|
313501
|
4.6 |
MEDIUM
|
microsoft
|
mn-500_wireless_base_station
|
The backup configuration file for Microsoft MN-500 wireless base station stores administrative passwords in plaintext, which allows local users to gain access.
|
CWE-255
証明書・パスワード管理
|
CVE-2003-1482
|
2008-09-6 05:37 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313502
|
5.0 |
MEDIUM
|
clearswift
|
mailsweeper
|
Clearswift MAILsweeper 4.0 through 4.3.7 allows remote attackers to bypass filtering via a file attachment that contains "multiple extensions combined with large blocks of white space."
|
CWE-20
不適切な入力確認
|
CVE-2003-1485
|
2008-09-6 05:37 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313503
|
4.6 |
MEDIUM
|
snert.com
|
mod_throttle
|
mod_throttle 3.0 allows local users with Apache privileges to access shared memory that points to a file that is writable by the apache user, which could allow local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2003-1502
|
2008-09-6 05:37 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313504
|
4.3 |
MEDIUM
|
mirc
|
mirc
|
Buffer overflow in mIRC 6.12, when the DCC get dialog window has been minimized and the user opens the minimized window, allows remote attackers to cause a denial of service (crash) via a long filena…
|
CWE-119
バッファエラー
|
CVE-2003-1508
|
2008-09-6 05:37 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313505
|
4.3 |
MEDIUM
|
bajie
|
java_http_server
|
Cross-site scripting (XSS) vulnerability in Bajie Java HTTP Server 0.95 through 0.95zxv4 allows remote attackers to inject arbitrary web script or HTML via (1) the query string to test.txt, (2) the g…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2003-1511
|
2008-09-6 05:37 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313506
|
5.0 |
MEDIUM
|
khaled_mardam-bey
|
mirc
|
Buffer overflow in mIRC 6.1 and 6.11 allows remote attackers to cause a denial of service (crash) via a long DCC SEND request.
|
CWE-119
バッファエラー
|
CVE-2003-1512
|
2008-09-6 05:37 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313507
|
6.8 |
MEDIUM
|
sun
|
java_plug-in
|
The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote …
|
NVD-CWE-Other
|
CVE-2003-1516
|
2008-09-6 05:37 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313508
|
6.8 |
MEDIUM
|
fuzzymonkey
|
myclassifieds
|
SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email parameter.
|
CWE-89
SQLインジェクション
|
CVE-2003-1520
|
2008-09-6 05:37 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313509
|
6.4 |
MEDIUM
|
sun
|
java_plug-in
|
Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates t…
|
NVD-CWE-Other
|
CVE-2003-1521
|
2008-09-6 05:37 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313510
|
5.0 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
PHP-Nuke 7.0 allows remote attackers to obtain the installation path via certain characters such as (1) ", (2) ', or (3) > in the search field, which reveals the path in an error message.
|
CWE-200
情報漏えい
|
CVE-2003-1526
|
2008-09-6 05:37 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313511
|
4.3 |
MEDIUM
|
ibm iss
|
internet_security_systems_blackice_defender blackice_server_protection
|
BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packet…
|
NVD-CWE-Other
|
CVE-2003-1527
|
2008-09-6 05:37 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313512
|
5.0 |
MEDIUM
|
postnuke_software_foundation
|
postnuke
|
Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php.
|
CWE-22
パス・トラバーサル
|
CVE-2003-1537
|
2008-09-6 05:37 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313513
|
6.4 |
MEDIUM
|
suse
|
suse_linux_openexchange_server office_server suse_linux
|
susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands vi…
|
CWE-20
不適切な入力確認
|
CVE-2003-1538
|
2008-09-6 05:37 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313514
|
4.3 |
MEDIUM
|
onedotoh
|
simple_file_manager
|
Cross-site scripting (XSS) vulnerability in ONEdotOH Simple File Manager (SFM) before 0.21 allows remote attackers to inject arbitrary web script or HTML via (1) file names and (2) directory names.
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2003-1539
|
2008-09-6 05:37 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313515
|
5.0 |
MEDIUM
|
ondrej_jombik
|
phpwebfilemanager
|
Directory traversal vulnerability in plugins/file.php in phpWebFileManager before 0.4.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the fm_path parameter.
|
CWE-22
パス・トラバーサル
|
CVE-2003-1542
|
2008-09-6 05:37 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313516
|
5.0 |
MEDIUM
|
ssh
|
secure_shell
|
SSH Secure Shell before 3.2.9 allows remote attackers to cause a denial of service via malformed BER/DER packets.
|
NVD-CWE-Other
|
CVE-2003-1119
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313517
|
5.0 |
MEDIUM
|
sun
|
one_directory_server
|
Unknown vulnerability in ns-ldapd for Sun ONE Directory Server 4.16, 5.0, and 5.1 allows LDAP clients to cause a denial of service (service halt).
|
NVD-CWE-Other
|
CVE-2003-1125
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313518
|
5.0 |
MEDIUM
|
sun
|
one_web_server
|
Unknown vulnerability in SunOne/iPlanet Web Server SP3 through SP5 on Windows platforms allows remote attackers to cause a denial of service.
|
NVD-CWE-Other
|
CVE-2003-1126
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313519
|
5.0 |
MEDIUM
|
cisco
|
content_services_switch_11000 content_services_switch_11500
|
The DNS server for Cisco Content Service Switch (CSS) 11000 and 11500, when prompted for a nonexistent AAAA record, responds with response code 3 (NXDOMAIN or "Name Error") instead of response code 0…
|
NVD-CWE-Other
|
CVE-2003-1132
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313520
|
2.1 |
LOW
|
sun
|
java
|
Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of genera…
|
NVD-CWE-Other
|
CVE-2003-1134
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313521
|
2.6 |
LOW
|
yahoo
|
messenger
|
Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo…
|
NVD-CWE-Other
|
CVE-2003-1135
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313522
|
5.0 |
MEDIUM
|
redhat
|
interchange
|
The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page …
|
NVD-CWE-Other
|
CVE-2003-1138
|
2008-09-6 05:36 |
2003-10-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313523
|
6.8 |
MEDIUM
|
john_beatty
|
easy_php_photo_album
|
Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.
|
NVD-CWE-Other
|
CVE-2003-1146
|
2008-09-6 05:36 |
2003-05-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313524
|
7.2 |
HIGH
|
linux
|
linux_kernel
|
exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the s…
|
NVD-CWE-Other
|
CVE-2003-1161
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313525
|
5.0 |
MEDIUM
|
-
|
-
|
HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message.
|
NVD-CWE-Other
|
CVE-2003-1168
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313526
|
7.2 |
HIGH
|
gernot_stocker
|
kpopup
|
Format string vulnerability in main.cpp in kpopup 0.9.1 and 0.9.5pre2 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via format string specif…
|
NVD-CWE-Other
|
CVE-2003-1170
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313527
|
5.0 |
MEDIUM
|
-
|
-
|
BRW WebWeaver 1.03 allows remote attackers to obtain sensitive server environment information via a URL request for testcgi.exe, which lists the values of environment variables and the current workin…
|
NVD-CWE-Other
|
CVE-2003-1235
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313528
|
10.0 |
HIGH
|
tanne
|
tanne
|
Multiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to execute arbitrary code via format string specifiers in syslog.
|
NVD-CWE-Other
|
CVE-2003-1236
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313529
|
4.3 |
MEDIUM
|
-
|
-
|
Cross-site scripting vulnerability (XSS) in WWWBoard 2.0A2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via a message post.
|
NVD-CWE-Other
|
CVE-2003-1237
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313530
|
5.8 |
MEDIUM
|
nuked-klan
|
nuked-klan
|
Cross-site scripting vulnerability (XSS) in Nuked-Klan 1.3 beta and earlier allows remote attackers to steal authentication information via cookies by injecting arbitrary HTML or script into op of th…
|
NVD-CWE-Other
|
CVE-2003-1238
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313531
|
5.0 |
MEDIUM
|
wihphoto
|
wihphoto
|
Directory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via .. specifiers in the album parameter, and the target filename in the pic parame…
|
NVD-CWE-Other
|
CVE-2003-1239
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313532
|
7.5 |
HIGH
|
cutephp
|
cutenews
|
PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.php, or (3) comments…
|
CWE-94
コード・インジェクション
|
CVE-2003-1240
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313533
|
4.3 |
MEDIUM
|
levcgi.com
|
myguestbook
|
Cross-site scripting vulnerability (XSS) in (1) admin_index.php, (2) admin_pass.php, (3) admin_modif.php, and (4) admin_suppr.php in MyGuestbook 3.0 allows remote attackers to execute arbitrary PHP c…
|
NVD-CWE-Other
|
CVE-2003-1241
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313534
|
5.0 |
MEDIUM
|
-
|
-
|
Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path in an error message.
|
NVD-CWE-Other
|
CVE-2003-1242
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313535
|
7.5 |
HIGH
|
phpbb_group
|
phpbb
|
SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and possibly gain unauthorized access to forums via the forum_id par…
|
CWE-89
SQLインジェクション
|
CVE-2003-1244
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313536
|
2.1 |
LOW
|
pedestal_software
|
integrity_protection_driver
|
NtCreateSymbolicLinkObject in ntdll.dll in Integrity Protection Driver (IPD) 1.2 and 1.3 allows local users to create and overwrite arbitrary files via a symlink attack on \winnt\system32\drivers usi…
|
NVD-CWE-Other
|
CVE-2003-1246
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313537
|
7.5 |
HIGH
|
positive_software
|
h-sphere
|
Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::readFile, (2) a long path in diskusage, and (3) a long fnam…
|
NVD-CWE-Other
|
CVE-2003-1247
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313538
|
7.5 |
HIGH
|
positive_software
|
h-sphere
|
H-Sphere WebShell 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) mode and (2) zipfile parameters in a URL request.
|
NVD-CWE-Other
|
CVE-2003-1248
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313539
|
7.5 |
HIGH
|
businessobjects
|
webintelligence
|
WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions.
|
NVD-CWE-Other
|
CVE-2003-1249
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313540
|
5.0 |
MEDIUM
|
efficient_networks
|
5861_dsl_router
|
Efficient Networks 5861 DSL router, when running firmware 5.3.80 configured to block incoming TCP SYN, packets allows remote attackers to cause a denial of service (crash) via a flood of TCP SYN pack…
|
NVD-CWE-Other
|
CVE-2003-1250
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313541
|
7.5 |
HIGH
|
nx
|
n_x_web_content_management_system_2002
|
The (1) menu.inc.php, (2) datasets.php and (3) mass_operations.inc.php (mistakenly referred to as mass_opeations.inc.php) scripts in N/X 2002 allow remote attackers to execute arbitrary PHP code via …
|
NVD-CWE-Other
|
CVE-2003-1251
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313542
|
7.5 |
HIGH
|
kelli_shaver
|
s8forum
|
register.php in S8Forum 3.0 allows remote attackers to execute arbitrary PHP commands by creating a user whose name ends in a .php extension and entering the desired commands into the E-mail field, w…
|
NVD-CWE-Other
|
CVE-2003-1252
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313543
|
7.5 |
HIGH
|
sangwan_kim
|
bookmark4u
|
PHP remote file inclusion vulnerability in Bookmark4U 1.8.3 allows remote attackers to execute arbitrary PHP code viaa URL in the prefix parameter to (1) dbase.php, (2) config.php, or (3) common.load…
|
CWE-94
コード・インジェクション
|
CVE-2003-1253
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313544
|
5.0 |
MEDIUM
|
-
|
-
|
Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to execute arbitrary PHP code via (1) head.php, (2) apb_common.php, or (3) apb_view_class.php by modifying the APB_SETTINGS parameter to refe…
|
NVD-CWE-Other
|
CVE-2003-1254
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313545
|
6.8 |
MEDIUM
|
e-theni
|
e-theni
|
aff_liste_langue.php in E-theni allows remote attackers to execute arbitrary PHP code by modifying the rep_include parameter to reference a URL on a remote web server that contains para_langue.php.
|
NVD-CWE-Other
|
CVE-2003-1256
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313546
|
6.8 |
MEDIUM
|
e-theni
|
e-theni
|
Successful exploitation requires that "register_globals" is enabled.
|
NVD-CWE-Other
|
CVE-2003-1256
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313547
|
5.0 |
MEDIUM
|
e-theni
|
e-theni
|
find_theni_home.php in E-theni allows remote attackers to obtain sensitive system information via a URL request which executes phpinfo.
|
NVD-CWE-Other
|
CVE-2003-1257
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313548
|
7.5 |
HIGH
|
versatilebulletinboard
|
versatilebulletinboard
|
activate.php in versatileBulletinBoard (vBB) 0.9.5 and 0.9.6 allows remote attackers to gain unauthorized administrative access via a URL request with the uid parameter set to the webmaster uid.
|
NVD-CWE-Other
|
CVE-2003-1258
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313549
|
7.5 |
HIGH
|
-
|
-
|
Buffer overflow in CuteFTP 4.2 and 5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.
|
NVD-CWE-Other
|
CVE-2003-1259
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313550
|
7.6 |
HIGH
|
globalscape
|
cuteftp
|
Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command.
|
NVD-CWE-Other
|
CVE-2003-1260
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|