Vulnerabilities (CVE)

Total 304758 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1537 1 Phpbb Group 1 Phpbb 2008-09-05 10.0 HIGH N/A
admin_ug_auth.php in phpBB 2.0.0 allows local users to gain administrator privileges by directly calling admin_ug_auth.php with modifed form fields such as "u".
CVE-2002-1421 1 Ilia Alshanetsky 1 Fudforum 2008-09-05 7.5 HIGH N/A
SQL injection vulnerabilities in FUDforum before 2.2.0 allow remote attackers to perform unauthorized database operations via (1) report.php, (2) selmsg.php, and (3) showposts.php.
CVE-2002-1413 1 Novell 1 Netware 2008-09-05 7.5 HIGH N/A
RCONAG6 for Novell Netware SP2, while running RconJ in secure mode, allows remote attackers to bypass authentication using the RconJ "Secure IP" (SSL) option during a connection.
CVE-2002-1545 1 Cooolsoft 1 Personal Ftp Server 2008-09-05 5.0 MEDIUM N/A
CooolSoft Personal FTP Server 2.24 allows remote attackers to obtain the absolute pathname of the FTP root via a PWD command, which includes the full path in the response.
CVE-2002-1512 1 Tolis Group 1 Bru 2008-09-05 6.2 MEDIUM N/A
xbru in BRU Workstation 17.0 allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the xbru_dscheck.dd temporary file.
CVE-2002-1439 1 Hp 2 Virtualvault, Vvos 2008-09-05 4.6 MEDIUM N/A
Unknown vulnerability related to stack corruption in the TGA daemon for HP-UX 11.04 (VVOS) Virtualvault 4.0, 4.5, and 4.6 may allow attackers to obtain access to system files.
CVE-2002-1457 1 Leszek Krupinski 1 L-forum 2008-09-05 7.5 HIGH N/A
SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements via the search parameter.
CVE-2002-1431 1 Belkin 1 F5d5230-4 4-port Cable Dsl Gateway Router 2008-09-05 7.5 HIGH N/A
Belkin F5D5230-4 4-Port Cable/DSL Gateway Router 1.20.000 modifies the source IP address of internal packets to that of the router's external interface when forwarding a request from an internal host to an internal web server, which allows remote attackers to hide which host is being used to access the web server.
CVE-2002-1549 1 Light Httpd 1 Light Httpd 2008-09-05 7.5 HIGH N/A
Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request.
CVE-2002-1518 1 Sgi 1 Irix 2008-09-05 3.6 LOW N/A
mv in IRIX 6.5 creates a directory with world-writable permissions while moving a directory, which could allow local users to modify files and directories.
CVE-2002-1505 1 Woltlab 1 Burning Board 2008-09-05 7.5 HIGH N/A
SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the database and possibly gain privileges via the boardid parameter.
CVE-2002-1536 1 Hans Persson 1 Molly 2008-09-05 7.5 HIGH N/A
Molly IRC bot 0.5 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the $host variable for nslookup.pl, (2) the $to, $from, or $message variables in pop.pl, (3) the $words or $text variables in sms.pl, or (4) the $server or $printer variables in hpled.pl.
CVE-2002-1411 1 Duma 1 Photo Gallery System 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in update.dpgs in Duma Photo Gallery System (DPGS) 0.99.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the id parameter.
CVE-2002-1251 1 Log2mail 1 Log2mail 2008-09-05 10.0 HIGH N/A
Buffer overflow in log2mail before 0.2.5.1 allows remote attackers to execute arbitrary code via a long log message.
CVE-2002-1422 1 Ilia Alshanetsky 1 Fudforum 2008-09-05 5.0 MEDIUM N/A
admbrowse.php in FUDforum before 2.2.0 allows remote attackers to create or delete files via URL-encoded pathnames in the cur and dest parameters.
CVE-2002-1582 1 Mailreader.com 1 Mailreader.com 2008-09-05 10.0 HIGH N/A
compose.cgi in Mailreader.com 2.3.30 and 2.3.31, when using Sendmail as the Mail Transfer Agent, allows remote attackers to execute arbitrary commands via shell metacharacters in the RealEmail configuration variable, which is used to call Sendmail in network.cgi.
CVE-2002-1416 1 Webeasymail 1 Webeasymail 2008-09-05 5.0 MEDIUM N/A
The POP3 service for WebEasyMail 3.4.2.2 and earlier generates diffferent error messages for valid and invalid usernames during authentication, which makes it easier for remote attackers to conduct brute force attacks.
CVE-2002-1514 1 Borland Software 1 Interbase 2008-09-05 7.2 HIGH N/A
gds_lock_mgr in Borland InterBase allows local users to overwrite files and gain privileges via a symlink attack on a "isc_init1.X" temporary file, as demonstrated by modifying the xinetdbd file.
CVE-2002-1472 1 Xfree86 Project 1 X11r6 2008-09-05 7.2 HIGH N/A
Untrusted search path vulnerability in libX11.so in xfree86, when used in setuid or setgid programs, allows local users to gain root privileges via a modified LD_PRELOAD environment variable that points to a malicious module.
CVE-2002-1428 1 Dotproject 1 Dotproject 2008-09-05 10.0 HIGH N/A
index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1.