CVE-2002-0468
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 0.8%
from disclosure to weapon0 days
Published on NVDJun 11
1st PoCFeb 27
exploitation probability
0.8%top 46% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privileges via (1) a long command line argument, which is not properly handled in core.c, or possibly via bad uses of sprintf() in (2) moderate.c, (3) lcgi.c, (4) fileapi.c, (5) cookie.c, (6) codes.c, or other files.
Affected products
n/a · n/apublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/21341exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/21342⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://marc.info/?l=listar-support&m=101590272221720&w=2http://online.securityfocus.com/archive/1/269658http://online.securityfocus.com/archive/1/269879http://online.securityfocus.com/archive/82/258763http://www.ecartis.org/http://www.iss.net/security_center/static/8445.phphttp://www.securityfocus.com/archive/1/261209http://www.securityfocus.com/bid/4271