CSV
180,464 results for "vulnerability" Page 34
CVE-2002-0465

Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files, and execute commands, via a .. (dot dot) in the OpenPath parameter.

Aug 12, 2002 2 affected product(s) NVD
10.0
CVSS
4.0%
EPSS
⚡ 41.2
CVE-2002-0437

Smsd in SMS Server Tools (SMStools) before 1.4.8 allows remote attackers to execute arbitrary commands via shell metacharacters (backquotes) in message text, as described with the term "string format vulnerability" by some sources.

Jul 26, 2002 2 affected product(s) NVD
10.0
CVSS
3.4%
EPSS
⚡ 41
CVE-2002-0187

Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root parameter as part of an XML SQL query, aka "Script Injection via XML Tag."

Jul 3, 2002 3 affected product(s) NVD
7.5
CVSS
13.9%
EPSS
⚡ 34.2
CVE-2002-0682

Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.

Jul 23, 2002 1 affected product(s) NVD
7.5
CVSS
12.2%
EPSS
⚡ 33.7
CVE-2002-0573

Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.

Jul 3, 2002 6 affected product(s) NVD
7.5
CVSS
9.2%
EPSS
⚡ 32.8
CVE-2002-0681

Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that generates a "404 not found" message, which does not quote the script.

Jul 23, 2002 5 affected product(s) NVD
7.5
CVSS
8.3%
EPSS
⚡ 32.5
CVE-2002-0413

Cross-site scripting vulnerability in ReBB allows remote attackers to execute arbitrary Javascript and steal cookies via an IMG tag whose URL includes the malicious script.

Aug 12, 2002 1 affected product(s) NVD
7.5
CVSS
7.0%
EPSS
⚡ 32.1
CVE-2002-0419

Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (2) in certain configurations, the server IP address is provided as the realm for Basic authentication, which could reveal real IP addresses that were obscured by NAT, or (3) when NTLM authentication is used, the NetBIOS name of the server and its Windows NT domain are revealed in response to an Authorization request. NOTE: this entry originally contained a vector (1) in which the server reveals whether it supports Basic or NTLM authentication through 401 Access Denied error messages. CVE has REJECTED this vector; it is not a vulnerability because the information is already available through legitimate use, since authentication cannot proceed without specifying a scheme that is supported by both the client and the server.

Aug 12, 2002 3 affected product(s) NVD
5.0
CVSS
38.2%
EPSS
⚡ 31.5
CVE-2002-0412

Format string vulnerability in TraceEvent function for ntop before 2.1 allows remote attackers to execute arbitrary code by causing format strings to be injected into calls to the syslog function, via (1) an HTTP GET request, (2) a user name in HTTP authentication, or (3) a password in HTTP authentication.

Aug 12, 2002 1 affected product(s) NVD
7.5
CVSS
4.2%
EPSS
⚡ 31.3
CVE-2002-0551

Cross-site scripting vulnerability in Dynamic Guestbook 3.0 allows remote attackers to execute code in clients who access guestbook pages via the parameters (1) name, (2) mail, or (3) kommentar.

Jul 3, 2002 1 affected product(s) NVD
7.5
CVSS
3.6%
EPSS
⚡ 31.1
CVE-2002-0683

Directory traversal vulnerability in Carello 1.3 allows remote attackers to execute programs on the server via a .. (dot dot) in the VBEXE parameter.

Jul 23, 2002 1 affected product(s) NVD
7.5
CVSS
3.7%
EPSS
⚡ 31.1
CVE-2002-0458

Cross-site scripting vulnerability in News-TNK 1.2.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter.

Aug 12, 2002 1 affected product(s) NVD
7.6
CVSS
2.2%
EPSS
⚡ 31.1
CVE-2002-0459

Cross-site scripting vulnerability in Board-TNK 1.3.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter.

Aug 12, 2002 2 affected product(s) NVD
7.6
CVSS
2.2%
EPSS
⚡ 31.1
CVE-2002-0457

Cross-site scripting vulnerability in signgbook.php for BG GuestBook 1.0 allows remote attackers to execute arbitrary Javascript via encoded tags such as <, >, and & in fields such as (1) name, (2) email, (3) AIM screen name, (4) website, (5) location, or (6) message.

Aug 12, 2002 1 affected product(s) NVD
7.6
CVSS
2.1%
EPSS
⚡ 31
CVE-2002-0553

Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by injecting the script into fields during new customer registration.

Jul 3, 2002 6 affected product(s) NVD
7.5
CVSS
2.9%
EPSS
⚡ 30.9
CVE-2002-0411

Cross-site scripting vulnerability in message.php for AeroMail before 1.45 allows remote attackers to execute Javascript as an AeroMail user via an email message with the script in the Subject line.

Aug 12, 2002 6 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2002-0538

FTP proxy in Symantec Raptor Firewall 6.5.3 and Enterprise 7.0 rewrites an FTP server's "FTP PORT" responses in a way that allows remote attackers to redirect FTP data connections to arbitrary ports, a variant of the "FTP bounce" vulnerability.

Jul 3, 2002 7 affected product(s) NVD
7.5
CVSS
1.7%
EPSS
⚡ 30.5
CVE-2002-0546

Cross-site scripting vulnerability in the mini-browser for Winamp 2.78 and 2.79 allows remote attackers to execute script via an ID3v1 or ID3v2 tag in an MP3 file.

Jul 3, 2002 2 affected product(s) NVD
7.5
CVSS
1.7%
EPSS
⚡ 30.5
CVE-2002-0439

Cross-site scripting vulnerability in CaupoShop 1.30a and earlier, and possibly CaupoShopPro, allows remote attackers to execute arbitrary Javascript and steal credit card numbers or delete items by injecting the script into new customer information fields such as the message field.

Jul 26, 2002 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2002-0420

Vulnerability in PureTLS before 0.9b2 related to injection attacks, which could possibly allow remote attackers to corrupt or hijack user sessions.

Aug 12, 2002 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5