CSV
182,473 results for "vulnerability" Page 68
CVE-2003-1495

Unspecified vulnerability in the non-SSL web agent in various HP Management Agent products allows local users or remote attackers to gain privileges or cause a denial of service via unknown attack vectors.

Dec 31, 2003 6 affected product(s) NVD
10.0
CVSS
5.2%
EPSS
⚡ 41.6
CVE-2003-1361

Unknown vulnerability in VERITAS Bare Metal Restore (BMR) of Tivoli Storage Manager (TSM) 3.1.0 through 3.2.1 allows remote attackers to gain root privileges on the BMR Main Server.

Dec 31, 2003 1 affected product(s) NVD
10.0
CVSS
2.2%
EPSS
⚡ 40.7
CVE-2003-1496

Unspecified vulnerability in CDE dtmailpr of HP Tru64 4.0F through 5.1B allows local users to gain privileges via unknown attack vectors. NOTE: due to lack of details in the vendor advisory, it is not clear whether this is the same issue as CVE-1999-0840.

Dec 31, 2003 19 affected product(s) NVD
10.0
CVSS
2.3%
EPSS
⚡ 40.7
CVE-2003-1378

Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.

Dec 31, 2003 4 affected product(s) NVD
8.8
CVSS
15.6%
EPSS
⚡ 39.9
CVE-2003-1406

PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_header parameter to header.php3 or (2) my_footer parameter to footer.php3.

Dec 31, 2003 3 affected product(s) NVD
7.5
CVSS
2.5%
EPSS
⚡ 30.8
CVE-2003-1380

Directory traversal vulnerability in BisonFTP Server 4 release 2 allows remote attackers to (1) list directories above the root via an 'ls @../' command, or (2) list files above the root via a "mget @../FILE" command.

Dec 31, 2003 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2003-1402

PHP remote file inclusion vulnerability in hit.php for Kietu 2.0 and 2.3 allows remote attackers to execute arbitrary PHP code via the url_hit parameter, a different vulnerability than CVE-2006-5015.

Dec 31, 2003 2 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2003-1435

SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.

Dec 31, 2003 2 affected product(s) NVD
7.5
CVSS
1.7%
EPSS
⚡ 30.5
CVE-2003-1466

Unspecified vulnerability in Phorum 3.4 through 3.4.2 allows remote attackers to use Phorum as a connection proxy to other sites via (1) register.php or (2) login.php.

Dec 31, 2003 3 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.4
CVE-2003-1458

SQL injection vulnerability in Profile.php in ttCMS 2.2 and ttForum allows remote attackers to execute arbitrary SQL commands via the member name.

Dec 31, 2003 2 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2003-1461

Buffer overflow in rwrite for HP-UX 11.0 could allow local users to execute arbitrary code via a long argument. NOTE: the vendor was unable to reproduce the problem on a system that had been patched for an lp vulnerability (CVE-2002-1473).

Dec 31, 2003 1 affected product(s) NVD
7.2
CVSS
1.5%
EPSS
⚡ 29.3
CVE-2003-1474

slashem-tty in the FreeBSD Ports Collection is installed with write permissions for the games group, which allows local users with group games privileges to modify slashem-tty and execute arbitrary code as other users, as demonstrated using a separate vulnerability in LTris.

Dec 31, 2003 1 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2003-1381

Format string vulnerability in AMX 0.9.2 and earlier, a plugin for Valve Software's Half-Life Server, allows remote attackers to execute arbitrary commands via format string specifiers in the amx_say command.

Dec 31, 2003 1 affected product(s) NVD
6.8
CVSS
2.6%
EPSS
⚡ 28
CVE-2003-1412

PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code via the plugin parameter to (1) 3fax/1blocklists/index.php; (2) 6departamentadmin/index.php, (3) 5terminals/index.php, (4) 4mailinglists/index.php, (5) 3departaments/index.php, and (6) 2groupd/index.php in 2administration/; or (7) the base parameter to include/help.php.

Dec 31, 2003 1 affected product(s) NVD
6.8
CVSS
2.7%
EPSS
⚡ 28
CVE-2003-1410

PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary PHP code via the cer_skin parameter.

Dec 31, 2003 2 affected product(s) NVD
6.8
CVSS
2.3%
EPSS
⚡ 27.9
CVE-2003-1411

PHP remote file inclusion vulnerability in emailreader_execute_on_each_page.inc.php in Cedric Email Reader 0.4 allows remote attackers to execute arbitrary PHP code via the emailreader_ini parameter.

Dec 31, 2003 1 affected product(s) NVD
6.8
CVSS
2.3%
EPSS
⚡ 27.9
CVE-2003-1436

PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute arbitrary PHP code via the filhead parameter.

Dec 31, 2003 6 affected product(s) NVD
6.8
CVSS
2.1%
EPSS
⚡ 27.8
CVE-2003-1373

Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. (dot dot) sequences followed by NULL (%00) characters in CGI parameters, as demonstrated using the lang parameter in prefs.php.

Dec 31, 2003 4 affected product(s) NVD
6.8
CVSS
1.3%
EPSS
⚡ 27.6
CVE-2003-1427

Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary files, such as the netgear.cfg configuration file, via a hex-encoded (%2e%2e%2f) ../ (dot dot slash) in the port parameter.

Dec 31, 2003 1 affected product(s) NVD
6.4
CVSS
2.8%
EPSS
⚡ 26.4
CVE-2003-1494

Unspecified vulnerability in HP OpenView Network Node Manager (NNM) 6.2 and 6.4 allows remote attackers to cause a denial of service (CPU consumption) via a crafted TCP packet.

Dec 31, 2003 2 affected product(s) NVD
5.0
CVSS
3.2%
EPSS
⚡ 21