Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 308 304

Количество 308 304

nvd логотип

CVE-2003-1428

больше 21 года назад

Gallery 1.3.3 creates directories with insecure permissions, which allows local users to read, modify, or delete photos.

CVSS2: 4.8
EPSS: Низкий
nvd логотип

CVE-2003-1427

больше 21 года назад

Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary files, such as the netgear.cfg configuration file, via a hex-encoded (%2e%2e%2f) ../ (dot dot slash) in the port parameter.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2003-1426

больше 21 года назад

Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to Perl's @INC include array, which allows local users to execute arbitrary code by modifying SCRIPT_FILENAME to reference a directory containing a malicious openwebmail-shared.pl executable.

CVSS2: 3.3
EPSS: Низкий
nvd логотип

CVE-2003-1425

больше 21 года назад

guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2003-1424

больше 21 года назад

message.php in Petitforum does not properly authenticate users, which allows remote attackers to impersonate forum users via a modified connect cookie.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2003-1423

больше 21 года назад

Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as e-mail addresses and encrypted passwords.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1422

больше 21 года назад

Multiple unspecified vulnerabilities in the installer for SYSLINUX 2.01, when running setuid root, allow local users to gain privileges via unknown vectors.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2003-1421

больше 21 года назад

Unspecified vulnerability in mod_mysql_logger shared object in SuckBot 0.006 allows remote attackers to cause a denial of service (seg fault) via unknown attack vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1420

больше 21 года назад

Cross-site scripting (XSS) vulnerability in Opera 6.0 through 7.0 with automatic redirection disabled allows remote attackers to inject arbitrary web script or HTML via the HTTP Location header.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1419

больше 21 года назад

Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1418

больше 21 года назад

Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child process IDs (PID).

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1417

больше 21 года назад

nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key by reading the (1) key.pem or (2) key.der files.

CVSS2: 4.4
EPSS: Низкий
nvd логотип

CVE-2003-1416

больше 21 года назад

BisonFTP Server 4 release 2 allows remote attackers to cause a denial of service (CPU consumption) via a long (1) ls or (2) cwd command.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1415

больше 21 года назад

NetCharts XBRL Server 4.0.0 allows remote attackers to obtain sensitive information via an HTTP request with an invalid chunked transfer encoding specification.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2003-1414

больше 21 года назад

Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1413

больше 21 года назад

parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1412

больше 21 года назад

PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code via the plugin parameter to (1) 3fax/1blocklists/index.php; (2) 6departamentadmin/index.php, (3) 5terminals/index.php, (4) 4mailinglists/index.php, (5) 3departaments/index.php, and (6) 2groupd/index.php in 2administration/; or (7) the base parameter to include/help.php.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2003-1411

больше 21 года назад

PHP remote file inclusion vulnerability in emailreader_execute_on_each_page.inc.php in Cedric Email Reader 0.4 allows remote attackers to execute arbitrary PHP code via the emailreader_ini parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2003-1410

больше 21 года назад

PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary PHP code via the cer_skin parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2003-1409

больше 21 года назад

TOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter to (1) in.php or (2) out.php, which reveals the path to the TOPo directory in the error message.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2003-1428

Gallery 1.3.3 creates directories with insecure permissions, which allows local users to read, modify, or delete photos.

CVSS2: 4.8
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1427

Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary files, such as the netgear.cfg configuration file, via a hex-encoded (%2e%2e%2f) ../ (dot dot slash) in the port parameter.

CVSS2: 6.4
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1426

Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to Perl's @INC include array, which allows local users to execute arbitrary code by modifying SCRIPT_FILENAME to reference a directory containing a malicious openwebmail-shared.pl executable.

CVSS2: 3.3
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1425

guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.

CVSS2: 10
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1424

message.php in Petitforum does not properly authenticate users, which allows remote attackers to impersonate forum users via a modified connect cookie.

CVSS2: 6.8
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1423

Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as e-mail addresses and encrypted passwords.

CVSS2: 5
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1422

Multiple unspecified vulnerabilities in the installer for SYSLINUX 2.01, when running setuid root, allow local users to gain privileges via unknown vectors.

CVSS2: 10
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1421

Unspecified vulnerability in mod_mysql_logger shared object in SuckBot 0.006 allows remote attackers to cause a denial of service (seg fault) via unknown attack vectors.

CVSS2: 4.3
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1420

Cross-site scripting (XSS) vulnerability in Opera 6.0 through 7.0 with automatic redirection disabled allows remote attackers to inject arbitrary web script or HTML via the HTTP Location header.

CVSS2: 4.3
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1419

Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function.

CVSS2: 4.3
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1418

Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child process IDs (PID).

CVSS2: 4.3
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1417

nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key by reading the (1) key.pem or (2) key.der files.

CVSS2: 4.4
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1416

BisonFTP Server 4 release 2 allows remote attackers to cause a denial of service (CPU consumption) via a long (1) ls or (2) cwd command.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1415

NetCharts XBRL Server 4.0.0 allows remote attackers to obtain sensitive information via an HTTP request with an invalid chunked transfer encoding specification.

CVSS2: 6.8
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1414

Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter.

CVSS2: 4.3
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1413

parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.

CVSS2: 4.3
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1412

PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code via the plugin parameter to (1) 3fax/1blocklists/index.php; (2) 6departamentadmin/index.php, (3) 5terminals/index.php, (4) 4mailinglists/index.php, (5) 3departaments/index.php, and (6) 2groupd/index.php in 2administration/; or (7) the base parameter to include/help.php.

CVSS2: 6.8
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1411

PHP remote file inclusion vulnerability in emailreader_execute_on_each_page.inc.php in Cedric Email Reader 0.4 allows remote attackers to execute arbitrary PHP code via the emailreader_ini parameter.

CVSS2: 6.8
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1410

PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary PHP code via the cer_skin parameter.

CVSS2: 6.8
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-1409

TOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter to (1) in.php or (2) out.php, which reveals the path to the TOPo directory in the error message.

CVSS2: 5
3%
Низкий
больше 21 года назад

Уязвимостей на страницу