Latest CVE Feed
-
7.5
HIGHCVE-2002-0787
Cross-site scripting vulnerabilities in iCon administrative web server for Critical Path inJoin Directory Server 4.0 allow remote attackers to execute script as the administrator via administrator URLs with modified (1) LOCID or (2) OC parameters.... Read more
Affected Products : injoin_directory_server- EPSS Score: %16.40
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0735
Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code by triggering log messages.... Read more
- EPSS Score: %2.34
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0731
Cross-site scripting vulnerability in demonstration scripts for vqServer allows remote attackers to execute arbitrary script via a link that contains the script in arguments to demo scripts such as respond.pl.... Read more
Affected Products : vqserver- EPSS Score: %3.06
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0520
Cross-site scripting vulnerability in functions-inc.asp for ASP-Nuke RC1 allows remote attackers to execute script as other ASP-Nuke users by embedding it within an IMG tag.... Read more
Affected Products : asp-nuke- EPSS Score: %1.08
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0480
ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured to allow a user "skank" on a machine "starscream" to become a key manager when the "first time connection" feature is enabled and before any legitimate administrators have conn... Read more
Affected Products : realsecure_nokia- EPSS Score: %0.99
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0469
Ecartis (formerly Listar) 1.0.0 in snapshot 20020125 and earlier does not properly drop privileges when Ecartis is installed setuid-root, "lock-to-user" is not set, and ecartis is called by certain MTA's, which could allow local users to gain privileges.... Read more
- EPSS Score: %0.15
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGH- EPSS Score: %0.61
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0753
Buffer overflow in Talentsoft Web+ 5.0 allows remote attackers to execute arbitrary code via an HTTP request with a long cookie.... Read more
Affected Products : web\+_server- EPSS Score: %7.82
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0736
Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank.... Read more
Affected Products : backoffice- EPSS Score: %15.93
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0487
Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by reading the password from the source file, e.g. from th... Read more
Affected Products : xpede- EPSS Score: %0.15
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0783
Opera 6.01, 6.0, and 5.12 allows remote attackers to execute arbitrary JavaScript in the security context of other sites by setting the location of a frame or iframe to a Javascript: URL.... Read more
Affected Products : opera_web_browser- EPSS Score: %11.51
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0807
Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not properly quoted by editusers.cgi.... Read more
Affected Products : bugzilla- EPSS Score: %0.74
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0806
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows authenticated users with editing privileges to delete other users by directly calling the editusers.cgi script with the "del" option.... Read more
Affected Products : bugzilla- EPSS Score: %0.13
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0805
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, (1) creates new directories with world-writable permissions, and (2) creates the params file with world-writable permissions, which allows local users to modify the files and execute code.... Read more
Affected Products : bugzilla- EPSS Score: %0.08
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0804
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when configured to perform reverse DNS lookups, allows remote attackers to bypass IP restrictions by connecting from a system with a spoofed reverse DNS hostname.... Read more
Affected Products : bugzilla- EPSS Score: %0.55
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0799
Buffer overflow in YoungZSoft CMailServer 3.30 allows remote attackers to execute arbitrary code via a long USER argument.... Read more
Affected Products : cmailserver- EPSS Score: %10.98
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0756
Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert script into an error page and possibly steal cookies.... Read more
- EPSS Score: %1.03
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0751
CGIscript.net csMailto.cgi program allows remote attackers to use csMailto as a "spam proxy" and send mail to arbitrary users via modified (1) form-to, (2) form-from, and (3) form-results parameters.... Read more
Affected Products : csmailto- EPSS Score: %1.24
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0750
CGIscript.net csMailto.cgi program allows remote attackers to read arbitrary files by specifying the target filename in the form-attachment field.... Read more
Affected Products : csmailto- EPSS Score: %1.30
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0719
SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files.... Read more
Affected Products : content_management_server- EPSS Score: %6.09
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025