Show filters
486 Total Results
Displaying 401-410 of 486
Sort by:
Attacker Value
Unknown
CVE-2002-1658
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
0
Attacker Value
Unknown
CVE-2002-2269
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Directory traversal vulnerability in Webster HTTP Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
0
Attacker Value
Unknown
CVE-2002-2416
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request.
0
Attacker Value
Unknown
CVE-2002-2273
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Webster HTTP Server allows remote attackers to inject arbitrary web script or HTML via the URL.
0
Attacker Value
Unknown
CVE-2002-2029
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.
0
Attacker Value
Unknown
CVE-2002-2268
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL.
0
Attacker Value
Unknown
CVE-2002-2103
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
0
Attacker Value
Unknown
CVE-2002-1825
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Format string vulnerability in PerlRTE_example1.pl in WASD 7.1, 7.2.0 through 7.2.3, and 8.0.0 allows remote attackers to execute arbitrary commands or crash the server via format strings in the $name variable.
0
Attacker Value
Unknown
CVE-2002-1233
Disclosure Date: November 04, 2002 (last updated February 22, 2025)
A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.
0
Attacker Value
Unknown
CVE-2002-1178
Disclosure Date: October 11, 2002 (last updated February 22, 2025)
Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (dot-dot backslash) sequences in an HTTP request to the cgi-bin directory.
0