CVE Database - 2003

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

116
Matching CVEs
15853
Critical
26962
High
69389
High WAF Coverage

CVE-2003-1444

MEDIUM
4.40 CVSS 2.0

Kaspersky Antivirus (KAV) 4.0.9.0 allows local users to cause a denial of service (CPU consumption or crash) and prevent malicious code from being detected via a file with a long pathname.

Improper Input Validation
WAF: Medium

CVE-2003-1450

MEDIUM
5.00 CVSS 2.0

BitchX 75p3 and 1.0c16 through 1.0c20cvs allows remote attackers to cause a denial of service (segmentation fault) via a malformed RPL_NAMREPLY numeric 353 message.

Improper Input Validation
WAF: Medium

CVE-2003-1453

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the MytextSanitizer function in XOOPS 1.3.5 through 1.3.9 and XOOPS 2.0 through 2.0.1 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in an IMG tag.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1456

MEDIUM
5.00 CVSS 2.0

Album.pl 6.1 allows remote attackers to execute arbitrary commands, when an alternative configuration file is used, via unknown attack vectors.

Improper Input Validation
WAF: Medium

CVE-2003-1458

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in Profile.php in ttCMS 2.2 and ttForum allows remote attackers to execute arbitrary SQL commands via the member name.

SQL Injection
WAF: High

CVE-2003-1459

MEDIUM
6.80 CVSS 2.0

Multiple PHP remote file inclusion vulnerabilities in ttCMS 2.2 and ttForum allow remote attackers to execute arbitrary PHP code via the (1) template parameter in News.php or (2) installdir parameter in install.php.

Code Injection
WAF: Medium

CVE-2003-1463

LOW
3.50 CVSS 2.0

Absolute path traversal vulnerability in Alt-N Technologies WebAdmin 2.0.0 through 2.0.2 allows remote attackers with administrator privileges to (1) determine the installation path by reading the contents of the Name parameter in a link, and (2) read arbitrary files via an absolute path in the Name parameter.

Improper Input Validation
WAF: Medium

CVE-2003-1465

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in download.php in Phorum 3.4 through 3.4.2 allows remote attackers to read arbitrary files.

Path Traversal
WAF: High

CVE-2003-1467

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in (1) login.php, (2) register.php, (3) post.php, and (4) common.php in Phorum before 3.4.3 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1471

MEDIUM
6.30 CVSS 2.0

MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service (crash) via a (1) DELE or (2) UIDL with a negative number.

Improper Input Validation
WAF: Medium

CVE-2003-1475

MEDIUM
6.80 CVSS 2.0

Netbus 1.5 through 1.7 allows more than one client to be connected at the same time, but only prompts the first connection for authentication, which allows remote attackers to gain access.

Improper Authentication
WAF: Low

CVE-2003-1479

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in webcamXP 1.02.432 and 1.02.535 allows remote attackers to inject arbitrary web script or HTML via the message field.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1485

MEDIUM
5.00 CVSS 2.0

Clearswift MAILsweeper 4.0 through 4.3.7 allows remote attackers to bypass filtering via a file attachment that contains "multiple extensions combined with large blocks of white space."

Improper Input Validation
WAF: Medium

CVE-2003-1487

HIGH
10.00 CVSS 2.0

Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify the Phorum configuration files via the (1) UserAdmin program, (2) Edit user profile, or (3) stats program.

Improper Input Validation
WAF: Medium

CVE-2003-1488

MEDIUM
6.40 CVSS 2.0

The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.php without the connect parameter and with the loggedin parameter set to any value, such as 1.

Improper Input Validation
WAF: Medium

CVE-2003-1489

MEDIUM
5.00 CVSS 2.0

upload.php in Truegalerie 1.0 allows remote attackers to read arbitrary files by specifying the target filename in the file cookie in form.php, then downloading the file from the image gallery.

Improper Authentication
WAF: Low

CVE-2003-1490

HIGH
7.80 CVSS 2.0

SonicWall Pro running firmware 6.4.0.1 allows remote attackers to cause a denial of service (device reset) via a long HTTP POST to the internal interface, possibly due to a buffer overflow.

Improper Input Validation
WAF: Medium

CVE-2003-1491

HIGH
7.50 CVSS 2.0

Kerio Personal Firewall (KPF) 2.1.4 has a default rule to accept incoming packets from DNS (UDP port 53), which allows remote attackers to bypass the firewall filters via packets with a source port of 53.

Code Injection
WAF: Medium

CVE-2003-1498

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in search.php for WRENSOFT Zoom Search Engine 2.0 Build 1018 and earlier allows remote attackers to inject arbitrary web script or HTML via the zoom_query parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1499

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in index.php in Bytehoard 0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the infolder parameter.

Path Traversal
WAF: High

CVE-2003-1500

MEDIUM
6.80 CVSS 2.0

PHP remote file inclusion vulnerability in _functions.php in cpCommerce 0.5f allows remote attackers to execute arbitrary code via the prefix parameter.

Code Injection
WAF: Medium

CVE-2003-1501

MEDIUM
6.40 CVSS 2.0

Directory traversal vulnerability in the file upload CGI of Gast Arbeiter 1.3 allows remote attackers to write arbitrary files via a .. (dot dot) in the req_file parameter.

Path Traversal
WAF: High

CVE-2003-1504

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in variables.php in Goldlink 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) vadmin_login or (2) vadmin_pass cookie in a request to goldlink.php.

SQL Injection
WAF: High

CVE-2003-1506

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in dansguardian.pl in Adelix CensorNet 3.0 through 3.2 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the DENIEDURL parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1511

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Bajie Java HTTP Server 0.95 through 0.95zxv4 allows remote attackers to inject arbitrary web script or HTML via (1) the query string to test.txt, (2) the guestName parameter to the custMsg servlet, or (3) the cookiename parameter to the CookieExample servlet.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1513

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in example scripts in Caucho Technology Resin 2.0 through 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) env.jsp, (2) form.jsp, (3) session.jsp, (4) the move parameter to tictactoe.jsp, or the (5) name or (6) comment fields to guestbook.jsp.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1519

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Vivisimo clustering engine allows remote attackers to inject arbitrary web script or HTML via the query parameter to the search program.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1520

MEDIUM
6.80 CVSS 2.0

SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email parameter.

SQL Injection
WAF: High

CVE-2003-1522

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in PSCS VPOP3 Web Mail server 2.0e and 2.0f allows remote attackers to inject arbitrary web script or HTML via the redirect parameter to the admin/index.html page.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1523

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in the IMAP daemon in dbmail 1.1 allows remote attackers to execute arbitrary SQL commands via the (1) login username, (2) mailbox name, and possibly other attack vectors.

SQL Injection
WAF: High

CVE-2003-1529

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in Seagull Software Systems J Walk application server 3.2C9, and other versions before 3.3c4, allows remote attackers to read arbitrary files via a ".%252e" (encoded dot dot) in the URL.

Path Traversal
WAF: High

CVE-2003-1530

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the mark[] parameter.

SQL Injection
WAF: High

CVE-2003-1531

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in testcgi.exe in Lilikoi Software Ceilidh 2.70 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1532

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in compte.php in PhpMyShop 1.00 allows remote attackers to execute arbitrary SQL commands via the (1) identifiant and (2) password parameters.

SQL Injection
WAF: High

CVE-2003-1533

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in accesscontrol.php in PhpPass 2 allows remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameters.

SQL Injection
WAF: High

CVE-2003-1534

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in jgb.php3 in Justice Guestbook 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) homepage, (3) aim, (4) yim, (5) location, and (6) comment variables.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1536

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in Codeworx Technologies DCP-Portal 5.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the q parameter to search.php and (2) the year parameter to calendar.php.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1537

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php.

Path Traversal
WAF: High

CVE-2003-1538

MEDIUM
6.40 CVSS 2.0

susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands via CGI queries.

Improper Input Validation
WAF: Medium

CVE-2003-1539

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in ONEdotOH Simple File Manager (SFM) before 0.21 allows remote attackers to inject arbitrary web script or HTML via (1) file names and (2) directory names.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1542

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in plugins/file.php in phpWebFileManager before 0.4.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the fm_path parameter.

Path Traversal
WAF: High

CVE-2003-1543

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Bajie Http Web Server 0.95zxe, 0.95zxc, and possibly others, allows remote attackers to inject arbitrary web script or HTML via the query string, which is reflected in an error message.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1545

MEDIUM
5.00 CVSS 2.0

Absolute path traversal vulnerability in nukestyles.com viewpage.php addon for PHP-Nuke allows remote attackers to read arbitrary files via a full pathname in the file parameter. NOTE: This was originally reported as an issue in PHP-Nuke 6.5, but this is an independent addon.

Path Traversal
WAF: High

CVE-2003-1546

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in gbook.php in Filebased guestbook 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the comment section.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1547

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in block-Forums.php in the Splatt Forum module for PHP-Nuke 6.x allows remote attackers to inject arbitrary web script or HTML via the subject parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1549

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in header.php in MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the ma_kw parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1554

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in scozbook/add.php in ScozNet ScozBook 1.1 BETA allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) useremail, (3) aim, (4) msn, (5) sitename and (6) siteaddy variables.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-1556

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in cc_guestbook.pl in CGI City CC GuestBook allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) homepage_title (webpage title) parameters.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-0795

MEDIUM
5.00 CVSS 2.0

The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial of service (crash) via a malformed telnet command to the telnet CLI port, which may trigger a null dereference.

Improper Input Validation
WAF: Medium

CVE-2003-0624

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter.

Cross-Site Scripting (XSS)
WAF: High
Page 2 of 3 (116 CVEs)