Latest CVE Feed
-
6.8
MEDIUMCVE-2002-1464
Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable.... Read more
Affected Products : b2- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1481
savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbitrary PHP code by using savesettings.php to modify config.php.... Read more
Affected Products : phpgb- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1469
scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs and modifying the PATH variable in $HOME/.ssh/environmen... Read more
Affected Products : scponly- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2002-1484
DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a... Read more
Affected Products : db4web- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1474
Unknown vulnerability or vulnerabilities in TCP/IP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to cause a denial of service.... Read more
Affected Products : tru64- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1483
db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument is a filename of the form (1) C: (drive letter), (2) //absolute/path (double-slash), or (3) .. (dot-dot).... Read more
Affected Products : db4web- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1478
Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode.... Read more
Affected Products : cacti- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1477
graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode.... Read more
Affected Products : cacti- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1468
Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.... Read more
Affected Products : aix- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1482
SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain administrative privileges via SQL code in the password entry.... Read more
Affected Products : phpgb- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1475
Unknown vulnerability in the ARP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to "take over packets destined for another host" and cause a denial of service.... Read more
Affected Products : tru64- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1466
CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable.... Read more
Affected Products : b2- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1473
Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbitrary code.... Read more
Affected Products : hp-ux- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1479
Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly gain privileges.... Read more
Affected Products : cacti- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1476
Buffer overflow in setlocale in libc on NetBSD 1.4.x through 1.6, and possibly other operating systems, when called with the LC_ALL category, allows local attackers to execute arbitrary code via a user-controlled locale string that has more than 6 element... Read more
Affected Products : netbsd- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1054
mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.... Read more
Affected Products : mod_access_referer- Published: Apr. 16, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0203
Buffer overflow in moxftp 2.2 and earlier allows remote malicious FTP servers to execute arbitrary code via a long FTP banner.... Read more
- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1432
MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly requesting the database.... Read more
Affected Products : a-cart metacart midicart_asp midicart_asp_maxi midicart_asp_plus salescart-pro salescart-std- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0134
Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.... Read more
Affected Products : http_server- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1436
The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary Perl code via an HTTP POST request.... Read more
- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025