Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 115

Количество 372 115

nvd логотип

CVE-2003-1538

больше 22 лет назад

susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands via CGI queries.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2003-1537

больше 22 лет назад

Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1536

больше 22 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Codeworx Technologies DCP-Portal 5.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the q parameter to search.php and (2) the year parameter to calendar.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1535

больше 22 лет назад

Justice Guestbook 1.3 allows remote attackers to obtain the full installation path via a direct request to cfooter.php3, which leaks the path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1534

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in jgb.php3 in Justice Guestbook 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) homepage, (3) aim, (4) yim, (5) location, and (6) comment variables.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1533

больше 22 лет назад

SQL injection vulnerability in accesscontrol.php in PhpPass 2 allows remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-1532

больше 22 лет назад

SQL injection vulnerability in compte.php in PhpMyShop 1.00 allows remote attackers to execute arbitrary SQL commands via the (1) identifiant and (2) password parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-1531

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in testcgi.exe in Lilikoi Software Ceilidh 2.70 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1530

больше 22 лет назад

SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the mark[] parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-1529

больше 22 лет назад

Directory traversal vulnerability in Seagull Software Systems J Walk application server 3.2C9, and other versions before 3.3c4, allows remote attackers to read arbitrary files via a ".%252e" (encoded dot dot) in the URL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1528

больше 22 лет назад

nsr_shutdown in Fujitsu Siemens NetWorker 6.0 allows local users to overwrite arbitrary files via a symlink attack on the nsrsh[PID] temporary file.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2003-1527

больше 22 лет назад

BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1526

больше 22 лет назад

PHP-Nuke 7.0 allows remote attackers to obtain the installation path via certain characters such as (1) ", (2) ', or (3) > in the search field, which reveals the path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1525

больше 22 лет назад

Unspecified vulnerability in My Photo Gallery 3.5, and possibly earlier versions, has unknown impact and attack vectors.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2003-1524

больше 22 лет назад

PGPi PGPDisk 6.0.2i does not unmount a PGP partition when the switch user function in Windows XP is used, which could allow local users to access data on another user's PGP partition.

CVSS2: 6.3
EPSS: Низкий
nvd логотип

CVE-2003-1523

больше 22 лет назад

SQL injection vulnerability in the IMAP daemon in dbmail 1.1 allows remote attackers to execute arbitrary SQL commands via the (1) login username, (2) mailbox name, and possibly other attack vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-1522

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in PSCS VPOP3 Web Mail server 2.0e and 2.0f allows remote attackers to inject arbitrary web script or HTML via the redirect parameter to the admin/index.html page.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1521

больше 22 лет назад

Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2003-1520

больше 22 лет назад

SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2003-1519

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in Vivisimo clustering engine allows remote attackers to inject arbitrary web script or HTML via the query parameter to the search program.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2003-1538

susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands via CGI queries.

CVSS2: 6.4
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1537

Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1536

Multiple cross-site scripting (XSS) vulnerabilities in Codeworx Technologies DCP-Portal 5.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the q parameter to search.php and (2) the year parameter to calendar.php.

CVSS2: 4.3
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1535

Justice Guestbook 1.3 allows remote attackers to obtain the full installation path via a direct request to cfooter.php3, which leaks the path in an error message.

CVSS2: 5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1534

Cross-site scripting (XSS) vulnerability in jgb.php3 in Justice Guestbook 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) homepage, (3) aim, (4) yim, (5) location, and (6) comment variables.

CVSS2: 4.3
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1533

SQL injection vulnerability in accesscontrol.php in PhpPass 2 allows remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameters.

CVSS2: 7.5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1532

SQL injection vulnerability in compte.php in PhpMyShop 1.00 allows remote attackers to execute arbitrary SQL commands via the (1) identifiant and (2) password parameters.

CVSS2: 7.5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1531

Cross-site scripting (XSS) vulnerability in testcgi.exe in Lilikoi Software Ceilidh 2.70 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string.

CVSS2: 4.3
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1530

SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the mark[] parameter.

CVSS2: 7.5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1529

Directory traversal vulnerability in Seagull Software Systems J Walk application server 3.2C9, and other versions before 3.3c4, allows remote attackers to read arbitrary files via a ".%252e" (encoded dot dot) in the URL.

CVSS2: 5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1528

nsr_shutdown in Fujitsu Siemens NetWorker 6.0 allows local users to overwrite arbitrary files via a symlink attack on the nsrsh[PID] temporary file.

CVSS2: 7.2
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1527

BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.

CVSS2: 4.3
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1526

PHP-Nuke 7.0 allows remote attackers to obtain the installation path via certain characters such as (1) ", (2) ', or (3) > in the search field, which reveals the path in an error message.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1525

Unspecified vulnerability in My Photo Gallery 3.5, and possibly earlier versions, has unknown impact and attack vectors.

CVSS2: 10
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1524

PGPi PGPDisk 6.0.2i does not unmount a PGP partition when the switch user function in Windows XP is used, which could allow local users to access data on another user's PGP partition.

CVSS2: 6.3
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1523

SQL injection vulnerability in the IMAP daemon in dbmail 1.1 allows remote attackers to execute arbitrary SQL commands via the (1) login username, (2) mailbox name, and possibly other attack vectors.

CVSS2: 7.5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1522

Cross-site scripting (XSS) vulnerability in PSCS VPOP3 Web Mail server 2.0e and 2.0f allows remote attackers to inject arbitrary web script or HTML via the redirect parameter to the admin/index.html page.

CVSS2: 4.3
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1521

Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.

CVSS2: 6.4
6%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1520

SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email parameter.

CVSS2: 6.8
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1519

Cross-site scripting (XSS) vulnerability in Vivisimo clustering engine allows remote attackers to inject arbitrary web script or HTML via the query parameter to the search program.

CVSS2: 4.3
1%
Низкий
больше 22 лет назад

Уязвимостей на страницу