Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 330 130

Количество 330 130

nvd логотип

CVE-2003-1554

около 22 лет назад

Cross-site scripting (XSS) vulnerability in scozbook/add.php in ScozNet ScozBook 1.1 BETA allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) useremail, (3) aim, (4) msn, (5) sitename and (6) siteaddy variables.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1553

около 22 лет назад

Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1552

около 22 лет назад

Unrestricted file upload vulnerability in uploader.php in Uploader 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2003-1551

около 22 лет назад

Unspecified vulnerability in Novell GroupWise 6 SP3 WebAccess before Revision F has unknown impact and attack vectors related to "malicious script."

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2003-1550

около 22 лет назад

XOOPS 2.0, and possibly earlier versions, allows remote attackers to obtain sensitive information via an invalid xoopsOption parameter, which reveals the installation path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1549

около 22 лет назад

Cross-site scripting (XSS) vulnerability in header.php in MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the ma_kw parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1548

около 22 лет назад

MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other parameter, which reveals the installation path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1547

около 22 лет назад

Cross-site scripting (XSS) vulnerability in block-Forums.php in the Splatt Forum module for PHP-Nuke 6.x allows remote attackers to inject arbitrary web script or HTML via the subject parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1546

около 22 лет назад

Cross-site scripting (XSS) vulnerability in gbook.php in Filebased guestbook 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the comment section.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1545

около 22 лет назад

Absolute path traversal vulnerability in nukestyles.com viewpage.php addon for PHP-Nuke allows remote attackers to read arbitrary files via a full pathname in the file parameter. NOTE: This was originally reported as an issue in PHP-Nuke 6.5, but this is an independent addon.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1544

около 22 лет назад

Unrestricted critical resource lock in Terminal Services for Windows 2000 before SP4 and Windows XP allows remote authenticated users to cause a denial of service (reboot) by obtaining a read lock on msgina.dll, which prevents msgina.dll from being loaded.

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2003-1543

около 22 лет назад

Cross-site scripting (XSS) vulnerability in Bajie Http Web Server 0.95zxe, 0.95zxc, and possibly others, allows remote attackers to inject arbitrary web script or HTML via the query string, which is reflected in an error message.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1542

около 22 лет назад

Directory traversal vulnerability in plugins/file.php in phpWebFileManager before 0.4.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the fm_path parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1541

около 22 лет назад

PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin script password, and other passwords, via a direct request to files/passwd.txt.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1540

около 22 лет назад

WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain authentication information via a direct request to (1) !pwds.txt and (2) !nicks.txt.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1539

около 22 лет назад

Cross-site scripting (XSS) vulnerability in ONEdotOH Simple File Manager (SFM) before 0.21 allows remote attackers to inject arbitrary web script or HTML via (1) file names and (2) directory names.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1538

около 22 лет назад

susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands via CGI queries.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2003-1537

около 22 лет назад

Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1536

около 22 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Codeworx Technologies DCP-Portal 5.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the q parameter to search.php and (2) the year parameter to calendar.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1535

около 22 лет назад

Justice Guestbook 1.3 allows remote attackers to obtain the full installation path via a direct request to cfooter.php3, which leaks the path in an error message.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2003-1554

Cross-site scripting (XSS) vulnerability in scozbook/add.php in ScozNet ScozBook 1.1 BETA allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) useremail, (3) aim, (4) msn, (5) sitename and (6) siteaddy variables.

CVSS2: 4.3
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1553

Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory.

CVSS2: 4.3
3%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1552

Unrestricted file upload vulnerability in uploader.php in Uploader 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/.

CVSS2: 6.8
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1551

Unspecified vulnerability in Novell GroupWise 6 SP3 WebAccess before Revision F has unknown impact and attack vectors related to "malicious script."

CVSS2: 10
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1550

XOOPS 2.0, and possibly earlier versions, allows remote attackers to obtain sensitive information via an invalid xoopsOption parameter, which reveals the installation path in an error message.

CVSS2: 5
6%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1549

Cross-site scripting (XSS) vulnerability in header.php in MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the ma_kw parameter.

CVSS2: 4.3
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1548

MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other parameter, which reveals the installation path in an error message.

CVSS2: 5
6%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1547

Cross-site scripting (XSS) vulnerability in block-Forums.php in the Splatt Forum module for PHP-Nuke 6.x allows remote attackers to inject arbitrary web script or HTML via the subject parameter.

CVSS2: 4.3
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1546

Cross-site scripting (XSS) vulnerability in gbook.php in Filebased guestbook 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the comment section.

CVSS2: 4.3
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1545

Absolute path traversal vulnerability in nukestyles.com viewpage.php addon for PHP-Nuke allows remote attackers to read arbitrary files via a full pathname in the file parameter. NOTE: This was originally reported as an issue in PHP-Nuke 6.5, but this is an independent addon.

CVSS2: 5
5%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1544

Unrestricted critical resource lock in Terminal Services for Windows 2000 before SP4 and Windows XP allows remote authenticated users to cause a denial of service (reboot) by obtaining a read lock on msgina.dll, which prevents msgina.dll from being loaded.

CVSS2: 6.8
30%
Средний
около 22 лет назад
nvd логотип
CVE-2003-1543

Cross-site scripting (XSS) vulnerability in Bajie Http Web Server 0.95zxe, 0.95zxc, and possibly others, allows remote attackers to inject arbitrary web script or HTML via the query string, which is reflected in an error message.

CVSS2: 4.3
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1542

Directory traversal vulnerability in plugins/file.php in phpWebFileManager before 0.4.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the fm_path parameter.

CVSS2: 5
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1541

PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin script password, and other passwords, via a direct request to files/passwd.txt.

CVSS2: 5
6%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1540

WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain authentication information via a direct request to (1) !pwds.txt and (2) !nicks.txt.

CVSS2: 5
4%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1539

Cross-site scripting (XSS) vulnerability in ONEdotOH Simple File Manager (SFM) before 0.21 allows remote attackers to inject arbitrary web script or HTML via (1) file names and (2) directory names.

CVSS2: 4.3
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1538

susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands via CGI queries.

CVSS2: 6.4
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1537

Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php.

CVSS2: 5
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1536

Multiple cross-site scripting (XSS) vulnerabilities in Codeworx Technologies DCP-Portal 5.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the q parameter to search.php and (2) the year parameter to calendar.php.

CVSS2: 4.3
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1535

Justice Guestbook 1.3 allows remote attackers to obtain the full installation path via a direct request to cfooter.php3, which leaks the path in an error message.

CVSS2: 5
4%
Низкий
около 22 лет назад

Уязвимостей на страницу