CSV
180,944 results for "vulnerability" Page 39
CVE-2002-0840 Exploit

Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.

Oct 11, 2002 47 affected product(s) NVD
6.8
CVSS
95.1%
EPSS
⚡ 65.7
CVE-2002-1217

Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses <frame> and <iframe> domain restrictions.

Oct 28, 2002 4 affected product(s) NVD
7.5
CVSS
49.8%
EPSS
⚡ 44.9
CVE-2002-1058

Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin via .. (dot dot) sequences in the sessionId cookie that point to an alternate session file.

Oct 4, 2002 1 affected product(s) NVD
10.0
CVSS
4.4%
EPSS
⚡ 41.3
CVE-2002-0951

SQL injection vulnerability in Ruslan <Body>Builder allows remote attackers to gain administrative privileges via a "'--" sequence in the username and password.

Oct 4, 2002 1 affected product(s) NVD
10.0
CVSS
2.1%
EPSS
⚡ 40.6
CVE-2002-0955

Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execute arbitrary script as other web site visitors via script in the num parameter, which is not filtered in the resulting error message.

Oct 4, 2002 1 affected product(s) NVD
7.5
CVSS
8.6%
EPSS
⚡ 32.6
CVE-2002-0959

Cross-site scripting vulnerability in Splatt Forum 3.0 allows remote attackers to execute arbitrary script as other users via an [img] tag with a closing quote followed by the script.

Oct 4, 2002 1 affected product(s) NVD
7.5
CVSS
7.2%
EPSS
⚡ 32.2
CVE-2002-1036

Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote attackers to execute web script via the (1) Rank or (2) Match parameters.

Oct 4, 2002 5 affected product(s) NVD
7.5
CVSS
7.2%
EPSS
⚡ 32.2
CVE-2002-1008

Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via a request to urlcount.cgi that contains the script, which is not filtered when the REPORT capability prints the original request.

Oct 4, 2002 2 affected product(s) NVD
7.5
CVSS
7.1%
EPSS
⚡ 32.1
CVE-2002-1009

Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via the (1) "Name" or (2) "E-mail" parameters.

Oct 4, 2002 2 affected product(s) NVD
7.5
CVSS
7.0%
EPSS
⚡ 32.1
CVE-2002-1027

Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attackers to execute arbitrary web script via a link to 500error.jsp with the script in 1the et parameter.

Oct 4, 2002 1 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2002-1070

Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter.

Oct 4, 2002 6 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2002-0958

Cross-site scripting vulnerability in browse.php for PHP(Reactor) 1.2.7 allows remote attackers to execute script as other users via the go parameter in the comments section.

Oct 4, 2002 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2002-1202

Unknown vulnerability in routed for HP Tru64 UNIX V4.0F through V5.1A allows local and remote attackers to read arbitrary files.

Oct 28, 2002 5 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2002-1006

Cross-site scripting (XSS) vulnerability in BBC Education Text to Speech Internet Enhancer (Betsie) 1.5.11 and earlier allows remote attackers to execute arbitrary web script via parserl.pl.

Oct 4, 2002 12 affected product(s) NVD
6.8
CVSS
4.4%
EPSS
⚡ 28.5
CVE-2002-1053

Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a URL that contains a reference to a nonexistent host followed by the script, which is included in the resulting error message.

Oct 4, 2002 1 affected product(s) NVD
6.8
CVSS
2.1%
EPSS
⚡ 27.8
CVE-2002-1054

Directory traversal vulnerability in Pablo FTP server 1.0 build 9 and earlier allows remote authenticated users to list arbitrary directories via "..\" (dot-dot backslash) sequences in a LIST command.

Oct 4, 2002 1 affected product(s) NVD
6.4
CVSS
2.2%
EPSS
⚡ 26.3
CVE-2002-1178

Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (dot-dot backslash) sequences in an HTTP request to the cgi-bin directory.

Oct 11, 2002 1 affected product(s) NVD
5.0
CVSS
9.5%
EPSS
⚡ 22.8
CVE-2002-1224

Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers to read arbitrary files as the kpf user via a URL with a modified icon parameter.

Oct 28, 2002 4 affected product(s) NVD
5.0
CVSS
8.8%
EPSS
⚡ 22.7
CVE-2002-1004

Directory traversal vulnerability in webmail feature of ArGoSoft Mail Server Plus or Pro 1.8.1.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in a URL.

Oct 4, 2002 2 affected product(s) NVD
5.0
CVSS
8.3%
EPSS
⚡ 22.5
CVE-2002-1079

Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in an HTTP GET request.

Oct 4, 2002 1 affected product(s) NVD
5.0
CVSS
4.7%
EPSS
⚡ 21.4