6.8
    Medium

    CVE-2003-1385

    Last Modified: 28 Oct 2012

    ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.

    Source:frog
    Published:31 Dec 2003
    6.8
    Medium

    CVE-2003-1381

    Last Modified: 28 Oct 2012

    Format string vulnerability in AMX 0.9.2 and earlier, a plugin for Valve Software's Half-Life Server, allows remote attackers to execute arbitrary commands via format string specifiers in the amx_say command.

    Source:greuff
    Published:31 Dec 2003
    8.8
    High

    CVE-2003-1378

    Last Modified: 28 Oct 2012

    Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.

    Source:http-equiv
    Published:31 Dec 2003
    7.2
    High

    CVE-2003-1375

    Last Modified: 25 Oct 2012

    Buffer overflow in wall for HP-UX 10.20 through 11.11 may allow local users to execute arbitrary code by calling wall with a large file as an argument.

    Source:Scotty
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1372

    Last Modified: 23 Dec 2016

    Cross-site scripting (XSS) vulnerability in links.php script in myPHPNuke 1.8.8, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the (1) ratenum or (2) query parameters.

    Source:Tacettin Karadeniz
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1371

    Last Modified: 27 Oct 2012

    Nuked-Klan 1.3b, and possibly earlier versions, allows remote attackers to obtain sensitive server information via an op parameter set to phpinfo for the (1) Team, (2) News, or (3) Liens modules.

    Source:gregory Le Bras
    Published:31 Dec 2003
    6.8
    Medium

    CVE-2003-1369

    Last Modified: 24 Oct 2012

    Buffer overflow in ByteCatcher FTP client 1.04b allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.

    Source:Dennis Rand
    Published:31 Dec 2003
    6.4
    Medium

    CVE-2003-1368

    Last Modified: 24 Oct 2012

    Buffer overflow in the 32bit FTP client 9.49.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.

    Source:Dennis Rand
    Published:31 Dec 2003
    3.3
    Low

    CVE-2003-1366

    Last Modified: 24 Oct 2012

    chpass in OpenBSD 2.0 through 3.2 allows local users to read portions of arbitrary files via a hard link attack on a temporary file used to store user database information.

    Source:Marc Bevand
    Published:31 Dec 2003
    8.5
    High

    CVE-2003-1364

    Last Modified: 3 Nov 2012

    Aprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of service (crash) via an HTTP GET message with empty (1) Connection or (2) Range fields.

    Source:Auriemma Luigi
    Published:31 Dec 2003
    7.2
    High

    CVE-2003-1359

    Last Modified: 25 Oct 2012

    Buffer overflow in stmkfont utility of HP-UX 10.0 through 11.22 allows local users to gain privileges via a long command line argument.

    Source:Last Stage of Delirium
    Published:31 Dec 2003
    7.2
    High

    CVE-2003-1358

    Last Modified: 25 Oct 2012

    rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.

    Source:Last Stage of Delirium
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1355

    Last Modified: 28 Oct 2012

    Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long user name and password.

    Source:greuff
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1354

    Last Modified: 23 Oct 2012

    Multiple GameSpy 3D 2.62 compatible gaming servers generate very large UDP responses to small requests, which allows remote attackers to use the servers as an amplifier in DDoS attacks with spoofed UDP query packets, as demonstrated using Battlefield 1942.

    Source:Mike Kristovich
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1350

    Last Modified: 24 Oct 2012

    List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl field.

    Source:Statix
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1348

    Last Modified: 24 Oct 2012

    Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) name, or (3) title field.

    Source:BrainRawt
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1347

    Last Modified: 22 Oct 2012

    Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to comment.php, (2) uid parameter to profiles.php, (3) uid to users.php, and (4) homepage field.

    Source:snooq
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1344

    Last Modified: 23 Oct 2012

    Trend Micro Virus Control System (TVCS) Log Collector allows remote attackers to obtain usernames, encrypted passwords, and other sensitive information via a URL request for getservers.exe with the action parameter set to "selects1", which returns log files.

    Source:Rod Boron
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1343

    Last Modified: 23 Oct 2012

    Trend Micro ScanMail for Exchange (SMEX) before 3.81 and before 6.1 might install a back door account in smg_Smxcfg30.exe, which allows remote attackers to gain access to the web management interface via the vcc parameter, possibly "3560121183d3".

    Source:Rod Boron
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1342

    Last Modified: 23 Oct 2012

    Trend Micro Virus Control System (TVCS) 1.8 running with IIS allows remote attackers to cause a denial of service (memory consumption) in IIS via multiple URL requests for ActiveSupport.exe.

    Source:Rod Boron
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1341

    Last Modified: 22 Oct 2012

    The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.exe and gain access to the web management console via a direct request to cgiMasterPwd.exe.

    Source:Rod Boron
    Published:31 Dec 2003
    10
    Critical

    CVE-2003-1339

    Last Modified: 22 Feb 2016

    Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare allows remote attackers to cause a denial of service (crash) or execute arbitrary code, as demonstrated via (1) a long GET request and (2) a long operation or autologin parameter to SwEzModule.dll.

    Source:Peter Winter-Smith
    Published:31 Dec 2003
    9.3
    Critical

    CVE-2003-1336

    Last Modified: 10 Mar 2011

    Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL.

    Source:Metasploit
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1328

    Last Modified: 25 Oct 2012

    The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Validation with ShowHelp functionality."

    Source:Andreas Sandblad
    Published:19 Feb 2003
    5.2
    Medium

    CVE-2003-1325

    Last Modified: 16 Apr 2026

    The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a certain connection string to UDP port 27015 that represents "absence of player informations," a related issue to CVE-2006-0734.

    Source:Firestorm
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1321

    Last Modified: 1 Dec 2012

    Buffer overflow in Avant Browser 8.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request.

    Published:31 Dec 2003
    7.8
    High

    CVE-2003-1318

    Last Modified: 16 Apr 2026

    Twilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request for a long URI, a different vulnerability than CVE-2004-2376.

    Source:anonymous
    Published:31 Dec 2003
    6.8
    Medium

    CVE-2003-1317

    Last Modified: 2 Dec 2012

    Cross-site scripting (XSS) vulnerability in mod.php in eNdonesia 8.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Bahaa Naamneh
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1314

    Last Modified: 21 Sept 2016

    PHP remote file inclusion vulnerability in admin/auth.php in EternalMart Guestbook (EMGB) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the emgb_admin_path parameter.

    Source:mdx
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1313

    Last Modified: 8 Dec 2012

    Multiple PHP remote file inclusion vulnerabilities in EternalMart Mailing List Manager (EMLM) 1.32 allow remote attackers to execute arbitrary PHP code via a URL in (1) the emml_admin_path parameter to admin/auth.php or (2) the emml_path parameter to emml_email_func.php.

    Source:frog
    Published:31 Dec 2003
    4.6
    Medium

    CVE-2003-1310

    Last Modified: 28 Nov 2012

    The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain privileges by overwriting memory locations via certain control codes (aka "Device Driver Attack").

    Source:Lord Yup
    Published:31 Dec 2003
    4.6
    Medium

    CVE-2003-1308

    Last Modified: 16 Dec 2012

    CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary commands via carriage returns in a filename.

    Source:auto22238
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1307

    Last Modified: 31 Jan 2017

    The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP.

    Source:Steve Grubb
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1304

    Last Modified: 21 Nov 2012

    EarlyImpact ProductCart 1.0 through 2.0 stores database/EIPC.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive database information via a direct request.

    Source:Tri Huynh
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1292

    Last Modified: 16 Apr 2026

    PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbitrary remote files via a URL in the pathtoashnews parameter to (1) ashnews.php and (2) ashheadlines.php.

    Source:Kacper
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1286

    Last Modified: 6 Sept 2017

    HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attackers to send proxy HTTP requests to the Sambar Server's administrative interface and external web servers, by making a "Connection: keep-alive" request before the proxy requests.

    Source:David Endler
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1278

    Last Modified: 21 Oct 2012

    Cross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 allows remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into IMG tags.

    Source:frog
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1275

    Last Modified: 20 Oct 2012

    Pocket Internet Explorer (PIE) 3.0 allows remote attackers to cause a denial of service (crash) via a Javascript function that uses the object.innerHTML function to recursively call that function.

    Source:Christopher Sogge Røtnes
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1271

    Last Modified: 21 Oct 2012

    Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTML as other users via a URL containing the script.

    Source:D4rkGr3y
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1266

    Last Modified: 21 Oct 2012

    The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a denial of service (crash) via a large amount of data.

    Source:D4rkGr3y
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1263

    Last Modified: 11 Jul 2017

    ICAL.EXE in iCal 3.7 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, possibly due to an invalid method name.

    Source:securma massine
    Published:31 Dec 2003
    7.6
    High

    CVE-2003-1260

    Last Modified: 23 Oct 2012

    Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command.

    Source:snooq
    Published:31 Dec 2003
    6.8
    Medium

    CVE-2003-1256

    Last Modified: 28 Oct 2012

    aff_liste_langue.php in E-theni allows remote attackers to execute arbitrary PHP code by modifying the rep_include parameter to reference a URL on a remote web server that contains para_langue.php.

    Source:frog
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1252

    Last Modified: 21 Oct 2012

    register.php in S8Forum 3.0 allows remote attackers to execute arbitrary PHP commands by creating a user whose name ends in a .php extension and entering the desired commands into the E-mail field, which creates a web-accessible .php file that can be called by the attacker, as demonstrated using a "system($cmd)" E-mail address with a "any_name.php" username.

    Source:nmsh_sa
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1251

    Last Modified: 20 Oct 2012

    The (1) menu.inc.php, (2) datasets.php and (3) mass_operations.inc.php (mistakenly referred to as mass_opeations.inc.php) scripts in N/X 2002 allow remote attackers to execute arbitrary PHP code via a c_path that references a URL on a remote web server that contains the code.

    Source:frog
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1247

    Last Modified: 21 Oct 2012

    Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::readFile, (2) a long path in diskusage, and (3) a long fname in flist.

    Source:Carl Livitt
    Published:31 Dec 2003
    10
    Critical

    CVE-2003-1245

    Last Modified: 28 Oct 2012

    index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash of a session cookie.

    Source:Simen Bergo
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1244

    Last Modified: 27 Oct 2012

    SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and possibly gain unauthorized access to forums via the forum_id parameter to index.php.

    Source:David Zentner
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1243

    Last Modified: 27 Oct 2012

    Cross-site scripting vulnerability (XSS) in Sage 1.0 b3 allows remote attackers to insert arbitrary HTML or web script via the mod parameter.

    Source:euronymous
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1242

    Last Modified: 27 Oct 2012

    Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path in an error message.

    Source:euronymous
    Published:31 Dec 2003