michael Rawls
    Published:11 Jun 2002
    10
    Critical

    CVE-2002-0539

    Last Modified: 19 Sept 2012

    Demarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session ID that is stored in the s_key cookie.

    Source:pokleyzz sakamaniaka
    Published:3 Jul 2002
    7.5
    High

    CVE-2002-0536

    Last Modified: 18 Sept 2012

    PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the database via a SQL injection attack.

    Source:Matthias Jordan
    Published:3 Jul 2002
    5
    Medium

    CVE-2002-0535

    Last Modified: 19 Sept 2012

    Cross-site scripting vulnerabilities in PostBoard 2.0.1 and earlier allows remote attackers to execute script as other users via (1) an [IMG] tag when BBCode is enabled, or (2) in a topic title.

    Source:gcsb
    Published:11 Jun 2002
    10
    Critical

    CVE-2002-0525

    Last Modified: 23 Sept 2012

    Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses.

    Source:Paul Starzetz
    Published:11 Jun 2002
    10
    Critical

    CVE-2002-0516

    Last Modified: 18 Sept 2012

    SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cookie.

    Source:pokleyzz sakamaniaka
    Published:12 Aug 2002
    7.5
    High

    CVE-2002-0504

    Last Modified: 17 Sept 2012

    Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp.

    Source:Eric Detoisien
    Published:11 Jun 2002
    5
    Medium

    CVE-2002-0502

    Last Modified: 10 Sept 2012

    Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.

    Source:Ian Vitek
    Published:11 Jun 2002
    2.1
    Low

    CVE-2002-0499

    Last Modified: 17 Sept 2012

    The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.

    Source:cliph
    Published:11 Jun 2002
    10
    Critical

    CVE-2002-0495

    Last Modified: 17 Sept 2012

    csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file that is loaded by csSearch.cgi.

    Source:Steve Gustin
    Published:12 Aug 2002
    5
    Medium

    CVE-2002-0492

    Last Modified: 17 Sept 2012

    dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.

    Source:pokleyzz sakamaniaka
    Published:11 Jun 2002
    7.2
    High

    CVE-2002-0486

    Last Modified: 17 Sept 2012

    Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the cookies to gain privileges.

    Source:c3rb3r
    Published:11 Jun 2002
    5
    Medium

    CVE-2002-0484

    Last Modified: 2 Dec 2016

    move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system.

    Source:Tozz
    Published:12 Aug 2002
    5
    Medium

    CVE-2002-0483

    Last Modified: 17 Sept 2012

    index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that leaks the pathname.

    Source:godminus
    Published:11 Jun 2002
    4.6
    Medium

    CVE-2002-0468

    Last Modified: 17 Sept 2012

    Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privileges via (1) a long command line argument, which is not properly handled in core.c, or possibly via bad uses of sprintf() in (2) moderate.c, (3) lcgi.c, (4) fileapi.c, (5) cookie.c, (6) codes.c, or other files.

    Source:the itch
    Published:11 Jun 2002
    5
    Medium

    CVE-2002-0461

    Last Modified: 17 Sept 2012

    Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript in a web page that calls location.replace on itself, causing a loop.

    Source:Patrik Birgersson
    Published:11 Jun 2002
    5
    Medium

    CVE-2002-0454

    Last Modified: 17 Sept 2012

    Qpopper (aka in.qpopper or popper) 4.0.3 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a very large string, which causes an infinite loop.

    Source:Jonas Frey
    Published:12 Aug 2002
    7.5
    High

    CVE-2002-0451

    Last Modified: 17 Sept 2012

    filemanager_forms.php in PHProjekt 3.1 and 3.1a allows remote attackers to execute arbitrary PHP code by specifying the URL to the code in the lib_path parameter.

    Source:b0iler
    Published:12 Aug 2002
    5
    Medium

    CVE-2002-0448

    Last Modified: 17 Sept 2012

    Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many "C:/" sequences.

    Source:Alex Hernandez
    Published:11 Jun 2002
    7.5
    High

    CVE-2002-0440

    Last Modified: 17 Sept 2012

    Trend Micro InterScan VirusWall HTTP proxy 3.6 with the "Skip scanning if Content-length equals 0" option enabled allows malicious web servers to bypass content scanning via a Content-length header set to 0, which is often ignored by HTTP clients.

    Source:Jochen Thomas Bauer
    Published:11 Jun 2002
    10
    Critical

    CVE-2002-0436

    Last Modified: 17 Sept 2012

    sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shell metacharacters in the email address parameter.

    Source:Fyodor
    Published:11 Jun 2002
    5
    Medium

    CVE-2002-0431

    Last Modified: 17 Sept 2012

    XTux allows remote attackers to cause a denial of service (CPU consumption) via random inputs in the initial connection.

    Source:b0iler
    Published:26 Jul 2002
    3.7
    Low

    CVE-2002-0430

    Last Modified: 17 Sept 2012

    MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authentication and overwrite arbitrary files via a symlink attack on a temporary file, followed by a request to MultiFileUpload.php.

    Source:Wouter ter Maat
    Published:11 Jun 2002
    5
    Medium

    CVE-2002-0419

    Last Modified: 12 Sept 2012

    Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (2) in certain configurations, the server IP address is provided as the realm for Basic authentication, which could reveal real IP addresses that were obscured by NAT, or (3) when NTLM authentication is used, the NetBIOS name of the server and its Windows NT domain are revealed in response to an Authorization request. NOTE: this entry originally contained a vector (1) in which the server reveals whether it supports Basic or NTLM authentication through 401 Access Denied error messages. CVE has REJECTED this vector; it is not a vulnerability because the information is already available through legitimate use, since authentication cannot proceed without specifying a scheme that is supported by both the client and the server.

    Source:David Litchfield
    Published:11 Jun 2002
    7.5
    High

    CVE-2002-0413

    Last Modified: 12 Sept 2012

    Cross-site scripting vulnerability in ReBB allows remote attackers to execute arbitrary Javascript and steal cookies via an IMG tag whose URL includes the malicious script.

    Source:skizzik
    Published:11 Jun 2002
    5
    Medium

    CVE-2002-0406

    Last Modified: 17 Sept 2012

    Menasoft SPHERE server 0.99x and 0.5x allows remote attackers to cause a denial of service by establishing a large number of connections to the server without providing login credentials, which prevents other users from being able to log in.

    Source:H Zero Seven
    Published:26 Jul 2002
    7.5
    High

    CVE-2002-0392

    Last Modified: 27 Sept 2012

    Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.

    Source:Gobbles Security
    Published:17 Jun 2002
    7.5
    High

    CVE-2002-0388

    Last Modified: 23 Sept 2012

    Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or (2) the Pipermail index summaries.

    Source:office
    Published:20 May 2002
    5
    Medium

    CVE-2002-0386

    Last Modified: 11 Oct 2012

    The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cause a denial of service (crash) via (1) an HTTP GET request containing a ".." (dot dot) sequence, or (2) a malformed HTTP GET request with a chunked Transfer-Encoding with missing data.

    Source:@stake
    Published:29 Oct 2002