|
347301
|
5.0 |
MEDIUM
|
wihphoto
|
wihphoto
|
Directory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via .. specifiers in the album parameter, and the target filename in the pic parame…
|
NVD-CWE-Other
|
CVE-2003-1239
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347302
|
7.5 |
HIGH
|
cutephp
|
cutenews
|
PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.php, or (3) comments…
|
CWE-94
Code Injection
|
CVE-2003-1240
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347303
|
4.3 |
MEDIUM
|
levcgi.com
|
myguestbook
|
Cross-site scripting vulnerability (XSS) in (1) admin_index.php, (2) admin_pass.php, (3) admin_modif.php, and (4) admin_suppr.php in MyGuestbook 3.0 allows remote attackers to execute arbitrary PHP c…
|
NVD-CWE-Other
|
CVE-2003-1241
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347304
|
5.0 |
MEDIUM
|
-
|
-
|
Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path in an error message.
|
NVD-CWE-Other
|
CVE-2003-1242
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347305
|
7.5 |
HIGH
|
phpbb_group
|
phpbb
|
SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and possibly gain unauthorized access to forums via the forum_id par…
|
CWE-89
SQL Injection
|
CVE-2003-1244
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347306
|
2.1 |
LOW
|
pedestal_software
|
integrity_protection_driver
|
NtCreateSymbolicLinkObject in ntdll.dll in Integrity Protection Driver (IPD) 1.2 and 1.3 allows local users to create and overwrite arbitrary files via a symlink attack on \winnt\system32\drivers usi…
|
NVD-CWE-Other
|
CVE-2003-1246
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347307
|
7.5 |
HIGH
|
positive_software
|
h-sphere
|
Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::readFile, (2) a long path in diskusage, and (3) a long fnam…
|
NVD-CWE-Other
|
CVE-2003-1247
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347308
|
7.5 |
HIGH
|
positive_software
|
h-sphere
|
H-Sphere WebShell 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) mode and (2) zipfile parameters in a URL request.
|
NVD-CWE-Other
|
CVE-2003-1248
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347309
|
7.5 |
HIGH
|
businessobjects
|
webintelligence
|
WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions.
|
NVD-CWE-Other
|
CVE-2003-1249
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347310
|
5.0 |
MEDIUM
|
efficient_networks
|
5861_dsl_router
|
Efficient Networks 5861 DSL router, when running firmware 5.3.80 configured to block incoming TCP SYN, packets allows remote attackers to cause a denial of service (crash) via a flood of TCP SYN pack…
|
NVD-CWE-Other
|
CVE-2003-1250
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347311
|
7.5 |
HIGH
|
nx
|
n_x_web_content_management_system_2002
|
The (1) menu.inc.php, (2) datasets.php and (3) mass_operations.inc.php (mistakenly referred to as mass_opeations.inc.php) scripts in N/X 2002 allow remote attackers to execute arbitrary PHP code via …
|
NVD-CWE-Other
|
CVE-2003-1251
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347312
|
7.5 |
HIGH
|
kelli_shaver
|
s8forum
|
register.php in S8Forum 3.0 allows remote attackers to execute arbitrary PHP commands by creating a user whose name ends in a .php extension and entering the desired commands into the E-mail field, w…
|
NVD-CWE-Other
|
CVE-2003-1252
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347313
|
7.5 |
HIGH
|
sangwan_kim
|
bookmark4u
|
PHP remote file inclusion vulnerability in Bookmark4U 1.8.3 allows remote attackers to execute arbitrary PHP code viaa URL in the prefix parameter to (1) dbase.php, (2) config.php, or (3) common.load…
|
CWE-94
Code Injection
|
CVE-2003-1253
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347314
|
5.0 |
MEDIUM
|
-
|
-
|
Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to execute arbitrary PHP code via (1) head.php, (2) apb_common.php, or (3) apb_view_class.php by modifying the APB_SETTINGS parameter to refe…
|
NVD-CWE-Other
|
CVE-2003-1254
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347315
|
6.8 |
MEDIUM
|
e-theni
|
e-theni
|
aff_liste_langue.php in E-theni allows remote attackers to execute arbitrary PHP code by modifying the rep_include parameter to reference a URL on a remote web server that contains para_langue.php.
|
NVD-CWE-Other
|
CVE-2003-1256
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347316
|
6.8 |
MEDIUM
|
e-theni
|
e-theni
|
Successful exploitation requires that "register_globals" is enabled.
|
NVD-CWE-Other
|
CVE-2003-1256
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347317
|
5.0 |
MEDIUM
|
e-theni
|
e-theni
|
find_theni_home.php in E-theni allows remote attackers to obtain sensitive system information via a URL request which executes phpinfo.
|
NVD-CWE-Other
|
CVE-2003-1257
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347318
|
7.5 |
HIGH
|
versatilebulletinboard
|
versatilebulletinboard
|
activate.php in versatileBulletinBoard (vBB) 0.9.5 and 0.9.6 allows remote attackers to gain unauthorized administrative access via a URL request with the uid parameter set to the webmaster uid.
|
NVD-CWE-Other
|
CVE-2003-1258
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347319
|
7.5 |
HIGH
|
-
|
-
|
Buffer overflow in CuteFTP 4.2 and 5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.
|
NVD-CWE-Other
|
CVE-2003-1259
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347320
|
7.6 |
HIGH
|
globalscape
|
cuteftp
|
Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command.
|
NVD-CWE-Other
|
CVE-2003-1260
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347321
|
2.1 |
LOW
|
globalscape
|
cuteftp
|
Buffer overflow in CuteFTP 5.0 and 5.0.1 allows local users to cause a denial of service (crash) by copying a long URL into a clipboard.
|
NVD-CWE-Other
|
CVE-2003-1261
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347322
|
5.0 |
MEDIUM
|
brown_bear_software
|
ical
|
ICAL.EXE in iCal 3.7 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, possibly due to an invalid method name.
|
NVD-CWE-Other
|
CVE-2003-1263
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347323
|
5.0 |
MEDIUM
|
d-link longshine_technologie
|
di-614\+ longshine_wireless_ethernet_access_point
|
TFTP server in Longshine Wireless Access Point (WAP) LCS-883R-AC-B, and in D-Link DI-614+ 2.0 which is based on it, allows remote attackers to obtain the WEP secret and gain administrator privileges …
|
NVD-CWE-Other
|
CVE-2003-1264
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347324
|
2.1 |
LOW
|
mozilla netscape
|
mozilla navigator
|
Netscape 7.0 and Mozilla 5.0 do not immediately delete messages in the trash folder when users select the 'Empty Trash' option, which could allow local users to access deleted messages.
|
NVD-CWE-Other
|
CVE-2003-1265
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347325
|
5.0 |
MEDIUM
|
etype
|
eserv
|
The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a denial of service (crash) via a large amount of data.
|
NVD-CWE-Other
|
CVE-2003-1266
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347326
|
5.0 |
MEDIUM
|
steve_poulsen
|
guildftpd
|
GuildFTPd 0.999 allows remote attackers to cause a denial of service (crash) via a GET request for MS-DOS device names such as lpt1.
|
NVD-CWE-Other
|
CVE-2003-1267
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347327
|
7.5 |
HIGH
|
urlogy
|
a.shop.kart
|
Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive informatio…
|
NVD-CWE-Other
|
CVE-2003-1268
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347328
|
5.0 |
MEDIUM
|
an
|
an-http
|
AN HTTP 1.41e allows remote attackers to obtain the root web server path via an HTTP request with a long argument to a script, which leaks the path in an error message.
|
NVD-CWE-Other
|
CVE-2003-1269
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347329
|
5.0 |
MEDIUM
|
an
|
an-http
|
AN HTTP 1.41e allows remote attackers to cause a denial of service (borken pipe) via an HTTP request to aux.cgi with a long argument, possibly triggering a buffer overflow or MS-DOS device vulnerabil…
|
NVD-CWE-Other
|
CVE-2003-1270
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347330
|
4.3 |
MEDIUM
|
an
|
an-http
|
Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTML as other users via a URL containing the script.
|
NVD-CWE-Other
|
CVE-2003-1271
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347331
|
5.0 |
MEDIUM
|
microsoft
|
pocket_ie
|
Pocket Internet Explorer (PIE) 3.0 allows remote attackers to cause a denial of service (crash) via a Javascript function that uses the object.innerHTML function to recursively call that function.
|
NVD-CWE-Other
|
CVE-2003-1275
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347332
|
4.6 |
MEDIUM
|
nettelephone
|
nettelephone
|
Netfone.exe of NetTelephone 3.5.6 uses weak encryption for user PIN's and stores user account numbers in plaintext in the HKEY_CURRENT_USER\Software\MediaRing.com\SDK\NetTelephone\settings registry k…
|
NVD-CWE-Other
|
CVE-2003-1276
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347333
|
4.3 |
MEDIUM
|
yabb
|
yabb
|
Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information v…
|
NVD-CWE-Other
|
CVE-2003-1277
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347334
|
4.3 |
MEDIUM
|
infopop
|
opentopic
|
Cross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 allows remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting a…
|
NVD-CWE-Other
|
CVE-2003-1278
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347335
|
4.6 |
MEDIUM
|
-
|
-
|
S-PLUS 6.0 allows local users to overwrite arbitrary files and possibly elevate privileges via a symlink attack on (1) /tmp/__F8499 by Sqpe, (2) /tmp/PRINT.$$.out by PRINT, (3) /tmp/SUBST$PID.TXT and…
|
NVD-CWE-Other
|
CVE-2003-1279
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347336
|
5.0 |
MEDIUM
|
eekim
|
cgihtml
|
Directory traversal vulnerability in cgihtml 1.69 allows remote attackers to overwrite and create arbitrary files via a .. (dot dot) in multipart/form-data uploads.
|
NVD-CWE-Other
|
CVE-2003-1280
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347337
|
2.1 |
LOW
|
eekim
|
cgihtml
|
cgihtml 1.69 allows local users to overwrite arbitrary files via a symlink attack on certain temporary files.
|
NVD-CWE-Other
|
CVE-2003-1281
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347338
|
5.0 |
MEDIUM
|
-
|
-
|
IBM Net.Data allows remote attackers to obtain sensitive information such as path names, server names and possibly user names and passwords by causing the (1) $(DTW_CURRENT_FILENAME), (2) $(DATABASE)…
|
NVD-CWE-Other
|
CVE-2003-1282
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347339
|
7.5 |
HIGH
|
kazaa
|
kazaa_media_desktop
|
KaZaA Media Desktop (KMD) 2.0 launches advertisements in the Internet Explorer (IE) local security zone, which could allow remote attackers to view local files and possibly execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2003-1283
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347340
|
5.0 |
MEDIUM
|
vserver
|
linux-vserver
|
Multiple race conditions in Linux-VServer 1.22 with Linux kernel 2.4.23 and SMP allow local users to cause a denial of service (kernel oops) via unknown attack vectors related to the (1) s_info and (…
|
NVD-CWE-Other
|
CVE-2003-1288
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347341
|
4.3 |
MEDIUM
|
nukedweb
|
guestbookhost
|
Multiple cross-site scripting (XSS) vulnerabilities in NukedWeb GuestBookHost allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Email and (3) Message fields when sig…
|
NVD-CWE-Other
|
CVE-2003-1293
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347342
|
2.1 |
LOW
|
redhat suse
|
enterprise_linux suse_linux
|
Unspecified vulnerability in xscreensaver 4.12, and possibly other versions, allows attackers to cause xscreensaver to crash via unspecified vectors "while verifying the user-password."
|
NVD-CWE-Other
|
CVE-2003-1295
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347343
|
5.0 |
MEDIUM
|
-
|
-
|
Easy File Sharing (EFS) Web Server 1.2 stores the (1) option.ini (aka options.ini) file and (2) log directory under the web root with insufficient access control, which allows remote attackers to obt…
|
NVD-CWE-Other
|
CVE-2003-1297
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347344
|
5.0 |
MEDIUM
|
pablo_software_solutions
|
baby_ftp_server
|
Baby FTP Server (BabyFTP) 1.2, and possibly other versions before May 31, 2003, allows remote attackers to cause a denial of service via a large number of connections from the same IP address, which …
|
NVD-CWE-Other
|
CVE-2003-1300
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347345
|
2.6 |
LOW
|
-
|
-
|
Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors …
|
NVD-CWE-Other
|
CVE-2003-1306
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347346
|
2.6 |
LOW
|
-
|
-
|
Successful exploitation requires that the RemoveServerHeader option is enabled.
|
NVD-CWE-Other
|
CVE-2003-1306
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347347
|
4.6 |
MEDIUM
|
fvwm
|
fvwm
|
CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary commands via carriage returns in a filename.
|
NVD-CWE-Other
|
CVE-2003-1308
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347348
|
6.8 |
MEDIUM
|
-
|
-
|
siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder does not ensure that the TARGET parameter names a valid redirection resource, which allows remote attackers to construct a URL that might tric…
|
NVD-CWE-Other
|
CVE-2003-1311
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347349
|
4.3 |
MEDIUM
|
-
|
-
|
siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder places a session ID string in the value of the SMSESSION parameter in a URL, which might allow remote attackers to obtain the ID by sniffing, …
|
NVD-CWE-Other
|
CVE-2003-1312
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347350
|
7.5 |
HIGH
|
eternalmart
|
mailing_list_manager
|
Multiple PHP remote file inclusion vulnerabilities in EternalMart Mailing List Manager (EMLM) 1.32 allow remote attackers to execute arbitrary PHP code via a URL in (1) the emml_admin_path parameter …
|
NVD-CWE-Other
|
CVE-2003-1313
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|