CSV
180,465 results for "vulnerability" Page 35
CVE-2002-0661

Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters.

Aug 12, 2002 12 affected product(s) NVD
7.5
CVSS
69.7%
EPSS
⚡ 50.9
CVE-2002-0465

Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files, and execute commands, via a .. (dot dot) in the OpenPath parameter.

Aug 12, 2002 2 affected product(s) NVD
10.0
CVSS
4.0%
EPSS
⚡ 41.2
CVE-2002-0746

Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument.

Aug 12, 2002 1 affected product(s) NVD
10.0
CVSS
1.8%
EPSS
⚡ 40.6
CVE-2002-0619

The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071, Word Mail Merge Vulnerability" (CVE-2000-0788).

Aug 12, 2002 2 affected product(s) NVD
7.5
CVSS
16.1%
EPSS
⚡ 34.8
CVE-2002-0719

SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files.

Aug 12, 2002 2 affected product(s) NVD
7.5
CVSS
10.4%
EPSS
⚡ 33.1
CVE-2002-0504

Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp.

Aug 12, 2002 2 affected product(s) NVD
7.5
CVSS
7.9%
EPSS
⚡ 32.4
CVE-2002-0733

Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message.

Aug 12, 2002 1 affected product(s) NVD
7.5
CVSS
8.0%
EPSS
⚡ 32.4
CVE-2002-0413

Cross-site scripting vulnerability in ReBB allows remote attackers to execute arbitrary Javascript and steal cookies via an IMG tag whose URL includes the malicious script.

Aug 12, 2002 1 affected product(s) NVD
7.5
CVSS
7.0%
EPSS
⚡ 32.1
CVE-2002-0730

Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields such as (1) Name, (2) EMail, or (3) Homepage.

Aug 12, 2002 1 affected product(s) NVD
7.5
CVSS
6.9%
EPSS
⚡ 32.1
CVE-2002-0419

Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (2) in certain configurations, the server IP address is provided as the realm for Basic authentication, which could reveal real IP addresses that were obscured by NAT, or (3) when NTLM authentication is used, the NetBIOS name of the server and its Windows NT domain are revealed in response to an Authorization request. NOTE: this entry originally contained a vector (1) in which the server reveals whether it supports Basic or NTLM authentication through 401 Access Denied error messages. CVE has REJECTED this vector; it is not a vulnerability because the information is already available through legitimate use, since authentication cannot proceed without specifying a scheme that is supported by both the client and the server.

Aug 12, 2002 3 affected product(s) NVD
5.0
CVSS
38.2%
EPSS
⚡ 31.5
CVE-2002-0412

Format string vulnerability in TraceEvent function for ntop before 2.1 allows remote attackers to execute arbitrary code by causing format strings to be injected into calls to the syslog function, via (1) an HTTP GET request, (2) a user name in HTTP authentication, or (3) a password in HTTP authentication.

Aug 12, 2002 1 affected product(s) NVD
7.5
CVSS
4.2%
EPSS
⚡ 31.3
CVE-2002-0645

SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands.

Aug 12, 2002 2 affected product(s) NVD
7.5
CVSS
3.8%
EPSS
⚡ 31.2
CVE-2002-0458

Cross-site scripting vulnerability in News-TNK 1.2.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter.

Aug 12, 2002 1 affected product(s) NVD
7.6
CVSS
2.2%
EPSS
⚡ 31.1
CVE-2002-0459

Cross-site scripting vulnerability in Board-TNK 1.3.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter.

Aug 12, 2002 2 affected product(s) NVD
7.6
CVSS
2.2%
EPSS
⚡ 31.1
CVE-2002-0457

Cross-site scripting vulnerability in signgbook.php for BG GuestBook 1.0 allows remote attackers to execute arbitrary Javascript via encoded tags such as <, >, and & in fields such as (1) name, (2) email, (3) AIM screen name, (4) website, (5) location, or (6) message.

Aug 12, 2002 1 affected product(s) NVD
7.6
CVSS
2.1%
EPSS
⚡ 31
CVE-2002-0660

Buffer overflow in libpng 1.0.12-3.woody.2 and libpng3 1.2.1-1.1.woody.2 on Debian GNU/Linux 3.0, and other operating systems, may allow attackers to cause a denial of service and possibly execute arbitrary code, a different vulnerability than CVE-2002-0728.

Aug 12, 2002 2 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2002-0735

Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code by triggering log messages.

Aug 12, 2002 17 affected product(s) NVD
7.5
CVSS
2.9%
EPSS
⚡ 30.9
CVE-2002-0411

Cross-site scripting vulnerability in message.php for AeroMail before 1.45 allows remote attackers to execute Javascript as an AeroMail user via an email message with the script in the Subject line.

Aug 12, 2002 6 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2002-0731

Cross-site scripting vulnerability in demonstration scripts for vqServer allows remote attackers to execute arbitrary script via a link that contains the script in arguments to demo scripts such as respond.pl.

Aug 12, 2002 4 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2002-0732

Cross-site scripting vulnerability in MyGuestbook 1.0 allows remote attackers to execute arbitrary script or inject HTML via fields such as (1) user name or (2) comments.

Aug 12, 2002 1 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8