Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2001-12-18 CVE-2001-1213 Unspecified vulnerability in Datawizard Ftpxq 2.0/2.1
The default configuration of DataWizard FtpXQ 2.0 and 2.1 includes a default username and password, which allows remote attackers to read and write arbitrary files in the root folder.
network
low complexity
datawizard
6.4
2001-12-18 CVE-2001-1212 Cross-Site Scripting vulnerability in Aktivate 1.03
Cross-site scripting vulnerability in catgy.cgi for Aktivate 1.03 allows remote attackers to execute arbitrary Javascript via the desc parameter.
network
low complexity
aktivate
5.0
2001-12-17 CVE-2001-1448 Local Security vulnerability in Edeveloper
Magic eDeveloper Enterprise Edition 8.30-5 and earlier allows local users to overwrite arbitrary files and possibly execute code via a symlink attack on temporary files created by the (1) mkuserproc, (2) mgrnt, and (3) mgdatasrvr.sc scripts.
local
low complexity
magic
4.6
2001-12-17 CVE-2001-1201 Unspecified vulnerability in Timecop Wmcube GDK 0.98
Buffer overflow in wmcube-gdk for WMCube/GDK 0.98 allows local users to execute arbitrary code via long lines in the object description file.
local
low complexity
timecop
7.2
2001-12-17 CVE-2001-1200 Unspecified vulnerability in Microsoft Windows XP
Microsoft Windows XP allows local users to bypass a locked screen and run certain programs that are associated with Hot Keys.
local
low complexity
microsoft
7.2
2001-12-17 CVE-2001-1199 Cross-Site Scripting vulnerability in Agora.CGI Debug Mode
Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote attackers to execute Javascript on other clients via the cart_id parameter.
network
low complexity
steve-kneizys
7.5
2001-12-17 CVE-2001-1196 Directory Traversal vulnerability in Webmin 0.91
Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argument.
network
low complexity
webmin
critical
10.0
2001-12-15 CVE-2001-1214 Unspecified vulnerability in Marcus S. Xenakis Unix Manual 1.0
manual.php in Marcus S.
network
low complexity
marcus-s-xenakis
7.5
2001-12-15 CVE-2001-1198 Unspecified vulnerability in HP Hp-Ux
RLPDaemon in HP-UX 10.20 and 11.0 allows local users to overwrite arbitrary files and gain privileges by specifying the target file in the -L option.
local
low complexity
hp
7.2
2001-12-15 CVE-2001-1195 Authentication vulnerability in Novell Groupwise Servlet Gateway Default
Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager, which allows remote attackers to gain privileges.
network
low complexity
novell
7.5