CSV
180,950 results for "vulnerability" Page 45
CVE-2002-1847

Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a long mp3 filename command line argument. NOTE: since the only known attack vector requires command line access, this may not be a vulnerability.

Dec 31, 2002 5 affected product(s) NVD
7.5
CVSS
33.6%
EPSS
⚡ 40.1
CVE-2002-1885

PHP remote file inclusion vulnerability in showhits.php3 for PowerPhlogger (PPhlogger) 2.0.9 through 2.2.2 allows remote attackers to execute arbitrary PHP code via the rel_path parameter.

Dec 31, 2002 3 affected product(s) NVD
7.5
CVSS
6.7%
EPSS
⚡ 32
CVE-2002-1882

Unknown vulnerability in AolSecurityPrivate.class in Oracle E-Business Suite 11i 11.1 through 11.6 allows remote attackers to bypass user authentication checks via unknown attack vectors.

Dec 31, 2002 6 affected product(s) NVD
7.5
CVSS
5.2%
EPSS
⚡ 31.6
CVE-2002-1887

PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l parameter.

Dec 31, 2002 1 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2002-1919

SQL injection vulnerability in shopadmin.asp in VP-ASP 4.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password fields.

Dec 31, 2002 1 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.5
CVE-2002-1817

Unknown vulnerability in Veritas Cluster Server (VCS) 1.2 for WindowsNT, Cluster Server 1.3.0 for Solaris, and Cluster Server 1.3.1 for HP-UX allows attackers to gain privileges via unknown attack vectors.

Dec 31, 2002 4 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2002-1879

SQL injection vulnerability in LokwaBB 1.2.2 allows remote attackers to execute arbitrary SQL commands via the (1) member parameter to member.php or (2) loser parameter to misc.php.

Dec 31, 2002 1 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2002-1825

Format string vulnerability in PerlRTE_example1.pl in WASD 7.1, 7.2.0 through 7.2.3, and 8.0.0 allows remote attackers to execute arbitrary commands or crash the server via format strings in the $name variable.

Dec 31, 2002 6 affected product(s) NVD
6.4
CVSS
2.2%
EPSS
⚡ 26.3
CVE-2002-1819

Directory traversal vulnerability in TinyHTTPD 0.1 .0 allows remote attackers to read or execute arbitrary files via a ".." (dot dot) in the URL.

Dec 31, 2002 1 affected product(s) NVD
6.4
CVSS
1.8%
EPSS
⚡ 26.1
CVE-2002-1864

Directory traversal vulnerability in Simple Web Server (SWS) 0.0.4 through 0.1.0 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP request.

Dec 31, 2002 4 affected product(s) NVD
5.0
CVSS
17.8%
EPSS
⚡ 25.3
CVE-2002-1824

Microsoft Internet Explorer 6.0, when handling an expired CA-CERT in a webserver's certificate chain during a SSL/TLS handshake, does not prompt the user before searching for and finding a newer certificate, which may allow attackers to perform a man-in-the-middle attack. NOTE: it is not clear whether this poses a vulnerability.

Dec 31, 2002 2 affected product(s) NVD
5.0
CVSS
2.6%
EPSS
⚡ 20.8
CVE-2002-1878

PHP remote file inclusion vulnerability in w-Agora 4.1.3 allows remote attackers to execute arbitrary PHP code via the inc_dir parameter.

Dec 31, 2002 3 affected product(s) NVD
5.0
CVSS
2.6%
EPSS
⚡ 20.8
CVE-2002-1954

Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php.

Dec 31, 2002 1 affected product(s) NVD
4.3
CVSS
11.9%
EPSS
⚡ 20.8
CVE-2002-1815

Directory traversal vulnerability in source.php and source.cgi in Aquonics File Manager 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

Dec 31, 2002 1 affected product(s) NVD
5.0
CVSS
1.7%
EPSS
⚡ 20.5
CVE-2002-1832

Unknown vulnerability in the "ipopts decode" functionality in Firestorm IDS 0.4.0 through 0.4.2 allows remote attackers to cause a denial of service (crash) via certain IP options.

Dec 31, 2002 3 affected product(s) NVD
5.0
CVSS
1.6%
EPSS
⚡ 20.5
CVE-2002-1926

Directory traversal vulnerability in source.php in Aquonics File Manager 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP query string.

Dec 31, 2002 1 affected product(s) NVD
5.0
CVSS
1.7%
EPSS
⚡ 20.5
CVE-2002-1917

CRLF injection vulnerability in the "User Profile: Send Email" feature in Geeklog 1.35 and 1.3.5sr1 allows remote attackers to obtain e-mail addresses by injecting a CRLF into the Subject field and adding a BCC mail header.

Dec 31, 2002 2 affected product(s) NVD
5.0
CVSS
1.4%
EPSS
⚡ 20.4
CVE-2002-1845

Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter.

Dec 31, 2002 2 affected product(s) NVD
4.3
CVSS
3.9%
EPSS
⚡ 18.4
CVE-2002-1799

Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) email parameter to add.php or (2) banurl parameter.

Dec 31, 2002 1 affected product(s) NVD
4.3
CVSS
3.6%
EPSS
⚡ 18.3
CVE-2002-1806

Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

Dec 31, 2002 1 affected product(s) NVD
4.3
CVSS
3.5%
EPSS
⚡ 18.3