Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 863

Количество 371 863

nvd логотип

CVE-2003-1226

больше 22 лет назад

BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certain secrets concerning password encryption insecurely in config.xml, filerealm.properties, and weblogic-rar.xml, which allows local users to learn those secrets and decrypt passwords.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2003-1225

больше 22 лет назад

The default CredentialMapper for BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores passwords in cleartext on disk, which allows local users to extract passwords.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2003-1224

больше 22 лет назад

Weblogic.admin for BEA WebLogic Server and Express 7.0 and 7.0.0.1 displays the JDBCConnectionPoolRuntimeMBean password to the screen in cleartext, which allows attackers to read a user's password by physically observing ("shoulder surfing") the screen.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2003-1223

больше 22 лет назад

The Node Manager for BEA WebLogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (Node Manager crash) via malformed data to the Node Manager's port, as demonstrated by nmap.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1222

больше 22 лет назад

BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext in config.xml, which could allow attackers to obtain the password.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1221

больше 22 лет назад

BEA WebLogic Express and Server 7.0 through 8.1 SP 1, under certain circumstances when a request to use T3 over SSL (t3s) is made to the insecure T3 port, may use a non-SSL connection for the communication, which could allow attackers to sniff sessions.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1220

больше 22 лет назад

BEA WebLogic Server proxy plugin for BEA Weblogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (proxy plugin crash) via a malformed URL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1219

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in the tep_href_link function in html_output.php for osCommerce before 2.2-MS3 allows remote attackers to inject arbitrary web script or HTML via the osCsid parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1218

около 9 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none

EPSS: Низкий
nvd логотип

CVE-2003-1217

около 9 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none

EPSS: Низкий
nvd логотип

CVE-2003-1216

больше 22 лет назад

SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the search_id parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-1215

больше 22 лет назад

SQL injection vulnerability in groupcp.php for phpBB 2.0.6 and earlier allows group moderators to perform unauthorized activities via the sql_in parameter.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2003-1214

больше 22 лет назад

Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restrictions and gain access to restricted functions.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-1213

больше 22 лет назад

The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which allows remote attackers to obtain sensitive information via a direct request to database/db2000.mdb.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-1212

больше 22 лет назад

MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the 'start new topic' HTML page.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-1211

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in search.asp for MaxWebPortal 1.30 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the Search parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2003-1210

больше 22 лет назад

Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-1209

больше 22 лет назад

The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request without a Content-Type header.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1208

больше 21 года назад

Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing long parameters to the (2) NUMTOYMINTERVAL, (3) NUMTODSINTERVAL or (4) FROM_TZ functions.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2003-1207

больше 22 лет назад

Crob FTP Server 3.5.1 allows remote authenticated users to cause a denial of service (crash) via a dir command with a large number of "." characters followed by a "/*" string.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2003-1226

BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certain secrets concerning password encryption insecurely in config.xml, filerealm.properties, and weblogic-rar.xml, which allows local users to learn those secrets and decrypt passwords.

CVSS2: 2.1
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1225

The default CredentialMapper for BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores passwords in cleartext on disk, which allows local users to extract passwords.

CVSS2: 2.1
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1224

Weblogic.admin for BEA WebLogic Server and Express 7.0 and 7.0.0.1 displays the JDBCConnectionPoolRuntimeMBean password to the screen in cleartext, which allows attackers to read a user's password by physically observing ("shoulder surfing") the screen.

CVSS2: 2.1
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1223

The Node Manager for BEA WebLogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (Node Manager crash) via malformed data to the Node Manager's port, as demonstrated by nmap.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1222

BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext in config.xml, which could allow attackers to obtain the password.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1221

BEA WebLogic Express and Server 7.0 through 8.1 SP 1, under certain circumstances when a request to use T3 over SSL (t3s) is made to the insecure T3 port, may use a non-SSL connection for the communication, which could allow attackers to sniff sessions.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1220

BEA WebLogic Server proxy plugin for BEA Weblogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (proxy plugin crash) via a malformed URL.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1219

Cross-site scripting (XSS) vulnerability in the tep_href_link function in html_output.php for osCommerce before 2.2-MS3 allows remote attackers to inject arbitrary web script or HTML via the osCsid parameter.

CVSS2: 4.3
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1218

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none

около 9 лет назад
nvd логотип
CVE-2003-1217

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none

около 9 лет назад
nvd логотип
CVE-2003-1216

SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the search_id parameter.

CVSS2: 7.5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1215

SQL injection vulnerability in groupcp.php for phpBB 2.0.6 and earlier allows group moderators to perform unauthorized activities via the sql_in parameter.

CVSS2: 4.6
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1214

Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restrictions and gain access to restricted functions.

CVSS2: 7.5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1213

The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which allows remote attackers to obtain sensitive information via a direct request to database/db2000.mdb.

CVSS2: 7.5
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1212

MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the 'start new topic' HTML page.

CVSS2: 7.5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1211

Cross-site scripting (XSS) vulnerability in search.asp for MaxWebPortal 1.30 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the Search parameter.

CVSS2: 6.8
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1210

Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function.

CVSS2: 7.5
5%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1209

The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request without a Content-Type header.

CVSS2: 5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1208

Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing long parameters to the (2) NUMTOYMINTERVAL, (3) NUMTODSINTERVAL or (4) FROM_TZ functions.

CVSS2: 10
13%
Средний
больше 21 года назад
nvd логотип
CVE-2003-1207

Crob FTP Server 3.5.1 allows remote authenticated users to cause a denial of service (crash) via a dir command with a large number of "." characters followed by a "/*" string.

CVSS2: 5
3%
Низкий
больше 22 лет назад

Уязвимостей на страницу