CSV
180,953 results for "vulnerability" Page 46
CVE-2002-2015

PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute code via the caselist parameter.

Dec 31, 2002 1 affected product(s) NVD
7.5
CVSS
9.5%
EPSS
⚡ 32.8
CVE-2002-1991

PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.

Dec 31, 2002 1 affected product(s) NVD
7.5
CVSS
7.5%
EPSS
⚡ 32.2
CVE-2002-1885

PHP remote file inclusion vulnerability in showhits.php3 for PowerPhlogger (PPhlogger) 2.0.9 through 2.2.2 allows remote attackers to execute arbitrary PHP code via the rel_path parameter.

Dec 31, 2002 3 affected product(s) NVD
7.5
CVSS
6.7%
EPSS
⚡ 32
CVE-2002-1882

Unknown vulnerability in AolSecurityPrivate.class in Oracle E-Business Suite 11i 11.1 through 11.6 allows remote attackers to bypass user authentication checks via unknown attack vectors.

Dec 31, 2002 6 affected product(s) NVD
7.5
CVSS
5.2%
EPSS
⚡ 31.6
CVE-2002-1887

PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l parameter.

Dec 31, 2002 1 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2002-1964

Unknown vulnerability in WesMo phpEventCalendar 1.1 allows remote attackers to execute arbitrary commands via unknown attack vectors.

Dec 31, 2002 1 affected product(s) NVD
7.5
CVSS
2.6%
EPSS
⚡ 30.8
CVE-2002-2019

PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote attackers to execute arbitrary PHP code via the include_file parameter.

Dec 31, 2002 1 affected product(s) NVD
7.5
CVSS
2.6%
EPSS
⚡ 30.8
CVE-2002-2005

Unknown vulnerability in Java web start 1.0.1_01, 1.0.1, 1.0 and 1.0.1.01 (HP-UX 11.x only) allows attackers to gain access to restricted resources via unknown attack vectors.

Dec 31, 2002 3 affected product(s) NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.6
CVE-2002-1919

SQL injection vulnerability in shopadmin.asp in VP-ASP 4.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password fields.

Dec 31, 2002 1 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.5
CVE-2002-1879

SQL injection vulnerability in LokwaBB 1.2.2 allows remote attackers to execute arbitrary SQL commands via the (1) member parameter to member.php or (2) loser parameter to misc.php.

Dec 31, 2002 1 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2002-2035

SQL injection vulnerability in RealityScape MyLogin 2000 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password in the login form.

Dec 31, 2002 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2002-2043

SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute arbitrary SQL commands and log in as arbitrary POP mail users via the password.

Dec 31, 2002 2 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2002-2022

Format string vulnerability in Kaffe OpenVM 1.0.6 and earlier allows local users to execute arbitrary code, when a java.lang.NoClassDefFoundError is thrown, via format specifiers in the forName attribute.

Dec 31, 2002 1 affected product(s) NVD
7.2
CVSS
0.6%
EPSS
⚡ 29
CVE-2002-1864

Directory traversal vulnerability in Simple Web Server (SWS) 0.0.4 through 0.1.0 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP request.

Dec 31, 2002 4 affected product(s) NVD
5.0
CVSS
17.8%
EPSS
⚡ 25.3
CVE-2002-2012

Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request.

Dec 31, 2002 1 affected product(s) NVD
5.0
CVSS
6.0%
EPSS
⚡ 21.8
CVE-2002-1982

Directory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote attackers to determine if a directory exists via a .. (dot dot) in the GET request, which returns different error messages depending on whether the directory exists or not.

Dec 31, 2002 1 affected product(s) NVD
5.0
CVSS
3.2%
EPSS
⚡ 21
CVE-2002-1966

Directory traversal vulnerability in magiccard.cgi in My Postcards Platinum 5.0 and 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.

Dec 31, 2002 2 affected product(s) NVD
5.0
CVSS
3.1%
EPSS
⚡ 20.9
CVE-2002-1878

PHP remote file inclusion vulnerability in w-Agora 4.1.3 allows remote attackers to execute arbitrary PHP code via the inc_dir parameter.

Dec 31, 2002 3 affected product(s) NVD
5.0
CVSS
2.6%
EPSS
⚡ 20.8
CVE-2002-1954

Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php.

Dec 31, 2002 1 affected product(s) NVD
4.3
CVSS
11.9%
EPSS
⚡ 20.8
CVE-2002-1987

Directory traversal vulnerability in view_source.jsp in Resin 2.1.2 allows remote attackers to read arbitrary files via a "\.." (backslash dot dot).

Dec 31, 2002 1 affected product(s) NVD
5.0
CVSS
2.5%
EPSS
⚡ 20.8