CVE-2002-2000 to CVE-2002-2999
108 CVEs with public proof-of-concept exploits.
- CVE-2002-20061 PoCThe default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path…
- CVE-2002-20073 PoCsThe default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as…
- CVE-2002-20111 PoCCross-site scripting (XSS) vulnerability in the fom CGI program (fom.cgi) in Faq-O-Matic 2.711 and 2.712 allows remote attackers to inject…
- CVE-2002-20131 PoCMozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a…
- CVE-2002-20151 PoCPHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute…
- CVE-2002-20161 PoCUser-mode Linux (UML) 2.4.17-8 does not restrict access to kernel address space, which allows local users to execute arbitrary code.
- CVE-2002-20191 PoCPHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote attackers to execute…
- CVE-2002-20211 PoCCross-site scripting (XSS) vulnerability in WoltLab Burning Board (wbboard) 1.1.1 allows remote attackers to inject arbitrary web script…
- CVE-2002-20261 PoCBuffer overflow in BrowseFTP 1.62 client allows remote FTP servers to execute arbitrary code via a long FTP "220" message reply.
- CVE-2002-20291 PoCPHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and…
- CVE-2002-20312 PoCsInternet Explorer 5.0, 5.0.1 and 5.5 with JavaScript execution enabled allows remote attackers to determine the existence of arbitrary…
- CVE-2002-20321 PoCsql_layer.php in PHP-Nuke 5.4 and earlier does not restrict access to debugging features, which allows remote attackers to gain SQL query…
- CVE-2002-20391 PoC/bin/su in QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows local users to obtain sensitive information from core dump files by…
- CVE-2002-20402 PoCsThe (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges…
- CVE-2002-20412 PoCsMultiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG…
- CVE-2002-20421 PoCptrace in the QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows programs to attach to privileged processes, which could allow…
- CVE-2002-20551 PoCCross-site scripting (XSS) vulnerability in userlog.php in TeeKai Tracking Online 1.0 allows remote attackers to inject arbitrary web…
- CVE-2002-20621 PoCCross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder…
- CVE-2002-20711 PoCCompaq Tru64 4.0 d allows remote attackers to cause a denial of service in (1) telnet, (2) FTP, (3) ypbind, (4) rpc.lockd, (5) snmp, (6)…
- CVE-2002-20721 PoCjava.security.AccessController in Sun Java Virtual Machine (JVM) in JRE 1.2.2 and 1.3.1 allows remote attackers to cause a denial of…
- CVE-2002-20731 PoCCross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers…
- CVE-2002-20842 PoCsDirectory traversal vulnerability in index.php of Portix 0.4.02 allows remote attackers to read arbitrary files via a .. (dot dot) in the…
- CVE-2002-20874 PoCsBuffer overflow in Borland InterBase 6.0 allows local users to execute arbitrary code via a long INTERBASE environment variable when…
- CVE-2002-21051 PoCMicrosoft Windows XP allows local users to prevent the system from booting via a corrupt explorer.exe.manifest file.
- CVE-2002-21061 PoCPHP remote file inclusion vulnerability in WikkiTikkiTavi before 0.21 allows remote attackers to execute arbitrary PHP code via the…
- CVE-2002-21131 PoCsearch.cgi in AGH HTMLsearch 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the template parameter.
- CVE-2002-21231 PoCPHP remote file inclusion vulnerability in publish_xp_docs.php for Gallery 1.3.2 allows remote attackers to inject arbitrary PHP code by…
- CVE-2002-21291 PoCCross-site scripting vulnerability (XSS) in editform.php for w-Agora 4.1.5 allows remote attackers to execute arbitrary web script via an…
- CVE-2002-21301 PoCpublish_xp_docs.php in Gallery 1.3.2 allows remote attackers to execute arbitrary PHP code by modifying the GALLERY_BASEDIR parameter to…
- CVE-2002-21341 PoChaut.php in PEEL 1.0b allows remote attackers to execute arbitrary PHP code by modifying the dirroot parameter to reference a URL on a…
- CVE-2002-21431 PoCThe admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain…
- CVE-2002-21451 PoCSavant Web Server 3.1 and earlier allows remote attackers to bypass authentication for password protected user folders via a URL with a…
- CVE-2002-21491 PoCBuffer overflow in Lucent Access Point 300, 600, and 1500 Service Routers allows remote attackers to cause a denial of service (reboot)…
- CVE-2002-21542 PoCsDirectory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences.
- CVE-2002-21621 PoCCerulean Studios Trillian 0.73 and earlier use weak encrypttion (XOR) for storing user passwords in .ini files in the Trillian directory,…
- CVE-2002-21641 PoCBuffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (crash) via a long <A…
- CVE-2002-21651 PoCThe IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an error page, which…
- CVE-2002-21691 PoCCross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct…
- CVE-2002-21701 PoCWorking Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the…
- CVE-2002-21711 PoCCross-site scripting (XSS) vulnerability in acWEB 1.8 and 1.14 allows remote attackers to insert arbitrary HTML and web script via a URL,…
- CVE-2002-21741 PoCThe Telnet proxy of 602Pro LAN SUITE 2002 does not restrict the number of outstanding connections to the local host, which allows remote…
- CVE-2002-21762 PoCsSQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the…
- CVE-2002-21782 PoCsCross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute arbitrary…
- CVE-2002-21901 PoCArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the…
- CVE-2002-21911 PoCLotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obtain potential…
- CVE-2002-21922 PoCsCross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web script via (1) a…
- CVE-2002-21931 PoCCross-site scripting (XSS) vulnerability in mojo.cgi for Mojo Mail 2.7 allows remote attackers to inject arbitrary web script via the…
- CVE-2002-21952 PoCsBuffer overflow in the version update check for Winamp 2.80 and earlier allows remote attackers who can spoof www.winamp.com to execute…
- CVE-2002-22004 PoCsBenjamin Lefevre Dobermann FORUM 0.5 and earlier allows remote attackers to remotely include and execute malicious PHP files via the…
- CVE-2002-22171 PoCMultiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal (WSC-WebPortal) 0.1 allow remote attackers to…
- CVE-2002-22191 PoCchetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow file via a long…
- CVE-2002-22263 PoCsBuffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filename argument.
- CVE-2002-22321 PoCBuffer overflow in Enceladus Server Suite 3.9 allows remote attackers to execute arbitrary code via a long CD (CWD) command.
- CVE-2002-22351 PoCmember2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error…
- CVE-2002-22461 PoCCross-site scripting (XSS) vulnerability in VisNetic Website before 3.5.15 allows remote attackers to inject arbitrary web script or HTML…
- CVE-2002-22471 PoCThe administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information such as the full…
- CVE-2002-22491 PoCPHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands via the neurl…
- CVE-2002-22511 PoCBuffer overflow in the changevalue function in libcgi.h for Marcos Luiz Onisto Lib CGI 0.1 allows remote attackers to execute arbitrary…
- CVE-2002-22551 PoCCross-site scripting (XSS) vulnerability in search.php in phpBB 2.0.3 and possibly earlier versions allows remote attackers to inject…
- CVE-2002-22581 PoCMoby NetSuite allows remote attackers to cause a denial of service (crash) via an HTTP POST request with a (1) large integer or (2)…
- CVE-2002-22684 PoCsBuffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL.
- CVE-2002-22721 PoCTomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service…
- CVE-2002-22811 PoCSymantec Java! JIT (Just-In-Time) Compiler for Netscape Communicator 4.0 through 4.8 allows remote attackers to execute arbitrary Java…
- CVE-2002-22871 PoCPHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to…
- CVE-2002-22881 PoCMambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.php with a…
- CVE-2002-22951 PoCBuffer overflow in Pico Server (pServ) 2.0 beta 1 through beta 5 allows remote attackers to cause a denial of service (crash) and possibly…
- CVE-2002-22961 PoCCross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject…
- CVE-2002-22981 PoCPHP remote file inclusion vulnerability in config.php in Thatware 0.3 through 0.5.3 allows remote attackers to execute arbitrary PHP code…
- CVE-2002-23001 PoCBuffer overflow in ftpd 5.4 in 3Com NBX 4.0.17 or ftpd 5.4.2 in 3Com NBX 4.1.4 allows remote attackers to cause a denial of service…
- CVE-2002-23041 PoCSQL injection vulnerability in admin/auth/checksession.php in MyPHPLinks 2.1.9 and 2.2.0 allows remote attackers to execute arbitrary SQL…
- CVE-2002-23061 PoCSharman Networks KaZaA Media Desktop 1.7.1 allows remote attackers to cause a denial of service (CPU consumption) by sending several large…
- CVE-2002-23091 PoCphp.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of…
- CVE-2002-23121 PoCOpera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1)…
- CVE-2002-23141 PoCMozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline,…
- CVE-2002-23151 PoCCisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a denial of service…
- CVE-2002-23181 PoCCross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary…
- CVE-2002-23191 PoCStatic code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1)…
- CVE-2002-23211 PoCCross-site scripting (XSS) vulnerability in (1) showcat.php and (2) addyoursite.php in phpLinkat 0.1.0 allows remote attackers to inject…
- CVE-2002-23251 PoCThe c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote…
- CVE-2002-23351 PoCKiller Protection 1.0 stores the vars.inc include file under the web root with insufficient access control, which allows remote attackers…
- CVE-2002-23361 PoCNorton Personal Firewall 2002 4.0, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause…
- CVE-2002-23381 PoCThe POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of…
- CVE-2002-23391 PoCCross-site scripting (XSS) vulnerability in configure.asp in Script-Shed GuestBook 1.0 allows remote attackers to inject arbitrary web…
- CVE-2002-23411 PoCCross-site scripting (XSS) vulnerability in content blocking in SonicWALL SOHO3 6.3.0.0 allows remote attackers to inject arbitrary web…
- CVE-2002-23431 PoCCross-site scripting (XSS) vulnerability in NOCC 0.9 through 0.9.5 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2002-23481 PoCCross-site scripting (XSS) vulnerability in athcgi.exe in Authoria HR allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2002-23491 PoCphpinfo.php in phpBBmod 1.3.3 executes the phpinfo function, which allows remote attackers to obtain sensitive environment information.
- CVE-2002-23512 PoCsEudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with names containing a…
- CVE-2002-23531 PoCtftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests.
- CVE-2002-23571 PoCMailEnable 1.5 015 through 1.5 018 allows remote attackers to cause a denial of service (crash) via a long USER string, possibly due to a…
- CVE-2002-23581 PoCCross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject…
- CVE-2002-23591 PoCCross-site scripting (XSS) vulnerability in the FTP view feature in Mozilla 1.0 allows remote attackers to inject arbitrary web script or…
- CVE-2002-23601 PoCThe RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to…
- CVE-2002-23621 PoCCross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or…
- CVE-2002-23702 PoCsSWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request that does not end…
- CVE-2002-23761 PoCCross-site scripting (XSS) vulnerability in E-Guest_sign.pl in E-Guest 1.1 allows remote attackers to inject arbitrary SSI directives, web…
- CVE-2002-23791 PoCCisco AS5350 IOS 12.2(11)T with access control lists (ACLs) applied and possibly with ssh running allows remote attackers to cause a…
- CVE-2002-23851 PoCBuffer overflow in hotfoon4.exe in Hotfoon 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary…
- CVE-2002-23991 PoCDirectory traversal vulnerability in viewAttachment.cgi in W3Mail 1.0.6 allows remote attackers to read arbitrary files via a .. (dot dot)…
- CVE-2002-24001 PoCBuffer overflow in the httpdProcessRequest function in LibHTTPD 1.2 allows remote attackers to cause a denial of service (crash) and…
- CVE-2002-24031 PoCDirectory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type…
- CVE-2002-24041 PoCBuffer overflow in IISPop email server 1.161 and 1.181 allows remote attackers to cause a denial of service (crash) via a long request to…
- CVE-2002-24162 PoCsDirectory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET…
- CVE-2002-24171 PoCacFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers…
- CVE-2002-24201 PoCsite_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters in the page…
- CVE-2002-24221 PoCCross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remote attackers to…
- CVE-2002-24241 PoCCross-site scripting (XSS) vulnerability in PHP(Reactor) 1.2.7 pl1 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2002-24251 PoCSun AnswerBook2 1.2 through 1.4.2 allows remote attackers to execute administrative scripts such as (1) AdminViewError and (2)…