CSV
181,585 results for "vulnerability" Page 67
CVE-2003-1361

Unknown vulnerability in VERITAS Bare Metal Restore (BMR) of Tivoli Storage Manager (TSM) 3.1.0 through 3.2.1 allows remote attackers to gain root privileges on the BMR Main Server.

Dec 31, 2003 1 affected product(s) NVD
10.0
CVSS
2.2%
EPSS
⚡ 40.7
CVE-2003-1333

Unspecified vulnerability in the Cache' Server Page (CSP) implementation in InterSystems Cache' 4.0.3 through 5.0.5 allows remote attackers to "gain complete control" of a server.

Dec 31, 2003 11 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2003-1378

Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.

Dec 31, 2003 4 affected product(s) NVD
8.8
CVSS
15.6%
EPSS
⚡ 39.9
CVE-2003-1318

Twilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request for a long URI, a different vulnerability than CVE-2004-2376.

Dec 31, 2003 NVD
7.8
CVSS
3.1%
EPSS
⚡ 32.1
CVE-2003-1332

Stack-based buffer overflow in the reply_nttrans function in Samba 2.2.7a and earlier allows remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2003-0201.

Dec 31, 2003 1 affected product(s) NVD
7.5
CVSS
5.0%
EPSS
⚡ 31.5
CVE-2003-1314

PHP remote file inclusion vulnerability in admin/auth.php in EternalMart Guestbook (EMGB) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the emgb_admin_path parameter.

Dec 31, 2003 1 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2003-1406

PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_header parameter to header.php3 or (2) my_footer parameter to footer.php3.

Dec 31, 2003 3 affected product(s) NVD
7.5
CVSS
2.5%
EPSS
⚡ 30.8
CVE-2003-1380

Directory traversal vulnerability in BisonFTP Server 4 release 2 allows remote attackers to (1) list directories above the root via an 'ls @../' command, or (2) list files above the root via a "mget @../FILE" command.

Dec 31, 2003 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2003-1402

PHP remote file inclusion vulnerability in hit.php for Kietu 2.0 and 2.3 allows remote attackers to execute arbitrary PHP code via the url_hit parameter, a different vulnerability than CVE-2006-5015.

Dec 31, 2003 2 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2003-1244

SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and possibly gain unauthorized access to forums via the forum_id parameter to index.php.

Dec 31, 2003 3 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2003-1253

PHP remote file inclusion vulnerability in Bookmark4U 1.8.3 allows remote attackers to execute arbitrary PHP code viaa URL in the prefix parameter to (1) dbase.php, (2) config.php, or (3) common.load.php.

Dec 31, 2003 1 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2003-1315

SQL injection vulnerability in auth.php in Land Down Under (LDU) v601 and earlier allows remote attackers to execute arbitrary SQL commands.

Dec 31, 2003 1 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2003-1317

Cross-site scripting (XSS) vulnerability in mod.php in eNdonesia 8.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Dec 31, 2003 NVD
6.8
CVSS
4.0%
EPSS
⚡ 28.4
CVE-2003-1381

Format string vulnerability in AMX 0.9.2 and earlier, a plugin for Valve Software's Half-Life Server, allows remote attackers to execute arbitrary commands via format string specifiers in the amx_say command.

Dec 31, 2003 1 affected product(s) NVD
6.8
CVSS
2.6%
EPSS
⚡ 28
CVE-2003-1412

PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code via the plugin parameter to (1) 3fax/1blocklists/index.php; (2) 6departamentadmin/index.php, (3) 5terminals/index.php, (4) 4mailinglists/index.php, (5) 3departaments/index.php, and (6) 2groupd/index.php in 2administration/; or (7) the base parameter to include/help.php.

Dec 31, 2003 1 affected product(s) NVD
6.8
CVSS
2.7%
EPSS
⚡ 28
CVE-2003-1410

PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary PHP code via the cer_skin parameter.

Dec 31, 2003 2 affected product(s) NVD
6.8
CVSS
2.3%
EPSS
⚡ 27.9
CVE-2003-1411

PHP remote file inclusion vulnerability in emailreader_execute_on_each_page.inc.php in Cedric Email Reader 0.4 allows remote attackers to execute arbitrary PHP code via the emailreader_ini parameter.

Dec 31, 2003 1 affected product(s) NVD
6.8
CVSS
2.3%
EPSS
⚡ 27.9
CVE-2003-1373

Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. (dot dot) sequences followed by NULL (%00) characters in CGI parameters, as demonstrated using the lang parameter in prefs.php.

Dec 31, 2003 4 affected product(s) NVD
6.8
CVSS
1.3%
EPSS
⚡ 27.6
CVE-2003-1292

PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbitrary remote files via a URL in the pathtoashnews parameter to (1) ashnews.php and (2) ashheadlines.php.

Dec 31, 2003 1 affected product(s) NVD
5.0
CVSS
3.4%
EPSS
⚡ 21
CVE-2003-1349

Directory traversal vulnerability in NITE ftp-server (NiteServer) 1.83 allows remote attackers to list arbitrary directories via a "\.." (backslash dot dot) in the CD (CWD) command.

Dec 31, 2003 1 affected product(s) NVD
5.0
CVSS
2.3%
EPSS
⚡ 20.7