CVE-2003-1282
Last modified
CVE-2003-1282 is a vulnerability of currently unknown severity. IBM Net.Data allows remote attackers to obtain sensitive information such as path names, server names and possibly user names and passwords by causing the (1) $(DTW_CURRENT_FILENAME), (2) $(DATABASE), (3) $(LOGIN), (4) $(PASSWORD), and possibly other predefined variables that can be echoed back to the user via a web form.. EPSS estimates a 1.37% chance of exploitation in the next 30 days.
Description
IBM Net.Data allows remote attackers to obtain sensitive information such as path names, server names and possibly user names and passwords by causing the (1) $(DTW_CURRENT_FILENAME), (2) $(DATABASE), (3) $(LOGIN), (4) $(PASSWORD), and possibly other predefined variables that can be echoed back to the user via a web form.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
- http://www.securiteam.com/securitynews/5CP061F8VS.htmlVendor Advisory
- http://www.securiteam.com/securitynews/5CP061F8VS.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-1282?
How severe is CVE-2003-1282?
How do I fix CVE-2003-1282?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2003
- CVE-2003-1276Netfone.exe of NetTelephone 3.5.6 uses weak encryption for u…
- CVE-2003-1277Cross-site scripting (XSS) vulnerabilities in Yet Another Bu…
- CVE-2003-1278Cross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 …
- CVE-2003-1279S-PLUS 6.0 allows local users to overwrite arbitrary files a…
- CVE-2003-1280Directory traversal vulnerability in cgihtml 1.69 allows rem…
- CVE-2003-1281cgihtml 1.69 allows local users to overwrite arbitrary files…
- CVE-2003-1283KaZaA Media Desktop (KMD) 2.0 launches advertisements in the…
- CVE-2003-1284Sambar Server before 6.0 beta 6 allows remote attackers to o…
- CVE-2003-1285Multiple cross-site scripting (XSS) vulnerabilities in Samba…
- CVE-2003-1286HTTP Proxy in Sambar Server before 6.0 beta 6, when security…
- CVE-2003-1287Sambar Server before 6.0 beta 3 allows attackers with physic…
- CVE-2003-1288Multiple race conditions in Linux-VServer 1.22 with Linux ke…
Are you affected by CVE-2003-1282?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
