CVE-2003-1000 to CVE-2003-1999
207 CVEs with public proof-of-concept exploits.
- CVE-2003-10061 PoCBuffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0 through 10.3.2 may allow local users…
- CVE-2003-10171 PoCMacromedia Flash Player before 7,0,19,0 stores a Flash data file in a predictable location that is accessible to web browsers such as…
- CVE-2003-10253 PoCsInternet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the…
- CVE-2003-10261 PoCInternet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame,…
- CVE-2003-10291 PoCThe L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loop and memory…
- CVE-2003-10306 PoCsBuffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long…
- CVE-2003-10311 PoCCross-site scripting (XSS) vulnerability in register.php for vBulletin 3.0 Beta 2 allows remote attackers to inject arbitrary HTML or web…
- CVE-2003-10321 PoCPi3Web web server 2.0.2 Beta 1, when the Directory Index is configured to use the "Name" column and sort using the column title as a…
- CVE-2003-10411 PoCInternet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL…
- CVE-2003-10503 PoCsMultiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long command line…
- CVE-2003-10513 PoCsMultiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via certain…
- CVE-2003-10521 PoCIBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.
- CVE-2003-10541 PoCmod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a…
- CVE-2003-10551 PoCBuffer overflow in the nss_ldap.so.1 library for Sun Solaris 8 and 9 may allow local users to gain root access via a long hostname in an…
- CVE-2003-10711 PoCrpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from…
- CVE-2003-10731 PoCA race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot…
- CVE-2003-10832 PoCsStack-based buffer overflow in Monit 1.4 to 4.1 allows remote attackers to execute arbitrary code via a long HTTP request.
- CVE-2003-10851 PoCThe HTTP server in the Thomson TWC305, TWC315, and TCW690 cable modem ST42.03.0a allows remote attackers to cause a denial of service…
- CVE-2003-10861 PoCPHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to…
- CVE-2003-10881 PoCCross-site scripting (XSS) vulnerability in index.php for Zorum 3.4 and 3.5 allows remote attackers to inject arbitrary web script or HTML…
- CVE-2003-10891 PoCindex.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names, which reveals the…
- CVE-2003-10901 PoCBuffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title.
- CVE-2003-10911 PoCInteger overflow in MP3Broadcaster for Apple QuickTime/Darwin Streaming Server 4.1.3 allows remote attackers to cause a denial of service…
- CVE-2003-10921 PoCUnknown vulnerability in the "Automatic File Content Type Recognition (AFCTR) Tool version of the file package before 3.41, related to "a…
- CVE-2003-10961 PoCThe Cisco LEAP challenge/response authentication mechanism uses passwords in a way that is susceptible to dictionary attacks, which makes…
- CVE-2003-10971 PoCBuffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l…
- CVE-2003-11181 PoCBuffer overflow in the SETI@home client 3.03 and other versions allows remote attackers to cause a denial of service (client crash) and…
- CVE-2003-11231 PoCSun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted…
- CVE-2003-11291 PoCBuffer overflow in the Yahoo! Audio Conferencing (aka Voice Chat) ActiveX control before 1,0,0,45 allows remote attackers to cause a…
- CVE-2003-11311 PoCPHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute…
- CVE-2003-11341 PoCSun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function…
- CVE-2003-11351 PoCBuffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile)…
- CVE-2003-11361 PoCCross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web script or HTML…
- CVE-2003-11371 PoCCharles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that…
- CVE-2003-11381 PoCThe default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if…
- CVE-2003-11391 PoCMusicqueue 1.2.0 allows local users to overwrite arbitrary files by triggering a segmentation fault and using a symlink attack on the…
- CVE-2003-11401 PoCBuffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the configuration file.
- CVE-2003-11413 PoCsBuffer overflow in NIPrint 4.10 allows remote attackers to execute arbitrary code via a long string to TCP port 515.
- CVE-2003-11422 PoCsHelp in NIPrint LPD-LPR Print Server 4.10 and earlier executes Windows Explorer with SYSTEM privileges, which allows local users to gain…
- CVE-2003-11432 PoCsCroteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05 allow remote…
- CVE-2003-11451 PoCCross-site scripting (XSS) vulnerability in friendmail.php in OpenAutoClassifieds 1.0 allows remote attackers to inject arbitrary web…
- CVE-2003-11461 PoCCross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or…
- CVE-2003-11481 PoCMultiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference)…
- CVE-2003-11491 PoCCross-site scripting (XSS) vulnerability in Symantec Norton Internet Security 2003 6.0.4.34 allows remote attackers to inject arbitrary…
- CVE-2003-11511 PoCCross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrary web script or…
- CVE-2003-11571 PoCCross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web…
- CVE-2003-11581 PoCMultiple buffer overflows in the FTP service in Plug and Play Web Server 1.0002c allow remote attackers to cause a denial of service…
- CVE-2003-11601 PoCFlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request…
- CVE-2003-11621 PoCindex.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying the thread_id,…
- CVE-2003-11641 PoCCross-site scripting (XSS) vulnerability in Mldonkey 2.5-4 allows remote attackers to inject arbitrary web script or HTML via the URI,…
- CVE-2003-11651 PoCBuffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute…
- CVE-2003-11661 PoCDirectory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary…
- CVE-2003-11671 PoCmisc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their privileges by…
- CVE-2003-11691 PoCDATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access…
- CVE-2003-11721 PoCDirectory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers…
- CVE-2003-11731 PoCCentrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the URL and checking…
- CVE-2003-11742 PoCsBuffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name followed by a long…
- CVE-2003-11751 PoCCross-site scripting (XSS) vulnerability in index.php in Sympoll 1.5 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2003-11761 PoCpost_message_form.asp in Web Wiz Forums 6.34 through 7.5, when quote mode is used, allows remote attackers to read or write to private…
- CVE-2003-11771 PoCBuffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and…
- CVE-2003-11791 PoCMultiple PHP remote file inclusion vulnerabilities in Advanced Poll 2.0.2 allow remote attackers to execute arbitrary PHP code via the…
- CVE-2003-11811 PoCAdvanced Poll 2.0.2 allows remote attackers to obtain sensitive information via an HTTP request to info.php, which invokes the phpinfo()…
- CVE-2003-11821 PoCCross-site scripting (XSS) vulnerability in MPM Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the lng…
- CVE-2003-11871 PoCCross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script…
- CVE-2003-11911 PoCchatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML in the Name field,…
- CVE-2003-11924 PoCsStack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET request.
- CVE-2003-11961 PoCSQL injection vulnerability in viewtopic.asp in VieBoard 2.6 allows remote attackers to execute arbitrary SQL commands via the forumid…
- CVE-2003-11971 PoCCross-site scripting (XSS) vulnerability in index.php for Ledscripts.com LedForums Beta 1 allows remote attackers to inject arbitrary web…
- CVE-2003-11991 PoCCross-site scripting (XSS) vulnerability in MyProxy 20030629 allows remote attackers to inject arbitrary web script or HTML via the URL.
- CVE-2003-12005 PoCsStack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbitrary code via a…
- CVE-2003-12031 PoCCross-site scripting (XSS) vulnerability in index.php for Mambo Site Server 4.0.10 allows remote attackers to execute script on other…
- CVE-2003-12071 PoCCrob FTP Server 3.5.1 allows remote authenticated users to cause a denial of service (crash) via a dir command with a large number of "."…
- CVE-2003-12101 PoCMultiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary…
- CVE-2003-12131 PoCThe default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which…
- CVE-2003-12163 PoCsSQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges…
- CVE-2003-12191 PoCCross-site scripting (XSS) vulnerability in the tep_href_link function in html_output.php for osCommerce before 2.2-MS3 allows remote…
- CVE-2003-12271 PoCPHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix,…
- CVE-2003-12281 PoCBuffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions, allows remote…
- CVE-2003-12321 PoCEmacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows…
- CVE-2003-12362 PoCsMultiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to execute arbitrary…
- CVE-2003-12391 PoCDirectory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via .. specifiers in…
- CVE-2003-12403 PoCsPHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath…
- CVE-2003-12421 PoCSage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path…
- CVE-2003-12431 PoCCross-site scripting vulnerability (XSS) in Sage 1.0 b3 allows remote attackers to insert arbitrary HTML or web script via the mod…
- CVE-2003-12441 PoCSQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and…
- CVE-2003-12452 PoCsindex2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash…
- CVE-2003-12472 PoCsMultiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in…
- CVE-2003-12512 PoCsThe (1) menu.inc.php, (2) datasets.php and (3) mass_operations.inc.php (mistakenly referred to as mass_opeations.inc.php) scripts in N/X…
- CVE-2003-12521 PoCregister.php in S8Forum 3.0 allows remote attackers to execute arbitrary PHP commands by creating a user whose name ends in a .php…
- CVE-2003-12561 PoCaff_liste_langue.php in E-theni allows remote attackers to execute arbitrary PHP code by modifying the rep_include parameter to reference…
- CVE-2003-12601 PoCBuffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command.
- CVE-2003-12632 PoCsICAL.EXE in iCal 3.7 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, possibly due to an invalid…
- CVE-2003-12664 PoCsThe (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a…
- CVE-2003-12711 PoCCross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTML as other users…
- CVE-2003-12751 PoCPocket Internet Explorer (PIE) 3.0 allows remote attackers to cause a denial of service (crash) via a Javascript function that uses the…
- CVE-2003-12781 PoCCross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 allows remote attackers to execute arbitrary script as other users and…
- CVE-2003-12861 PoCHTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attackers to send proxy…
- CVE-2003-12921 PoCPHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbitrary remote files…
- CVE-2003-13011 PoCSun Java Runtime Environment (JRE) 1.x before 1.4.2_11 and 1.5.x before 1.5.0_06, and as used in multiple web browsers, allows remote…
- CVE-2003-13041 PoCEarlyImpact ProductCart 1.0 through 2.0 stores database/EIPC.mdb under the web root with insufficient access control, which allows remote…
- CVE-2003-13073 PoCsThe mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process…
- CVE-2003-13081 PoCCRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute…
- CVE-2003-13101 PoCThe DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain…
- CVE-2003-13131 PoCMultiple PHP remote file inclusion vulnerabilities in EternalMart Mailing List Manager (EMLM) 1.32 allow remote attackers to execute…
- CVE-2003-13141 PoCPHP remote file inclusion vulnerability in admin/auth.php in EternalMart Guestbook (EMGB) 1.1 allows remote attackers to execute arbitrary…
- CVE-2003-13171 PoCCross-site scripting (XSS) vulnerability in mod.php in eNdonesia 8.2 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2003-13181 PoCTwilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request for a long URI, a…
- CVE-2003-13211 PoCBuffer overflow in Avant Browser 8.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via…
- CVE-2003-13251 PoCThe SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows remote…
- CVE-2003-13281 PoCThe showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote…
- CVE-2003-13363 PoCsBuffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL.
- CVE-2003-13392 PoCsStack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare allows remote…
- CVE-2003-13411 PoCThe default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from…
- CVE-2003-13421 PoCTrend Micro Virus Control System (TVCS) 1.8 running with IIS allows remote attackers to cause a denial of service (memory consumption) in…
- CVE-2003-13431 PoCTrend Micro ScanMail for Exchange (SMEX) before 3.81 and before 6.1 might install a back door account in smg_Smxcfg30.exe, which allows…
- CVE-2003-13441 PoCTrend Micro Virus Control System (TVCS) Log Collector allows remote attackers to obtain usernames, encrypted passwords, and other…
- CVE-2003-13474 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web script or HTML via the…
- CVE-2003-13481 PoCCross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote attackers to inject arbitrary web script…
- CVE-2003-13501 PoCList Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the…
- CVE-2003-13541 PoCMultiple GameSpy 3D 2.62 compatible gaming servers generate very large UDP responses to small requests, which allows remote attackers to…
- CVE-2003-13551 PoCBuffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash)…
- CVE-2003-13581 PoCrs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised…
- CVE-2003-13592 PoCsBuffer overflow in stmkfont utility of HP-UX 10.0 through 11.22 allows local users to gain privileges via a long command line argument.
- CVE-2003-13641 PoCAprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of…
- CVE-2003-13661 PoCchpass in OpenBSD 2.0 through 3.2 allows local users to read portions of arbitrary files via a hard link attack on a temporary file used…
- CVE-2003-13681 PoCBuffer overflow in the 32bit FTP client 9.49.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary…
- CVE-2003-13691 PoCBuffer overflow in ByteCatcher FTP client 1.04b allows remote attackers to cause a denial of service (crash) and possibly execute…
- CVE-2003-13711 PoCNuked-Klan 1.3b, and possibly earlier versions, allows remote attackers to obtain sensitive server information via an op parameter set to…
- CVE-2003-13721 PoCCross-site scripting (XSS) vulnerability in links.php script in myPHPNuke 1.8.8, and possibly earlier versions, allows remote attackers to…
- CVE-2003-13751 PoCBuffer overflow in wall for HP-UX 10.20 through 11.11 may allow local users to execute arbitrary code by calling wall with a large file as…
- CVE-2003-13771 PoCBuffer overflow in the reverse DNS lookup of Smart IRC Daemon (SIRCD) 0.4.0 and 0.4.4 allows remote attackers to execute arbitrary code…
- CVE-2003-13781 PoCMicrosoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary…
- CVE-2003-13811 PoCFormat string vulnerability in AMX 0.9.2 and earlier, a plugin for Valve Software's Half-Life Server, allows remote attackers to execute…
- CVE-2003-13851 PoCipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by…
- CVE-2003-13861 PoCAXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages,…
- CVE-2003-13871 PoCBuffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a…
- CVE-2003-13961 PoCHeap-based buffer overflow in Opera 6.05 through 7.10 allows remote attackers to cause a denial of service (crash) and possibly execute…
- CVE-2003-13971 PoCThe PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP request containing…
- CVE-2003-14001 PoCCross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject…
- CVE-2003-14011 PoClogin.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which…
- CVE-2003-14052 PoCsDotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3.
- CVE-2003-14062 PoCsPHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in…
- CVE-2003-14071 PoCBuffer overflow in cmd.exe in Windows NT 4.0 may allow local users to execute arbitrary code via a long pathname argument to the cd command.
- CVE-2003-14091 PoCTOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter to (1) in.php or…
- CVE-2003-14101 PoCPHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to…
- CVE-2003-14111 PoCPHP remote file inclusion vulnerability in emailreader_execute_on_each_page.inc.php in Cedric Email Reader 0.4 allows remote attackers to…
- CVE-2003-14121 PoCPHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute…
- CVE-2003-14141 PoCDirectory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows…
- CVE-2003-14191 PoCNetscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to…
- CVE-2003-14254 PoCsguestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.
- CVE-2003-14271 PoCDirectory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary…
- CVE-2003-14301 PoCDirectory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".."…
- CVE-2003-14311 PoCBuffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash) via a long host…
- CVE-2003-14321 PoCEpic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly…
- CVE-2003-14351 PoCSQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to…
- CVE-2003-14361 PoCPHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute arbitrary PHP code…
- CVE-2003-14421 PoCThe web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to…
- CVE-2003-14451 PoCStack-based buffer overflow in Far Manager 1.70beta1 and earlier allows local users to cause a denial of service (crash) and possibly…
- CVE-2003-14501 PoCBitchX 75p3 and 1.0c16 through 1.0c20cvs allows remote attackers to cause a denial of service (segmentation fault) via a malformed…
- CVE-2003-14522 PoCsUntrusted search path vulnerability in Qualcomm qpopper 4.0 through 4.05 allows local users to execute arbitrary code by modifying the…
- CVE-2003-14531 PoCCross-site scripting (XSS) vulnerability in the MytextSanitizer function in XOOPS 1.3.5 through 1.3.9 and XOOPS 2.0 through 2.0.1 allows…
- CVE-2003-14561 PoCAlbum.pl 6.1 allows remote attackers to execute arbitrary commands, when an alternative configuration file is used, via unknown attack…
- CVE-2003-14592 PoCsMultiple PHP remote file inclusion vulnerabilities in ttCMS 2.2 and ttForum allow remote attackers to execute arbitrary PHP code via the…
- CVE-2003-14611 PoCBuffer overflow in rwrite for HP-UX 11.0 could allow local users to execute arbitrary code via a long argument. NOTE: the vendor was…
- CVE-2003-14632 PoCsAbsolute path traversal vulnerability in Alt-N Technologies WebAdmin 2.0.0 through 2.0.2 allows remote attackers with administrator…
- CVE-2003-14681 PoCThe Web_Links module in PHP-Nuke 6.0 through 6.5 final allows remote attackers to obtain the full web server path via an invalid cid…
- CVE-2003-14691 PoCThe default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to…
- CVE-2003-14721 PoCBuffer overflow in 3D-FTP client 4.0 allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code…
- CVE-2003-14731 PoCBuffer overflow in LTris 1.0.1 of FreeBSD Ports Collection 2003-02-25 and earlier allows local users to execute arbitrary code with gid…
- CVE-2003-14751 PoCNetbus 1.5 through 1.7 allows more than one client to be connected at the same time, but only prompts the first connection for…
- CVE-2003-14781 PoCKonqueror in KDE 3.0.3 allows remote attackers to cause a denial of service (core dump) via a web page that begins with a "xFFxFE" byte…
- CVE-2003-14801 PoCMySQL 3.20 through 4.1.0 uses a weak algorithm for hashed passwords, which makes it easier for attackers to decrypt the password via brute…
- CVE-2003-14812 PoCsCommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote…
- CVE-2003-14881 PoCThe (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a…
- CVE-2003-14981 PoCCross-site scripting (XSS) vulnerability in search.php for WRENSOFT Zoom Search Engine 2.0 Build 1018 and earlier allows remote attackers…
- CVE-2003-14991 PoCDirectory traversal vulnerability in index.php in Bytehoard 0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the…
- CVE-2003-15041 PoCSQL injection vulnerability in variables.php in Goldlink 3.0 allows remote attackers to execute arbitrary SQL commands via the (1)…
- CVE-2003-15051 PoCMicrosoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or HTML e-mail with a…
- CVE-2003-15061 PoCCross-site scripting (XSS) vulnerability in dansguardian.pl in Adelix CensorNet 3.0 through 3.2 allows remote attackers to execute…
- CVE-2003-15082 PoCsBuffer overflow in mIRC 6.12, when the DCC get dialog window has been minimized and the user opens the minimized window, allows remote…
- CVE-2003-15111 PoCCross-site scripting (XSS) vulnerability in Bajie Java HTTP Server 0.95 through 0.95zxv4 allows remote attackers to inject arbitrary web…
- CVE-2003-15122 PoCsBuffer overflow in mIRC 6.1 and 6.11 allows remote attackers to cause a denial of service (crash) via a long DCC SEND request.
- CVE-2003-15131 PoCMultiple cross-site scripting (XSS) vulnerabilities in example scripts in Caucho Technology Resin 2.0 through 2.1.2 allow remote attackers…
- CVE-2003-15161 PoCThe org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables,…
- CVE-2003-15171 PoCcart.pl in Dansie shopping cart allows remote attackers to obtain the installation path via an invalid db parameter, which leaks the path…
- CVE-2003-15181 PoCAdiscon WinSyslog 4.21 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a long syslog message.
- CVE-2003-15191 PoCCross-site scripting (XSS) vulnerability in Vivisimo clustering engine allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2003-15201 PoCSQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email…
- CVE-2003-15211 PoCSun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in…
- CVE-2003-15221 PoCCross-site scripting (XSS) vulnerability in PSCS VPOP3 Web Mail server 2.0e and 2.0f allows remote attackers to inject arbitrary web…
- CVE-2003-15301 PoCSQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2003-15321 PoCSQL injection vulnerability in compte.php in PhpMyShop 1.00 allows remote attackers to execute arbitrary SQL commands via the (1)…
- CVE-2003-15331 PoCSQL injection vulnerability in accesscontrol.php in PhpPass 2 allows remote attackers to execute arbitrary SQL commands via the (1) uid…
- CVE-2003-15351 PoCJustice Guestbook 1.3 allows remote attackers to obtain the full installation path via a direct request to cfooter.php3, which leaks the…
- CVE-2003-15361 PoCMultiple cross-site scripting (XSS) vulnerabilities in Codeworx Technologies DCP-Portal 5.3.1 allow remote attackers to inject arbitrary…
- CVE-2003-15401 PoCWF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain…
- CVE-2003-15411 PoCPlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers…
- CVE-2003-15451 PoCAbsolute path traversal vulnerability in nukestyles.com viewpage.php addon for PHP-Nuke allows remote attackers to read arbitrary files…
- CVE-2003-15481 PoCMyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other parameter, which…
- CVE-2003-15501 PoCXOOPS 2.0, and possibly earlier versions, allows remote attackers to obtain sensitive information via an invalid xoopsOption parameter,…
- CVE-2003-15531 PoCHaakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access…
- CVE-2003-15551 PoCScozNet ScozBook 1.1 BETA allows remote attackers to obtain sensitive information via an invalid PG parameter in view.php, which reveals…
- CVE-2003-15661 PoCMicrosoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain…
- CVE-2003-15711 PoCWeb Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to…
- CVE-2003-15732 PoCsThe PointBase 4.6 database component in the J2EE 1.4 reference implementation (J2EE/RI) allows remote attackers to execute arbitrary…
- CVE-2003-15981 PoCSQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via…
- CVE-2003-15991 PoCPHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code…