268901
|
- |
|
-
|
-
|
The RPM installation of SAP DB 7.x creates the (1) dbmsrv or (2) lserver programs with world-writable permissions, which allows local users to gain privileges by modifying those programs.
|
NVD-CWE-Other
|
CVE-2003-1034
|
2017-07-11 10:29 |
2004-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268902
|
- |
|
sap
|
internet_transaction_server
|
Multiple buffer overflows in the AGate component for SAP Internet Transaction Server (ITS) allow remote attackers to execute arbitrary code via long (1) ~command, (2) ~runtimemode, or (3) ~session pa…
|
NVD-CWE-Other
|
CVE-2003-1036
|
2017-07-11 10:29 |
2004-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268903
|
- |
|
sap
|
internet_transaction_server
|
Format string vulnerability in the WGate component for SAP Internet Transaction Server (ITS) allows remote attackers to execute arbitrary code via a high "trace level."
|
NVD-CWE-Other
|
CVE-2003-1037
|
2017-07-11 10:29 |
2004-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268904
|
- |
|
sap
|
internet_transaction_server
|
The AGate component for SAP Internet Transaction Server (ITS) allows remote attackers to obtain sensitive information via a ~command parameter with an AgateInstallCheck value, which provides a list o…
|
NVD-CWE-Other
|
CVE-2003-1038
|
2017-07-11 10:29 |
2004-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268905
|
- |
|
sap
|
mysap_business_suite
|
Multiple buffer overflows in the mySAP.com architecture for SAP allow remote attackers to execute arbitrary code via a long HTTP Host header to (1) Message Server, (2) Web Dispatcher, or (3) Applicat…
|
NVD-CWE-Other
|
CVE-2003-1039
|
2017-07-11 10:29 |
2004-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268906
|
- |
|
mozilla
|
bugzilla
|
SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to execute arbitrary SQL via the product name.
|
NVD-CWE-Other
|
CVE-2003-1042
|
2017-07-11 10:29 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268907
|
- |
|
mozilla
|
bugzilla
|
SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges to execute arbitrary SQL via the id parameter to …
|
NVD-CWE-Other
|
CVE-2003-1043
|
2017-07-11 10:29 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268908
|
- |
|
mozilla
|
bugzilla
|
editproducts.cgi in Bugzilla 2.16.3 and earlier, when usebuggroups is enabled, does not properly remove group add privileges from a group that is being deleted, which allows users with those privileg…
|
NVD-CWE-Other
|
CVE-2003-1044
|
2017-07-11 10:29 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268909
|
- |
|
mozilla
|
bugzilla
|
votes.cgi in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote attackers to read a user's voting page when that user has voted on a restricted bug, which allows remote attackers t…
|
NVD-CWE-Other
|
CVE-2003-1045
|
2017-07-11 10:29 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268910
|
- |
|
mozilla
|
bugzilla
|
describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwi…
|
NVD-CWE-Other
|
CVE-2003-1046
|
2017-07-11 10:29 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|