Vendorssoftware602602pro_lan_suite2002
Vulnerabilities

software602 602pro LAN Suite 2002

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2002-2152
The Czech edition of Software602's Web Server before 2002.0.02.0916 allows remote attackers to gain administrator privileges via direct HTTP requests to the /admin/ directory, which is not password protected.
Published 2005-11-16 · Modified
10.0EPSS 0.024
CVE-2004-0337
Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary script or HTML as other users via a URL to index.html, followed by a / (slash) and the desired script. NOTE: the vendor states that this bug could not be reproduced, so this issue may be REJECTed in the future.
Published 2004-03-18 · Modified
6.81 PoCEPSS 0.020
CVE-2002-2174
The Telnet proxy of 602Pro LAN SUITE 2002 does not restrict the number of outstanding connections to the local host, which allows remote attackers to create a denial of service (memory consumption) via a large number of connections.
Published 2005-11-16 · Modified
5.01 PoCEPSS 0.025
CVE-2004-0336
LAN SUITE Web Mail 602Pro allows remote attackers to gain sensitive information via the mail login form, which contains the path to the mail directory.
Published 2004-09-01 · Modified
5.0EPSS 0.015
CVE-2002-1928
602Pro LAN SUITE 2002 allows remote attackers to view the directory tree via an HTTP GET request with a trailing "~" (tilde) or ".bak" extension.
Published 2005-06-28 · Modified
5.0EPSS 0.012