CVE Database - 2002

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

110
Matching CVEs
15853
Critical
26962
High
69389
High WAF Coverage

CVE-2002-2321

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in (1) showcat.php and (2) addyoursite.php in phpLinkat 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the catid parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2322

MEDIUM
5.00 CVSS 2.0

Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords.

Improper Input Validation
WAF: Medium

CVE-2002-2325

HIGH
7.80 CVSS 2.0

The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote attackers to cause a denial of service (client crash) via a MIME-encoded email with Content-Type header containing an empty boundary field.

Improper Input Validation
WAF: Medium

CVE-2002-2328

HIGH
7.10 CVSS 2.0

Active Directory in Windows 2000, when supporting Kerberos V authentication and GSSAPI, allows remote attackers to cause a denial of service (hang) via an LDAP client that sets the page length to zero during a large request.

Improper Input Validation
WAF: Medium

CVE-2002-2329

HIGH
7.80 CVSS 2.0

ICQ client 2001b, 2002a and 2002b allows remote attackers to cause a denial of service (CPU consumption or crash) via a message with a large number of emoticons.

Improper Input Validation
WAF: Medium

CVE-2002-2330

MEDIUM
5.00 CVSS 2.0

Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to inject arbitrary web script or HTML via (1) HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to stats.html and executed in client browsers.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2338

MEDIUM
5.00 CVSS 2.0

The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message.

Improper Input Validation
WAF: Medium

CVE-2002-2339

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in configure.asp in Script-Shed GuestBook 1.0 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in (1) image, (2) img, (3) image=right, (4) img=right, (5) image=left, and (6) img=left tags.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2340

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in read.php in Phorum 3.3.2a allows remote attackers to inject arbitrary web script or HTML via (1) the t parameter or (2) the body of an email response.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2341

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in content blocking in SonicWALL SOHO3 6.3.0.0 allows remote attackers to inject arbitrary web script or HTML via a blocked URL.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2343

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in NOCC 0.9 through 0.9.5 allows remote attackers to inject arbitrary web script or HTML via email messages.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2347

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Oracle Java Server Page (OJSP) demo files (1) hellouser.jsp, (2) welcomeuser.jsp and (3) usebean.jsp in Oracle 9i Application Server 9.0.2, 1.0.2.2, 1.0.2.1s and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the text entry field.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2348

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in athcgi.exe in Authoria HR allows remote attackers to inject arbitrary web script or HTML via the command parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2350

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in z_user_show.php in dbtreelistproperty_method.php in Zorum 2.4 allows remote attackers to inject arbitrary web script or HTML via the class parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2351

MEDIUM
6.40 CVSS 2.0

Eudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with names containing a trailing "." (dot).

Path Traversal
WAF: High

CVE-2002-2354

HIGH
7.80 CVSS 2.0

Netgear FM114P firmware 1.3 wireless firewall allows remote attackers to cause a denial of service (crash or hang) via a large number of TCP connection requests.

Improper Input Validation
WAF: Medium

CVE-2002-2358

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject arbitrary web script or HTML via the title tag of an FTP URL.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2359

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the FTP view feature in Mozilla 1.0 allows remote attackers to inject arbitrary web script or HTML via the title tag of an ftp URL.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2362

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML via the noticemsg parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2364

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a help ticket.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2365

HIGH
10.00 CVSS 2.0

Simple WAIS (SWAIS) 1.11 allows remote attackers to execute arbitrary commands via the shell metacharacters in the search field, as demonstrated using the "|" (pipe) character.

Improper Input Validation
WAF: Medium

CVE-2002-2371

HIGH
7.80 CVSS 2.0

Linksys WET11 firmware 1.31 and 1.32 allows remote attackers to cause a denial of service (crash) via a packet containing the device's hardware address as the source MAC address in the DLC header.

Improper Input Validation
WAF: Medium

CVE-2002-2375

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in CommuniGate Pro 4.0b4 and possibly earlier versions allows remote attackers to list the contents of the WebUser directory and its parent directory via a (1) .. (dot dot) or (2) . (dot) in a URL. NOTE: it is not clear whether this issue reveals any more information regarding directory structure than is already available to any CommuniGate Pro user, although there is a possibility that it could be used to infer product version information.

Path Traversal
WAF: High

CVE-2002-2376

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in E-Guest_sign.pl in E-Guest 1.1 allows remote attackers to inject arbitrary SSI directives, web script, and HTML via the (1) full name, (2) email, (3) homepage, and (4) location parameters. NOTE: this issue might overlap CVE-2005-1605.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2377

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in addentry.cgi in ZAP 1.0.3 allows remote attackers to inject arbitrary SSi directives, web script, and HTML via the entry field.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2378

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in AN HTTP 1.41d allows remote attackers to inject arbitrary web script or HTML via a colon (:) in the query string, which is inserted into the resulting error page.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2383

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in f2html.pl 0.1 through 0.4 allows remote attackers to execute arbitrary SQL commands via file names.

SQL Injection
WAF: High

CVE-2002-2386

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the Quizz module for XOOPS 1.0, when allowing on-line question development, allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in the SRC attribute of an IMG tag.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2387

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in Hyperion FTP server 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the LS command.

Path Traversal
WAF: High

CVE-2002-2391

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in index.php of WebChat 1.5 included in XOOPS 1.0 allows remote attackers to execute arbitrary SQL commands via the roomid parameter.

SQL Injection
WAF: High

CVE-2002-2393

MEDIUM
5.00 CVSS 2.0

Serv-U FTP server 3.0, 3.1 and 4.0.0.4 does not accept new connections while validating user folder access rights, which allows remote attackers to cause a denial of service (no new connections) via a series of MKD commands.

Improper Input Validation
WAF: Medium

CVE-2002-2397

HIGH
10.00 CVSS 2.0

Sygate personal firewall 5.0 could allow remote attackers to bypass firewall filters via spoofed (1) source IP address of 127.0.0.1 or (2) network address of 127.0.0.0.

Improper Authentication
WAF: Low

CVE-2002-2399

MEDIUM
6.40 CVSS 2.0

Directory traversal vulnerability in viewAttachment.cgi in W3Mail 1.0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

Path Traversal
WAF: High

CVE-2002-2403

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences.

Path Traversal
WAF: High

CVE-2002-2406

MEDIUM
5.00 CVSS 2.0

Buffer overflow in HTTP server in LiteServe 2.0, 2.0.1 and 2.0.2 allows remote attackers to cause a denial of service (hang) via a large number of percent characters (%) in an HTTP GET request.

Improper Input Validation
WAF: Medium

CVE-2002-2415

MEDIUM
6.80 CVSS 2.0

Allied Telesyn AT-8024 1.3.1 and Rapier 24 switches allow remote authenticated users to cause a denial of service in the management interface via a stream of zero (null) bytes sent via UDP to a running service.

Improper Input Validation
WAF: Medium

CVE-2002-2416

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request.

Path Traversal
WAF: High

CVE-2002-2417

HIGH
10.00 CVSS 2.0

acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or misrepresent certain activity from log files and possibly gain privileges.

Improper Authentication
WAF: Low

CVE-2002-2418

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in acFreeProxy (aka acFP) 1.33 beta 7 allows remote attackers to inject arbitrary web script or HTML via the URL, which is inserted into an error page.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2420

HIGH
7.50 CVSS 2.0

site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.

Improper Input Validation
WAF: Medium

CVE-2002-2421

HIGH
7.80 CVSS 2.0

acWEB 1.14 allows remote attackers to cause a denial of service (crash) via an HTTP request for a MS-DOS device name such as COM2.

Improper Input Validation
WAF: Medium

CVE-2002-2422

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remote attackers to inject arbitrary web script or HTML via a URL, which inserts the script into the resulting error message.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2423

MEDIUM
6.40 CVSS 2.0

Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address from being logged via a long IDENT response.

Improper Input Validation
WAF: Medium

CVE-2002-2424

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in PHP(Reactor) 1.2.7 pl1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the style attribute of an HTML tag.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-2426

MEDIUM
4.30 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1.0 through 2.0 allows remote attackers to execute arbitrary published applications, and possibly other programs, as authenticated users via the InitialProgram key in an ICA connection. NOTE: some of these details are obtained from third party information.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2002-1358

HIGH
10.00 CVSS 2.0

Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.

Improper Input Validation
WAF: Medium

CVE-2002-1359

HIGH
10.00 CVSS 2.0

Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.

Improper Input Validation
WAF: Medium

CVE-2002-1360

HIGH
10.00 CVSS 2.0

Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite.

Improper Input Validation
WAF: Medium

CVE-2002-1175

MEDIUM
5.00 CVSS 2.0

The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a malicious DNS server, which allows remote attackers to cause a denial of service (crash) when Fetchmail attempts to read data beyond the expected boundary.

Improper Input Validation
WAF: Medium

CVE-2002-0999

HIGH
7.50 CVSS 2.0

Multiple SQL injection vulnerabilities in CARE 2002 before beta 1.0.02 allow remote attackers to perform unauthorized database operations.

SQL Injection
WAF: High
Page 2 of 3 (110 CVEs)