CVE Database - 2002

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

110
Matching CVEs
15853
Critical
26962
High
69389
High WAF Coverage

CVE-2002-1651

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Verity Search97 allows remote attackers to insert arbitrary web content and steal sensitive information from other clients, possibly due to certain error messages from template pages that use the (1) vformat or (2) vfilter functions.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-1660

HIGH
7.50 CVSS 2.0

calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.

OS Command Injection
WAF: High

CVE-2002-1663

MEDIUM
5.00 CVSS 2.0

The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a POST request with an invalid or missing Content-Length header value.

Improper Input Validation
WAF: Medium

CVE-2002-1700

MEDIUM
4.30 CVSS 2.0

Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-1750

HIGH
7.50 CVSS 2.0

csGuestbook.cgi in CGISCRIPT.NET csGuestbook 1.0 allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.

Code Injection
WAF: Medium

CVE-2002-1752

HIGH
7.50 CVSS 2.0

csChatRBox.cgi in CGIScript.net csChat-R-Box allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.

Code Injection
WAF: Medium

CVE-2002-1753

HIGH
7.50 CVSS 2.0

csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.

Code Injection
WAF: Medium

CVE-2002-1841

MEDIUM
5.00 CVSS 2.0

The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to upload and execute arbitrary PHP files with extensions such as .php4.

Unrestricted File Upload
WAF: Medium

CVE-2002-1852

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) a parameter to test2.pl.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-1873

MEDIUM
5.00 CVSS 2.0

Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls.

Uncontrolled Resource Consumption
WAF: Medium

CVE-2002-1874

HIGH
10.00 CVSS 2.0

astrocam.cgi in AstroCam 0.9-1-1 through 1.4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request. NOTE: earlier disclosures stated that the affected versions were 1.7.1 through 2.1.2, but the vendor explicitly stated that these were incorrect.

Improper Input Validation
WAF: Medium

CVE-2002-1876

LOW
2.10 CVSS 2.0

Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, which consumes all of the licenses that are granted to Exchange by IIS.

Uncontrolled Resource Consumption
WAF: Medium

CVE-2002-1898

HIGH
7.20 CVSS 2.0

Terminal 1.3 in Apple Mac OS X 10.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a telnet:// link, which is executed by Terminal.app window.

OS Command Injection
WAF: High

CVE-2002-1958

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in kmMail 1.0, 1.0a, and 1.0b allows remote attackers to inject arbitrary web script or HTML via (1) javascript in onmouseover or other attributes in "safe" HTML tags such as the "b" tag, or (2) the Subject field.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-1979

HIGH
7.50 CVSS 2.0

WatchGuard SOHO products running firmware 5.1.6 and earlier, and Vclass/RSSA using 3.2 SP1 and earlier, allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server, which generates a response that contains the string, causing IPFilter to treat the response as if it were a legitimate PASV command from the server.

Improper Input Validation
WAF: Medium

CVE-2002-1991

HIGH
7.50 CVSS 2.0

PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.

Code Injection
WAF: Medium

CVE-2002-2019

HIGH
7.50 CVSS 2.0

PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote attackers to execute arbitrary PHP code via the include_file parameter.

Code Injection
WAF: Medium

CVE-2002-2154

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences.

Path Traversal
WAF: High

CVE-2002-2228

MEDIUM
6.40 CVSS 2.0

MailScanner before 4.0 5-1 and before 3.2 6-1 allows remote attackers to bypass protection via attachments with a filename with (1) extra leading spaces, (2) extra trailing spaces, or (3) alternate character encodings that cannot be processed by MailScanner.

Improper Input Validation
WAF: Medium

CVE-2002-2229

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in Sapio Design Ltd. WebReflex 1.53 allows remote attackers to read arbitrary files via a .. in an HTTP request.

Path Traversal
WAF: High

CVE-2002-2230

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Ikonboard 3.1.1 allows remote attackers to inject arbitrary web script or HTML via a private message with a javascript: URL in the IMG tag, in which the URL ends in a ".gif" or ".jpg" string, a variant of CVE-2002-0328.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2231

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Ikonboard 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) a javascript: URL in a photo URL or (2) an X-Forwarded-For: header.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2233

HIGH
8.30 CVSS 2.0

Directory traversal vulnerability in Enceladus Server Suite 3.9 allows remote attackers to list arbitrary directories and possibly cause a denial of service via "@" (at) characters in a CD (CWD) command, such as (1) "@/....\", (2) "@@@/..c:\", or (3) "@/..@/..".

Path Traversal
WAF: High

CVE-2002-2236

HIGH
10.00 CVSS 2.0

Format string vulnerability in the awp_log function in apt-www-proxy 0.1 allows remote attackers to execute arbitrary code.

Improper Input Validation
WAF: Medium

CVE-2002-2237

MEDIUM
5.00 CVSS 2.0

tftp32 TFTP server 2.21 and earlier allows remote attackers to cause a denial of service via a GET request with a DOS device name such as com1 or aux.

Improper Input Validation
WAF: Medium

CVE-2002-2238

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in the Kunani ODBC FTP Server 1.0.10 allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in a GET request.

Path Traversal
WAF: High

CVE-2002-2239

HIGH
7.80 CVSS 2.0

The Cisco Optical Service Module (OSM) for the Catalyst 6500 and 7600 series running Cisco IOS 12.1(8)E through 12.1(13.4)E allows remote attackers to cause a denial of service (hang) via a malformed packet.

Improper Input Validation
WAF: Medium

CVE-2002-2240

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in MyServer 0.11 and 0.2 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP GET request.

Path Traversal
WAF: High

CVE-2002-2246

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in VisNetic Website before 3.5.15 allows remote attackers to inject arbitrary web script or HTML via the HTTP referer header (HTTP_REFERER) to a non-existent page, which is injected into the resulting 404 error page.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2249

HIGH
7.50 CVSS 2.0

PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands via the neurl parameter to (1) backend.php, (2) screen.php, or (3) admin/modules/comment.php.

Code Injection
WAF: Medium

CVE-2002-2252

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in auth.inc.php in Thatware 0.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via a base64-encoded user parameter.

SQL Injection
WAF: High

CVE-2002-2255

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in search.php in phpBB 2.0.3 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the search_username parameter in searchuser mode.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2256

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in pWins Webserver 0.2.5 and earlier allows remote attackers to read arbitrary files via Unicode characters.

Path Traversal
WAF: High

CVE-2002-2260

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the quips feature in Mozilla Bugzilla 2.10 through 2.17 allows remote attackers to inject arbitrary web script or HTML via the "show all quips" page.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2269

HIGH
9.40 CVSS 2.0

Directory traversal vulnerability in Webster HTTP Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

Path Traversal
WAF: High

CVE-2002-2273

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Webster HTTP Server allows remote attackers to inject arbitrary web script or HTML via the URL.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2277

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to execute arbitrary SQL commands via the (1) $rech, (2) $BD_Tab_docs, (3) $BD_Tab_file, (4) $BD_Tab_liens, (5) $BD_Tab_faq, or (6) $chemin variables.

SQL Injection
WAF: High

CVE-2002-2278

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to inject arbitrary web script or HTML via the (1) $App_Theme, (2) $Rub_Search, (3) $Rub_News, (4) $Rub_File, (5) $Rub_Liens, or (6) $Rub_Faq variables.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2279

HIGH
10.00 CVSS 2.0

Unspecified vulnerability in the bind function in config.inc of aldap 0.09 allows remote attackers to authenticate with Manager permissions.

Improper Authentication
WAF: Low

CVE-2002-2287

HIGH
7.50 CVSS 2.0

PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.

Code Injection
WAF: Medium

CVE-2002-2292

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in Remote Console Applet in Halycon Software iASP 1.0.9 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request to port 9095.

Path Traversal
WAF: High

CVE-2002-2296

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbitrary web script or HTML via the num parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2297

MEDIUM
6.80 CVSS 2.0

PHP remote file inclusion vulnerability in artlist.php in Thatware 0.5.2 and 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter.

Code Injection
WAF: Medium

CVE-2002-2298

MEDIUM
6.80 CVSS 2.0

PHP remote file inclusion vulnerability in config.php in Thatware 0.3 through 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter.

Code Injection
WAF: Medium

CVE-2002-2299

MEDIUM
6.80 CVSS 2.0

PHP remote file inclusion vulnerability in thatfile.php in Thatware 0.3 through 0.5.2 allows remote attackers to execute arbitrary PHP code via the root_path parameter.

Code Injection
WAF: Medium

CVE-2002-2304

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in admin/auth/checksession.php in MyPHPLinks 2.1.9 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the idsession parameter.

SQL Injection
WAF: High

CVE-2002-2305

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in agentadmin.php in Immobilier allows remote attackers to execute arbitrary SQL commands via the (1) agentname or (2) agentpassword parameter.

SQL Injection
WAF: High

CVE-2002-2314

MEDIUM
5.00 CVSS 2.0

Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which causes the host/path check to fail.

Improper Input Validation
WAF: Medium

CVE-2002-2318

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary web script or HTML via the URI, which is inserted into 301 error messages and executed by 404 error messages.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2319

HIGH
7.50 CVSS 2.0

Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2) DATA, and (3) MESS parameters, which are inserted into news.php3.

Code Injection
WAF: Medium
Page 1 of 3 (110 CVEs)