Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2002-0978

EPSS 6.20% · P91
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2002-0978

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to upload or download arbitrary files to arbitrary locations via a man-in-the-middle attack with modified TGT and TGN parameters in a call to the "Persist" function.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft File Transfer Manager远程任意文件上传/下载漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
文件传输管理程序(File Transfer Manager (FTM))用于Microsoft beta程序测试员,MSDN,Microsoft Volume Licensing服务等从Microsoft站上下载软件。 文件传输管理程序(FTM)ActiveX控件中的"Persist"函数对部分参数存在问题,远程攻击者可以利用这个漏洞在用户系统中上传/下载任意文件。 文件传输管理程序(FTM)ActiveX控件在调用"Persist"对"TGT="和"TGN="参数的值缺少正确检查,可以导致在不需要用户
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2002-0978

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2002-0978

登录查看更多情报信息。

Same Patch Batch · n/a · 2002-08-23 · 12 CVEs total

CVE-2002-0834Ethereal ISIS dissector缓冲区溢出漏洞
CVE-2002-0861Microsoft OWC剪贴板信息泄露漏洞
CVE-2002-0971Windows下的多个VNC产品窗口消息子系统设计错误漏洞
CVE-2002-0972PostgreSQL字符串填充函数本地缓冲区溢出漏洞
CVE-2002-0973FreeBSD系统调用有符号整数边界检查漏洞
CVE-2002-0975Microsoft DirectX Files Viewer ActiveX控件远程缓冲区溢出漏洞
CVE-2002-0976Microsoft Internet Explorer 安全漏洞
CVE-2002-0977Microsoft File Transfer Manager ActiveX控件远程缓冲区溢出漏洞
CVE-2002-0979Microsoft Internet Explorer Java记录远程执行代码漏洞
CVE-2002-0980Microsoft Internet Explorer安全漏洞
CVE-2002-0982Microsoft SQL Server漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2002-0978

No comments yet


Leave a comment