7.5
    High

    CVE-2003-1240

    Last Modified: 8 Dec 2016

    PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.php, or (3) comments.php.

    Source:Over_G
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1239

    Last Modified: 28 Oct 2012

    Directory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via .. specifiers in the album parameter, and the target filename in the pic parameter.

    Source:frog
    Published:31 Dec 2003
    10
    Critical

    CVE-2003-1236

    Last Modified: 21 Oct 2012

    Multiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to execute arbitrary code via format string specifiers in syslog.

    Source:dong-h0un yoU
    Published:31 Dec 2003
    5.1
    Medium

    CVE-2003-1232

    Last Modified: 30 Jun 2013

    Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted attackers to execute arbitrary commands, as demonstrated using the mode-name variable.

    Source:Georgi Guninski
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1228

    Last Modified: 2 Jan 2013

    Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via an HTTP request with a long path.

    Source:aion
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1227

    Last Modified: 9 Dec 2012

    PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix, allows remote attackers to inject arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412. NOTE: this issue might be exploitable only during installation, or if the administrator has not run a security script after installation.

    Source:peter
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1219

    Last Modified: 16 Dec 2012

    Cross-site scripting (XSS) vulnerability in the tep_href_link function in html_output.php for osCommerce before 2.2-MS3 allows remote attackers to inject arbitrary web script or HTML via the osCsid parameter.

    Source:JeiAr
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1216

    Last Modified: 7 Mar 2016

    SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the search_id parameter.

    Source:RusH
    Published:27 Nov 2003
    7.5
    High

    CVE-2003-1213

    Last Modified: 16 Nov 2012

    The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which allows remote attackers to obtain sensitive information via a direct request to database/db2000.mdb.

    Source:JeiAr
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1210

    Last Modified: 10 Nov 2012

    Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function.

    Source:Albert Puigsech Galicia
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1207

    Last Modified: 24 Dec 2012

    Crob FTP Server 3.5.1 allows remote authenticated users to cause a denial of service (crash) via a dir command with a large number of "." characters followed by a "/*" string.

    Source:Zero X
    Published:1 Feb 2004
    4.3
    Medium

    CVE-2003-1203

    Last Modified: 1 Nov 2012

    Cross-site scripting (XSS) vulnerability in index.php for Mambo Site Server 4.0.10 allows remote attackers to execute script on other clients via the ?option parameter.

    Source:Ertan Kurt
    Published:18 Mar 2003
    7.5
    High

    CVE-2003-1200

    Last Modified: 19 Dec 2012

    Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbitrary code via a long From parameter to Form2Raw.cgi.

    Source:Behrang Fouladi
    Published:29 Dec 2003
    6.8
    Medium

    CVE-2003-1199

    Last Modified: 1 Jan 2013

    Cross-site scripting (XSS) vulnerability in MyProxy 20030629 allows remote attackers to inject arbitrary web script or HTML via the URL.

    Source:Donato Ferrante
    Published:11 Mar 2004
    6.8
    Medium

    CVE-2003-1197

    Last Modified: 12 Dec 2012

    Cross-site scripting (XSS) vulnerability in index.php for Ledscripts.com LedForums Beta 1 allows remote attackers to inject arbitrary web script or HTML via the (1) top_message parameter or (2) topic field of a new thread.

    Source:ProXy
    Published:30 Oct 2003
    7.5
    High

    CVE-2003-1196

    Last Modified: 12 Dec 2012

    SQL injection vulnerability in viewtopic.asp in VieBoard 2.6 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.

    Published:3 Nov 2003
    10
    Critical

    CVE-2003-1192

    Last Modified: 12 Dec 2012

    Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET request.

    Source:Peter Winter-Smith
    Published:3 Nov 2003
    5
    Medium

    CVE-2003-1191

    Last Modified: 11 Dec 2012

    chatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML in the Name field, which prevents the main.php form from being loaded.

    Source:Blademaster
    Published:29 Oct 2003
    6.8
    Medium

    CVE-2003-1187

    Last Modified: 12 Dec 2012

    Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the contact_email parameter.

    Published:2 Nov 2003
    6.8
    Medium

    CVE-2003-1182

    Last Modified: 12 Dec 2012

    Cross-site scripting (XSS) vulnerability in MPM Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter.

    Source:David Ferreira
    Published:3 Nov 2003
    5
    Medium

    CVE-2003-1181

    Last Modified: 2 Nov 2012

    Advanced Poll 2.0.2 allows remote attackers to obtain sensitive information via an HTTP request to info.php, which invokes the phpinfo() function.

    Source:subj
    Published:25 Oct 2003
    7.5
    High

    CVE-2003-1179

    Last Modified: 13 Sept 2013

    Multiple PHP remote file inclusion vulnerabilities in Advanced Poll 2.0.2 allow remote attackers to execute arbitrary PHP code via the include_path parameter in (1) booth.php, (2) png.php, (3) poll_ssi.php, or (4) popup.php, the (5) base_path parameter to common.inc.php.

    Source:Solpot
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1177

    Last Modified: 9 Dec 2012

    Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) AUTH command to the POP3 server or (2) AUTHENTICATE command to the IMAP server.

    Source:Kostya KORTCHINSKY
    Published:31 Dec 2003
    6.4
    Medium

    CVE-2003-1176

    Last Modified: 12 Dec 2012

    post_message_form.asp in Web Wiz Forums 6.34 through 7.5, when quote mode is used, allows remote attackers to read or write to private forums by modifying the FID (forum ID) parameter.

    Source:Alexander Antipov
    Published:31 Dec 2003
    6.8
    Medium

    CVE-2003-1175

    Last Modified: 12 Dec 2012

    Cross-site scripting (XSS) vulnerability in index.php in Sympoll 1.5 allows remote attackers to inject arbitrary web script or HTML via the vo parameter.

    Source:Michael Frame
    Published:31 Dec 2003
    2.1
    Low

    CVE-2003-1174

    Last Modified: 3 Nov 2017

    Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name followed by a long server name or (2) icy-url followed by a long URL.

    Source:airsupply
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1173

    Last Modified: 11 Dec 2012

    Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the URL and checking all of the search option checkboxes and leaving the text field blank, which will return all files in the searched directory.

    Source:Richard Maudsley
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1172

    Last Modified: 11 Dec 2012

    Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.

    Source:Thierry De Leeuw
    Published:31 Dec 2003
    4.6
    Medium

    CVE-2003-1169

    Last Modified: 12 Dec 2012

    DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access restrictions by importing NukoInfo values in certain DATEV keys, which disables Nutzungskontrolle.

    Source:t4rku5
    Published:31 Dec 2003
    7.2
    High

    CVE-2003-1167

    Last Modified: 11 Dec 2012

    misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their privileges by modifying the PATH variable to reference a malicious killall program.

    Source:b0f
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1166

    Last Modified: 12 Dec 2012

    Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter.

    Source:Zero X
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1165

    Last Modified: 12 Dec 2012

    Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with a long User-Agent header.

    Source:D4rkGr3y
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1164

    Last Modified: 14 Feb 2017

    Cross-site scripting (XSS) vulnerability in Mldonkey 2.5-4 allows remote attackers to inject arbitrary web script or HTML via the URI, which is injected into the HTML error page.

    Source:Chris Sharp
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1162

    Last Modified: 12 Dec 2012

    index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying the thread_id, forum_id, and sid parameters.

    Source:Virginity Security
    Published:31 Dec 2003
    10
    Critical

    CVE-2003-1160

    Last Modified: 12 Dec 2012

    FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request to aindex.htm that contains double leading slashes (//).

    Source:slaizer
    Published:30 Oct 2003
    5
    Medium

    CVE-2003-1158

    Last Modified: 5 Dec 2012

    Multiple buffer overflows in the FTP service in Plug and Play Web Server 1.0002c allow remote attackers to cause a denial of service (crash) via long (1) dir, (2) ls, (3) delete, (4) mkdir, (5) DELE, (6) RMD, or (7) MKD commands.

    Source:Bahaa Naamneh
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1157

    Last Modified: 12 Dec 2012

    Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML via the NFuse_Message parameter.

    Source:Andy Davis
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1151

    Last Modified: 11 Dec 2012

    Cross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrary web script or HTML via the URL, which is displayed on a "404 Not Found" error page.

    Source:Oliver Karow
    Published:28 Oct 2003
    4.3
    Medium

    CVE-2003-1149

    Last Modified: 11 Dec 2012

    Cross-site scripting (XSS) vulnerability in Symantec Norton Internet Security 2003 6.0.4.34 allows remote attackers to inject arbitrary web script or HTML via a URL to a blocked site, which is displayed on the blocked sites error page.

    Source:KrazySnake
    Published:27 Oct 2003
    7.5
    High

    CVE-2003-1148

    Last Modified: 11 Dec 2012

    Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allow remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter to (1) config.inc.php or (2) new-visitor.inc.php in common/visiteurs/include/.

    Source:Matthieu Peschaud
    Published:25 Oct 2003
    6.8
    Medium

    CVE-2003-1146

    Last Modified: 12 Dec 2012

    Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.

    Published:11 May 2003
    6.8
    Medium

    CVE-2003-1145

    Last Modified: 12 Dec 2012

    Cross-site scripting (XSS) vulnerability in friendmail.php in OpenAutoClassifieds 1.0 allows remote attackers to inject arbitrary web script or HTML via the listing parameter.

    Source:David Sopas Ferreira
    Published:3 Nov 2003
    7.5
    High

    CVE-2003-1143

    Last Modified: 12 Dec 2012

    Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05 allow remote attackers to cause a denial of service (crash or freeze) via a TCP packet with an invalid first parameter.

    Source:Luigi Auriemma
    Published:30 Oct 2003
    10
    Critical

    CVE-2003-1142

    Last Modified: 22 Nov 2017

    Help in NIPrint LPD-LPR Print Server 4.10 and earlier executes Windows Explorer with SYSTEM privileges, which allows local users to gain privileges.

    Source:xCrZx
    Published:3 Nov 2003
    7.5
    High

    CVE-2003-1141

    Last Modified: 7 Mar 2011

    Buffer overflow in NIPrint 4.10 allows remote attackers to execute arbitrary code via a long string to TCP port 515.

    Source:Metasploit
    Published:4 Nov 2003
    10
    Critical

    CVE-2003-1140

    Last Modified: 11 Dec 2012

    Buffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the configuration file.

    Source:dong-h0un U
    Published:27 Oct 2003
    5
    Medium

    CVE-2003-1139

    Last Modified: 11 Dec 2012

    Musicqueue 1.2.0 allows local users to overwrite arbitrary files by triggering a segmentation fault and using a symlink attack on the resulting musicqueue.crash file.

    Source:dong-h0un U
    Published:27 Oct 2003
    5
    Medium

    CVE-2003-1138

    Last Modified: 11 Dec 2012

    The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).

    Source:TfM
    Published:27 Oct 2003
    5
    Medium

    CVE-2003-1137

    Last Modified: 11 Dec 2012

    Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character.

    Source:dong-h0un U
    Published:27 Oct 2003
    4.3
    Medium

    CVE-2003-1136

    Last Modified: 11 Dec 2012

    Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web script or HTML via (1) HTML in a posted message or (2) Javascript in an onmouseover attribute in an e-mail address or URL.

    Source:Joshua P. Miller
    Published:23 Oct 2003