CSV
180,961 results for "vulnerability" Page 51
CVE-2002-2279

Unspecified vulnerability in the bind function in config.inc of aldap 0.09 allows remote attackers to authenticate with Manager permissions.

Dec 31, 2002 1 affected product(s) NVD
10.0
CVSS
2.1%
EPSS
⚡ 40.6
CVE-2002-2374

Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files."

Dec 31, 2002 1 affected product(s) NVD
10.0
CVSS
1.2%
EPSS
⚡ 40.3
CVE-2002-2287

PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.

Dec 31, 2002 2 affected product(s) NVD
7.5
CVSS
2.3%
EPSS
⚡ 30.7
CVE-2002-2319

Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2) DATA, and (3) MESS parameters, which are inserted into news.php3.

Dec 31, 2002 1 affected product(s) NVD
7.5
CVSS
2.3%
EPSS
⚡ 30.7
CVE-2002-2304

SQL injection vulnerability in admin/auth/checksession.php in MyPHPLinks 2.1.9 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the idsession parameter.

Dec 31, 2002 2 affected product(s) NVD
7.5
CVSS
1.0%
EPSS
⚡ 30.3
CVE-2002-2305

SQL injection vulnerability in agentadmin.php in Immobilier allows remote attackers to execute arbitrary SQL commands via the (1) agentname or (2) agentpassword parameter.

Dec 31, 2002 1 affected product(s) NVD
7.5
CVSS
1.0%
EPSS
⚡ 30.3
CVE-2002-2383

SQL injection vulnerability in f2html.pl 0.1 through 0.4 allows remote attackers to execute arbitrary SQL commands via file names.

Dec 31, 2002 4 affected product(s) NVD
7.5
CVSS
1.0%
EPSS
⚡ 30.3
CVE-2002-2391

SQL injection vulnerability in index.php of WebChat 1.5 included in XOOPS 1.0 allows remote attackers to execute arbitrary SQL commands via the roomid parameter.

Dec 31, 2002 2 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.3
CVE-2002-2298

PHP remote file inclusion vulnerability in config.php in Thatware 0.3 through 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter.

Dec 31, 2002 1 affected product(s) NVD
6.8
CVSS
2.0%
EPSS
⚡ 27.8
CVE-2002-2297

PHP remote file inclusion vulnerability in artlist.php in Thatware 0.5.2 and 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter.

Dec 31, 2002 2 affected product(s) NVD
6.8
CVSS
1.3%
EPSS
⚡ 27.6
CVE-2002-2299

PHP remote file inclusion vulnerability in thatfile.php in Thatware 0.3 through 0.5.2 allows remote attackers to execute arbitrary PHP code via the root_path parameter.

Dec 31, 2002 1 affected product(s) NVD
6.8
CVSS
1.3%
EPSS
⚡ 27.6
CVE-2002-2399

Directory traversal vulnerability in viewAttachment.cgi in W3Mail 1.0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

Dec 31, 2002 1 affected product(s) NVD
6.4
CVSS
2.4%
EPSS
⚡ 26.3
CVE-2002-2416

Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request.

Dec 31, 2002 1 affected product(s) NVD
5.0
CVSS
6.0%
EPSS
⚡ 21.8
CVE-2002-2403

Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences.

Dec 31, 2002 1 affected product(s) NVD
5.0
CVSS
2.7%
EPSS
⚡ 20.8
CVE-2002-2292

Directory traversal vulnerability in Remote Console Applet in Halycon Software iASP 1.0.9 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request to port 9095.

Dec 31, 2002 1 affected product(s) NVD
5.0
CVSS
1.5%
EPSS
⚡ 20.5
CVE-2002-2375

Directory traversal vulnerability in CommuniGate Pro 4.0b4 and possibly earlier versions allows remote attackers to list the contents of the WebUser directory and its parent directory via a (1) .. (dot dot) or (2) . (dot) in a URL. NOTE: it is not clear whether this issue reveals any more information regarding directory structure than is already available to any CommuniGate Pro user, although there is a possibility that it could be used to infer product version information.

Dec 31, 2002 1 affected product(s) NVD
5.0
CVSS
1.5%
EPSS
⚡ 20.5
CVE-2002-2387

Directory traversal vulnerability in Hyperion FTP server 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the LS command.

Dec 31, 2002 1 affected product(s) NVD
5.0
CVSS
1.5%
EPSS
⚡ 20.5
CVE-2002-2330

Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to inject arbitrary web script or HTML via (1) HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to stats.html and executed in client browsers.

Dec 31, 2002 1 affected product(s) NVD
5.0
CVSS
1.2%
EPSS
⚡ 20.3
CVE-2002-2327

Unspecified vulnerability in the environmental monitoring subsystem in Solaris 8 running on Sun Fire 280R, V480 and V880 allows local users to cause a denial of service by setting volatile properties.

Dec 31, 2002 1 affected product(s) NVD
4.9
CVSS
0.3%
EPSS
⚡ 19.7
CVE-2002-2359

Cross-site scripting (XSS) vulnerability in the FTP view feature in Mozilla 1.0 allows remote attackers to inject arbitrary web script or HTML via the title tag of an ftp URL.

Dec 31, 2002 4 affected product(s) NVD
4.3
CVSS
3.8%
EPSS
⚡ 18.3