{"api_version":"1","generated_at":"2026-07-23T03:37:40+00:00","cve":"CVE-2002-0437","urls":{"html":"https://cve.report/CVE-2002-0437","api":"https://cve.report/api/cve/CVE-2002-0437.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0437","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0437"},"summary":{"title":"CVE-2002-0437","description":"Smsd in SMS Server Tools (SMStools) before 1.4.8 allows remote attackers to execute arbitrary commands via shell metacharacters (backquotes) in message text, as described with the term \"string format vulnerability\" by some sources.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-07-26 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://archives.neohapsis.com/archives/bugtraq/2002-03/0103.html","name":"http://archives.neohapsis.com/archives/bugtraq/2002-03/0103.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Neohapsis Archives - Bugtraq - SMStools vulnerabilities in release before 1.4.8 - From m.magnifico@fabbricadigitale.it","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.isis.de/members/~s.frings/smstools/history.html","name":"http://www.isis.de/members/~s.frings/smstools/history.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Request failed","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/4268","name":"http://www.securityfocus.com/bid/4268","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"SMS Server Tools Arbitrary Command Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.iss.net/security_center/static/8433.php","name":"http://www.iss.net/security_center/static/8433.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"ISS X-Force Database: sms-tools-format-string (8433): SMS Server Tools format string attack","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0437","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0437","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"437","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"stefan_frings","cpe5":"sms_server_tools","cpe6":"1.4.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"437","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"stefan_frings","cpe5":"sms_server_tools","cpe6":"1.4.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:49:28.370Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.isis.de/members/~s.frings/smstools/history.html"},{"name":"4268","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4268"},{"name":"sms-tools-format-string(8433)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/8433.php"},{"name":"20020311 SMStools vulnerabilities in release before 1.4.8","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2002-03/0103.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-03-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Smsd in SMS Server Tools (SMStools) before 1.4.8 allows remote attackers to execute arbitrary commands via shell metacharacters (backquotes) in message text, as described with the term \"string format vulnerability\" by some sources."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2002-06-15T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.isis.de/members/~s.frings/smstools/history.html"},{"name":"4268","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4268"},{"name":"sms-tools-format-string(8433)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/8433.php"},{"name":"20020311 SMStools vulnerabilities in release before 1.4.8","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2002-03/0103.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0437","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Smsd in SMS Server Tools (SMStools) before 1.4.8 allows remote attackers to execute arbitrary commands via shell metacharacters (backquotes) in message text, as described with the term \"string format vulnerability\" by some sources."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.isis.de/members/~s.frings/smstools/history.html","refsource":"CONFIRM","url":"http://www.isis.de/members/~s.frings/smstools/history.html"},{"name":"4268","refsource":"BID","url":"http://www.securityfocus.com/bid/4268"},{"name":"sms-tools-format-string(8433)","refsource":"XF","url":"http://www.iss.net/security_center/static/8433.php"},{"name":"20020311 SMStools vulnerabilities in release before 1.4.8","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2002-03/0103.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0437","datePublished":"2003-04-02T05:00:00.000Z","dateReserved":"2002-06-07T00:00:00.000Z","dateUpdated":"2024-08-08T02:49:28.370Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-07-26 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:stefan_frings:sms_server_tools:1.4.6:*:*:*:*:*:*:*","matchCriteriaId":"AA8F3D85-2811-4378-A1A6-3DE1AAA7A58D"},{"vulnerable":true,"criteria":"cpe:2.3:a:stefan_frings:sms_server_tools:1.4.7:*:*:*:*:*:*:*","matchCriteriaId":"5C51E72E-C03B-4601-932E-CD3D49F303EE"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"437","Ordinal":"1","Title":"CVE-2002-0437","CVE":"CVE-2002-0437","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"437","Ordinal":"1","NoteData":"Smsd in SMS Server Tools (SMStools) before 1.4.8 allows remote attackers to execute arbitrary commands via shell metacharacters (backquotes) in message text, as described with the term \"string format vulnerability\" by some sources.","Type":"Description","Title":"CVE-2002-0437"},{"CveYear":"2002","CveId":"437","Ordinal":"2","NoteData":"2003-04-02","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"437","Ordinal":"3","NoteData":"2002-06-15","Type":"Other","Title":"Modified"}]}}}