CSV
180,474 results for "vulnerability" Page 38
CVE-2002-0951

SQL injection vulnerability in Ruslan <Body>Builder allows remote attackers to gain administrative privileges via a "'--" sequence in the username and password.

Oct 4, 2002 1 affected product(s) NVD
10.0
CVSS
2.1%
EPSS
⚡ 40.6
CVE-2002-0955

Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execute arbitrary script as other web site visitors via script in the num parameter, which is not filtered in the resulting error message.

Oct 4, 2002 1 affected product(s) NVD
7.5
CVSS
8.6%
EPSS
⚡ 32.6
CVE-2002-0959

Cross-site scripting vulnerability in Splatt Forum 3.0 allows remote attackers to execute arbitrary script as other users via an [img] tag with a closing quote followed by the script.

Oct 4, 2002 1 affected product(s) NVD
7.5
CVSS
7.2%
EPSS
⚡ 32.2
CVE-2002-1036

Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote attackers to execute web script via the (1) Rank or (2) Match parameters.

Oct 4, 2002 5 affected product(s) NVD
7.5
CVSS
7.2%
EPSS
⚡ 32.2
CVE-2002-0902

Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB users by including a http:// and a double-quote (") in the [IMG] tag, which bypasses phpBB's security check, terminates the src parameter of the resulting HTML IMG tag, and injects the script.

Oct 4, 2002 6 affected product(s) NVD
7.5
CVSS
7.2%
EPSS
⚡ 32.1
CVE-2002-1008

Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via a request to urlcount.cgi that contains the script, which is not filtered when the REPORT capability prints the original request.

Oct 4, 2002 2 affected product(s) NVD
7.5
CVSS
7.1%
EPSS
⚡ 32.1
CVE-2002-1009

Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via the (1) "Name" or (2) "E-mail" parameters.

Oct 4, 2002 2 affected product(s) NVD
7.5
CVSS
7.0%
EPSS
⚡ 32.1
CVE-2002-0913

Format string vulnerability in log_doit function of Slurp NNTP client 1.1.0 allows a malicious news server to execute arbitrary code on the client via format strings in a server response.

Oct 4, 2002 1 affected product(s) NVD
7.5
CVSS
4.5%
EPSS
⚡ 31.4
CVE-2002-0925

Format string vulnerability in mmsyslog function allows remote attackers to execute arbitrary code via (1) the USER command to mmpop3d for mmmail 0.0.13 and earlier, (2) the HELO command to mmsmtpd for mmmail 0.0.13 and earlier, or (3) the USER command to mmftpd 0.0.7 and earlier.

Oct 4, 2002 2 affected product(s) NVD
7.5
CVSS
3.4%
EPSS
⚡ 31
CVE-2002-0985

Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.

Sep 24, 2002 3 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2002-0916

Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2.4.STABLE6 and earlier, allows remote attackers to execute arbitrary code via format strings in the user name, which are not properly handled in a syslog call.

Oct 4, 2002 1 affected product(s) NVD
7.5
CVSS
2.9%
EPSS
⚡ 30.9
CVE-2002-0938

Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitrary script or HTML as other web users via the action argument in a link to setup.exe.

Oct 4, 2002 2 affected product(s) NVD
7.5
CVSS
3.1%
EPSS
⚡ 30.9
CVE-2002-0950

Cross-site scripting vulnerability in TransWARE Active! mail 1.422 and 2.0 allows remote attackers to execute arbitrary code via a certain e-mail header, which is not properly filtered.

Oct 4, 2002 2 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2002-1027

Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attackers to execute arbitrary web script via a link to 500error.jsp with the script in 1the et parameter.

Oct 4, 2002 1 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2002-0944

Cross-site scripting vulnerability in DeepMetrix LiveStats 5.03 through 6.2.1 allows remote attackers to execute arbitrary script as the LiveStats user via the (1) user-agent or (2) referrer, which are not filtered by the stats program.

Oct 4, 2002 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2002-0958

Cross-site scripting vulnerability in browse.php for PHP(Reactor) 1.2.7 allows remote attackers to execute script as other users via the go parameter in the comments section.

Oct 4, 2002 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2002-0878

SQL injection vulnerability in the login form for LogiSense software including (1) Hawk-i Billing, (2) Hawk-i ASP and (3) DNS Manager allows remote attackers to bypass authentication via SQL code in the password field.

Oct 4, 2002 3 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2002-0883

Vulnerability in Compaq ProLiant BL e-Class Integrated Administrator 1.0 and 1.10, allows authenticated users with Telnet, SSH, or console access to conduct unauthorized activities.

Oct 4, 2002 2 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2002-1006

Cross-site scripting (XSS) vulnerability in BBC Education Text to Speech Internet Enhancer (Betsie) 1.5.11 and earlier allows remote attackers to execute arbitrary web script via parserl.pl.

Oct 4, 2002 12 affected product(s) NVD
6.8
CVSS
4.4%
EPSS
⚡ 28.5
CVE-2002-0934

Directory traversal vulnerability in Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) allows remote attackers to read or modify arbitrary files via an illegal character in the middle of a .. (dot dot) sequence in the parameters (1) _browser_out or (2) _out_file.

Oct 4, 2002 1 affected product(s) NVD
6.4
CVSS
2.0%
EPSS
⚡ 26.2