CSV
180,407 results for "vulnerability" Page 33
CVE-2002-0437

Smsd in SMS Server Tools (SMStools) before 1.4.8 allows remote attackers to execute arbitrary commands via shell metacharacters (backquotes) in message text, as described with the term "string format vulnerability" by some sources.

Jul 26, 2002 2 affected product(s) NVD
10.0
CVSS
3.4%
EPSS
⚡ 41
CVE-2002-0187

Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root parameter as part of an XML SQL query, aka "Script Injection via XML Tag."

Jul 3, 2002 3 affected product(s) NVD
7.5
CVSS
13.9%
EPSS
⚡ 34.2
CVE-2002-0682

Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.

Jul 23, 2002 1 affected product(s) NVD
7.5
CVSS
12.2%
EPSS
⚡ 33.7
CVE-2002-0573

Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.

Jul 3, 2002 6 affected product(s) NVD
7.5
CVSS
9.2%
EPSS
⚡ 32.8
CVE-2002-0316

Cross-site scripting vulnerability in eXtreme message board (XMB) 1.6x and earlier allows remote attackers to execute script as other XMB users by inserting the script into an IMG tag.

Jun 25, 2002 1 affected product(s) NVD
7.5
CVSS
8.7%
EPSS
⚡ 32.6
CVE-2002-0681

Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that generates a "404 not found" message, which does not quote the script.

Jul 23, 2002 5 affected product(s) NVD
7.5
CVSS
8.3%
EPSS
⚡ 32.5
CVE-2002-0330

Cross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to execute arbitrary script and steal cookies via Javascript in the IMG tag.

Jun 25, 2002 3 affected product(s) NVD
7.5
CVSS
7.9%
EPSS
⚡ 32.4
CVE-2002-0319

Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other users via Javascript in a username.

Jun 25, 2002 4 affected product(s) NVD
7.5
CVSS
7.2%
EPSS
⚡ 32.2
CVE-2002-0346

Cross-site scripting vulnerability in Cobalt RAQ 4 allows remote attackers to execute arbitrary script as other Cobalt users via Javascript in a URL to (1) service.cgi or (2) alert.cgi.

Jun 25, 2002 3 affected product(s) NVD
7.5
CVSS
6.5%
EPSS
⚡ 31.9
CVE-2002-0328

Cross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonboard users and steal cookies via Javascript in an IMG tag.

Jun 25, 2002 2 affected product(s) NVD
7.5
CVSS
5.4%
EPSS
⚡ 31.6
CVE-2002-0329

Cross-site scripting vulnerability in Snitz Forums 2000 3.3.03 and earlier allows remote attackers to execute arbitrary script as other Forums 2000 users via Javascript in an IMG tag.

Jun 25, 2002 6 affected product(s) NVD
7.5
CVSS
4.9%
EPSS
⚡ 31.5
CVE-2002-0325

Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the URL.

Jun 25, 2002 2 affected product(s) NVD
5.0
CVSS
37.8%
EPSS
⚡ 31.3
CVE-2002-0551

Cross-site scripting vulnerability in Dynamic Guestbook 3.0 allows remote attackers to execute code in clients who access guestbook pages via the parameters (1) name, (2) mail, or (3) kommentar.

Jul 3, 2002 1 affected product(s) NVD
7.5
CVSS
3.6%
EPSS
⚡ 31.1
CVE-2002-0683

Directory traversal vulnerability in Carello 1.3 allows remote attackers to execute programs on the server via a .. (dot dot) in the VBEXE parameter.

Jul 23, 2002 1 affected product(s) NVD
7.5
CVSS
3.7%
EPSS
⚡ 31.1
CVE-2002-0586

Format string vulnerability in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to execute arbitrary code via the Error or Notice parameters.

Jun 18, 2002 9 affected product(s) NVD
7.5
CVSS
2.9%
EPSS
⚡ 30.9
CVE-2002-0598

Format string vulnerability in Foundstone FScan 1.12 with banner grabbing enabled allows remote attackers to execute arbitrary code on the scanning system via format string specifiers in the server banner.

Jun 18, 2002 1 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2002-0553

Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by injecting the script into fields during new customer registration.

Jul 3, 2002 6 affected product(s) NVD
7.5
CVSS
2.9%
EPSS
⚡ 30.9
CVE-2002-0590

Cross-site scripting (CSS) vulnerability in IcrediBB 1.1 Beta allows remote attackers to execute arbitrary script and steal cookies as other IcrediBB users via the (1) title or (2) body of posts.

Jun 18, 2002 1 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2002-0610

Vulnerability in FTPSRVR in HP MPE/iX 6.0 through 7.0 does not properly validate certain FTP commands, which allows attackers to gain privileges.

Jun 18, 2002 3 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2002-0326

Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to execute arbitrary script and possibly additional commands via a URL that contains Javascript.

Jun 25, 2002 5 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5