Search Results (29862 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2002-1711 1 Basilix 1 Basilix Webmail 2025-04-03 N/A
BasiliX 1.1.0 saves attachments in a world readable /tmp/BasiliX directory, which allows local users to read other users' attachments.
CVE-2002-1720 1 Outfront 1 Spooky Login 2025-04-03 N/A
SQL injection vulnerability in Spooky Login 2.0 through 2.5 allows remote attackers to bypass authentication and gain privileges via the password field.
CVE-2004-1654 1 Phpwebsite 1 Phpwebsite 2025-04-03 N/A
SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commands via cal_template.
CVE-2005-0780 1 Php Arena 1 Pafiledb 2025-04-03 N/A
paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php, (4) file.php, (5) team.php, (6) license.php, (7) custom.php, (8) admins.php, or (9) backupdb.php, which reveal the path in a PHP error message.
CVE-2002-1724 1 Onlinetools.org 1 Phpimageview 2025-04-03 N/A
Cross-site scripting vulnerability (XSS) in phpimageview.php for PHPImageView 1.0 allows remote attackers to execute arbitrary script as other users via the pic parameter.
CVE-2002-1725 1 Onlinetools.org 1 Phpimageview 2025-04-03 N/A
phpimageview.php in PHPImageView 1.0 allows remote attackers to obtain sensitive information via the pw=show option, which invokes the phpinfo function.
CVE-2002-1727 1 Asksam Systems 1 Asksam Web Publisher 2025-04-03 N/A
Cross-site scripting vulnerability (XSS) in (1) as_web.exe and (2) as_web4.exe in askSam Web Publisher 1 and 4 allows remote attackers to execute arbitrary script as other users via a URL.
CVE-2002-1728 1 Asksam Systems 1 Asksam Web Publisher 2025-04-03 N/A
askSam Web Publisher 1.0 and 4.0 allows remote attackers to determine the full path to the web root directory via a request for a file that does not exist, which generates an error message that reveals the full path.
CVE-2002-1729 1 Aspjar 1 Aspjar Guestbook 2025-04-03 N/A
Cross-site scripting vulnerability (XSS) in ASPjar Guestbook 1.00 allows remote attackers to execute arbitrary script as other users via the "web site" parameter in a guestbook message.
CVE-2002-1723 1 Powerboards 1 Powerboards 2025-04-03 N/A
Powerboards 2.2b allows remote attackers to view the full path to the backend database by sending a cookie containing a non-existent username to profiles.php, which displays the full path in the error message.
CVE-2002-1733 1 Prospero Technologies 1 Prospero Message Board 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in the web-based message board in Prospero Technologies allows remote attackers to inject arbitrary web script or HTML via a message board post.
CVE-2002-1734 1 Aspbin 1 Newspro 2025-04-03 N/A
NewsPro 1.01 allows remote attackers to gain unauthorized administrator access by setting their authentication cookie to "logged,true".
CVE-2002-1735 1 Davin Mccall 1 Dlogin 2025-04-03 N/A
Buffer overflow in dlogin 1.0a could allow local users to gain privileges via unknown attack vectors.
CVE-2002-1736 1 Markus Triska 1 Cginews 2025-04-03 N/A
Unknown vulnerability in CGINews before 1.06 allow remote attackers to read arbitrary files via "unfiltered user input."
CVE-2002-1737 1 Astaro 1 Security Linux 2025-04-03 N/A
Astaro Security Linux 2.016 creates world-writable files and directories, which allows local users to overwrite arbitrary files.
CVE-2002-1738 1 Alt-n 1 Mdaemon 2025-04-03 N/A
Alt-N Technologies MDaemon 5.0.5.0 and earlier creates a default MDaemon mail account with a password of MServer, which could allow remote attackers to send anonymous email.
CVE-2002-1740 1 Alt-n 2 Mdaemon, Worldclient 2025-04-03 N/A
Buffer overflow in WorldClient.cgi in WorldClient in Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to execute arbitrary code via a long folder name (NewFolder parameter).
CVE-2002-1741 1 Alt-n 1 Worldclient 2025-04-03 N/A
Directory traversal vulnerability in WorldClient.cgi in WorldClient for Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to delete arbitrary files via a ".." (dot dot) in the Attachments parameter.
CVE-2002-1742 1 Paul Kulchenko 1 Soap Lite 2025-04-03 N/A
SOAP::Lite 0.50 through 0.52 allows remote attackers to load arbitrary Perl functions by suppling a non-existent function in a script using a SOAP::Lite module, which causes the AUTOLOAD subroutine to trigger.
CVE-2002-1743 1 Mirabilis 1 Icq 2025-04-03 N/A
AOL ICQ 2002a Build 3722 allows remote attackers to cause a denial of service (crash) via a malformed .hpf file.