CVE Database - 2003

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

116
Matching CVEs
15853
Critical
26962
High
69389
High WAF Coverage

CVE-2003-1209

MEDIUM
5.00 CVSS 2.0

The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request without a Content-Type header.

Improper Input Validation
WAF: Medium

CVE-2003-1227

HIGH
7.50 CVSS 2.0

PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix, allows remote attackers to inject arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412. NOTE: this issue might be exploitable only during installation, or if the administrator has not run a security script after installation.

Code Injection
WAF: Medium

CVE-2003-1240

HIGH
7.50 CVSS 2.0

PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.php, or (3) comments.php.

Code Injection
WAF: Medium

CVE-2003-1244

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and possibly gain unauthorized access to forums via the forum_id parameter to index.php.

SQL Injection
WAF: High

CVE-2003-1253

HIGH
7.50 CVSS 2.0

PHP remote file inclusion vulnerability in Bookmark4U 1.8.3 allows remote attackers to execute arbitrary PHP code viaa URL in the prefix parameter to (1) dbase.php, (2) config.php, or (3) common.load.php.

Code Injection
WAF: Medium

CVE-2003-1334

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1335

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.5 allows remote attackers to download files from locations above the snif directory.

Path Traversal
WAF: High

CVE-2003-1340

MEDIUM
6.50 CVSS 2.0

Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 5.6 and 6.5 allow remote authenticated users to execute arbitrary SQL commands via (1) a uid (user) cookie to modules.php; and allow remote attackers to execute arbitrary SQL commands via an aid (admin) cookie to the Web_Links module in a (2) viewlink, (3) MostPopular, or (4) NewLinksDate action, different vectors than CVE-2003-0279.

SQL Injection
WAF: High

CVE-2003-1343

HIGH
7.50 CVSS 2.0

Trend Micro ScanMail for Exchange (SMEX) before 3.81 and before 6.1 might install a back door account in smg_Smxcfg30.exe, which allows remote attackers to gain access to the web management interface via the vcc parameter, possibly "3560121183d3".

Improper Authentication
WAF: Low

CVE-2003-1345

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in s.dll in WebCollection Plus 5.00 allows remote attackers to view arbitrary files in c:\ via a full pathname in the d parameter.

Path Traversal
WAF: High

CVE-2003-1347

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to comment.php, (2) uid parameter to profiles.php, (3) uid to users.php, and (4) homepage field.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1348

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) name, or (3) title field.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1349

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in NITE ftp-server (NiteServer) 1.83 allows remote attackers to list arbitrary directories via a "\.." (backslash dot dot) in the CD (CWD) command.

Path Traversal
WAF: High

CVE-2003-1350

MEDIUM
4.30 CVSS 2.0

List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl field.

Improper Input Validation
WAF: Medium

CVE-2003-1351

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in edittag.cgi in EditTag 1.1 allows remote attackers to read arbitrary files via a "%2F.." (encoded slash dot dot) in the file parameter.

Path Traversal
WAF: High

CVE-2003-1353

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in Outreach Project Tool (OPT) 0.946b allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the news field.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1364

HIGH
8.50 CVSS 2.0

Aprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of service (crash) via an HTTP GET message with empty (1) Connection or (2) Range fields.

Improper Input Validation
WAF: Medium

CVE-2003-1365

MEDIUM
5.00 CVSS 2.0

The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return, which could allow remote attackers to read or write arbitrary files, or execute arbitrary commands, in shell scripts that rely on CGI::Lite to filter such dangerous inputs.

Improper Input Validation
WAF: Medium

CVE-2003-1370

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in Nuked-Klan 1.2b allow remote attackers to inject arbitrary HTML or web script via (1) the Author field in the Guestbook module, (2) the Titre or Pseudo fields in the Forum module, or (3) "La Tribune Libre" in the Shoutbox module.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1371

MEDIUM
4.30 CVSS 2.0

Nuked-Klan 1.3b, and possibly earlier versions, allows remote attackers to obtain sensitive server information via an op parameter set to phpinfo for the (1) Team, (2) News, or (3) Liens modules.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1372

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in links.php script in myPHPNuke 1.8.8, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the (1) ratenum or (2) query parameters.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1373

MEDIUM
6.80 CVSS 2.0

Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. (dot dot) sequences followed by NULL (%00) characters in CGI parameters, as demonstrated using the lang parameter in prefs.php.

Path Traversal
WAF: High

CVE-2003-1380

HIGH
7.50 CVSS 2.0

Directory traversal vulnerability in BisonFTP Server 4 release 2 allows remote attackers to (1) list directories above the root via an 'ls @../' command, or (2) list files above the root via a "mget @../FILE" command.

Path Traversal
WAF: High

CVE-2003-1384

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in index.php in PY-Livredor 1.0 allows remote attackers to insert arbitrary web script or HTML via the (1) titre, (2) Votre pseudo, (3) Votre e-mail, or (4) Votre message fields.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1385

MEDIUM
6.80 CVSS 2.0

ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.

Code Injection
WAF: Medium

CVE-2003-1400

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1402

HIGH
7.50 CVSS 2.0

PHP remote file inclusion vulnerability in hit.php for Kietu 2.0 and 2.3 allows remote attackers to execute arbitrary PHP code via the url_hit parameter, a different vulnerability than CVE-2006-5015.

Improper Input Validation
WAF: Medium

CVE-2003-1403

HIGH
7.50 CVSS 2.0

foo.php3 in DotBr 0.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.

Improper Input Validation
WAF: Medium

CVE-2003-1405

HIGH
7.50 CVSS 2.0

DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3.

Improper Input Validation
WAF: Medium

CVE-2003-1406

HIGH
7.50 CVSS 2.0

PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_header parameter to header.php3 or (2) my_footer parameter to footer.php3.

Code Injection
WAF: Medium

CVE-2003-1410

MEDIUM
6.80 CVSS 2.0

PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary PHP code via the cer_skin parameter.

Code Injection
WAF: Medium

CVE-2003-1411

MEDIUM
6.80 CVSS 2.0

PHP remote file inclusion vulnerability in emailreader_execute_on_each_page.inc.php in Cedric Email Reader 0.4 allows remote attackers to execute arbitrary PHP code via the emailreader_ini parameter.

Code Injection
WAF: Medium

CVE-2003-1412

MEDIUM
6.80 CVSS 2.0

PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code via the plugin parameter to (1) 3fax/1blocklists/index.php; (2) 6departamentadmin/index.php, (3) 5terminals/index.php, (4) 4mailinglists/index.php, (5) 3departaments/index.php, and (6) 2groupd/index.php in 2administration/; or (7) the base parameter to include/help.php.

Code Injection
WAF: Medium

CVE-2003-1413

MEDIUM
4.30 CVSS 2.0

parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.

Path Traversal
WAF: High

CVE-2003-1414

MEDIUM
4.30 CVSS 2.0

Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter.

Path Traversal
WAF: High

CVE-2003-1416

MEDIUM
4.30 CVSS 2.0

BisonFTP Server 4 release 2 allows remote attackers to cause a denial of service (CPU consumption) via a long (1) ls or (2) cwd command.

Improper Input Validation
WAF: Medium

CVE-2003-1419

MEDIUM
4.30 CVSS 2.0

Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function.

Improper Input Validation
WAF: Medium

CVE-2003-1420

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Opera 6.0 through 7.0 with automatic redirection disabled allows remote attackers to inject arbitrary web script or HTML via the HTTP Location header.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1425

HIGH
10.00 CVSS 2.0

guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.

Improper Input Validation
WAF: Medium

CVE-2003-1427

MEDIUM
6.40 CVSS 2.0

Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary files, such as the netgear.cfg configuration file, via a hex-encoded (%2e%2e%2f) ../ (dot dot slash) in the port parameter.

Path Traversal
WAF: High

CVE-2003-1430

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL.

Path Traversal
WAF: High

CVE-2003-1432

HIGH
10.00 CVSS 2.0

Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via (1) a packet with a negative size value, which is treated as a large positive number during memory allocation, or (2) a negative size value in a package file.

Code Injection
WAF: Medium

CVE-2003-1433

MEDIUM
4.30 CVSS 2.0

Epic Games Unreal Engine 226f through 436 does not validate the challenge key, which allows remote attackers to exhaust the player limit by joining the game multiple times.

Improper Authentication
WAF: Low

CVE-2003-1434

MEDIUM
6.80 CVSS 2.0

login_ldap 3.1 and 3.2 allows remote attackers to initiate unauthenticated bind requests if (1) bind_anon_dn is on, which allows a bind with no password provided, (2) bind_anon_cred is on, which allows a bind with no DN, or (3) bind_anon is on, which allows a bind with no DN or password.

Improper Authentication
WAF: Low

CVE-2003-1435

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.

SQL Injection
WAF: High

CVE-2003-1436

MEDIUM
6.80 CVSS 2.0

PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute arbitrary PHP code via the filhead parameter.

Code Injection
WAF: Medium

CVE-2003-1440

MEDIUM
4.30 CVSS 2.0

SpamProbe 0.8a allows remote attackers to cause a denial of service (crash) via HTML e-mail with newline characters within an href tag, which is not properly handled by certain regular expressions.

Improper Input Validation
WAF: Medium

CVE-2003-1441

MEDIUM
4.30 CVSS 2.0

Posadis 0.50.4 through 0.50.8 allows remote attackers to cause a denial of service (crash) via a DNS message without a question section, which triggers null dereference.

Improper Input Validation
WAF: Medium

CVE-2003-1442

HIGH
7.50 CVSS 2.0

The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to gain access from the LAN side.

Improper Authentication
WAF: Low

CVE-2003-1443

MEDIUM
4.40 CVSS 2.0

Kaspersky Antivirus (KAV) 4.0.9.0 does not detect viruses in files with MS-DOS device names in their filenames, which allows local users to bypass virus protection, as demonstrated using aux.vbs and aux.com.

Improper Input Validation
WAF: Medium
Page 1 of 3 (116 CVEs)