2003 CVE Vulnerabilities

1,555 CVEs published in 2003.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2003-1245——index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is se...
CVE-2003-1244——SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user...
CVE-2003-1243——Cross-site scripting vulnerability (XSS) in Sage 1.0 b3 allows remote attackers to insert arbitrary HTML or web script v...
CVE-2003-1242——Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, whic...
CVE-2003-1241——Cross-site scripting vulnerability (XSS) in (1) admin_index.php, (2) admin_pass.php, (3) admin_modif.php, and (4) admin_...
CVE-2003-1240——PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL...
CVE-2003-1239——Directory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via ...
CVE-2003-1452——Untrusted search path vulnerability in Qualcomm qpopper 4.0 through 4.05 allows local users to execute arbitrary code by...
CVE-2003-1237——Cross-site scripting vulnerability (XSS) in WWWBoard 2.0A2.1 and earlier allows remote attackers to inject arbitrary HTM...
CVE-2003-1283——KaZaA Media Desktop (KMD) 2.0 launches advertisements in the Internet Explorer (IE) local security zone, which could all...
CVE-2003-1235——BRW WebWeaver 1.03 allows remote attackers to obtain sensitive server environment information via a URL request for test...
CVE-2003-1284——Sambar Server before 6.0 beta 6 allows remote attackers to obtain sensitive information via direct requests to the defau...
CVE-2003-1232——Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, ...
CVE-2003-1231——Cross-site scripting (XSS) vulnerability in index.php in ECW-Shop 5.5 allows remote attackers to inject arbitrary web sc...
CVE-2003-1230——The implementation of SYN cookies (syncookies) in FreeBSD 4.5 through 5.0-RELEASE-p3 uses only 32-bit internal keys when...
CVE-2003-1453——Cross-site scripting (XSS) vulnerability in the MytextSanitizer function in XOOPS 1.3.5 through 1.3.9 and XOOPS 2.0 thro...
CVE-2003-1228——Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions...
CVE-2003-1227——PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configurat...
CVE-2003-1226——BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certain secrets concerning password encryption insecurely in conf...
CVE-2003-1285——Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server before 6.0 beta 6 allow remote attackers to inject ...
CVE-2003-1223——The Node Manager for BEA WebLogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of s...
CVE-2003-1222——BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes t...
CVE-2003-1221——BEA WebLogic Express and Server 7.0 through 8.1 SP 1, under certain circumstances when a request to use T3 over SSL (t3s...
CVE-2003-1286——HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attack...
CVE-2003-1454——Invision Power Services Invision Board 1.0 through 1.1.1, when a forum is password protected, stores the administrator p...

Check if your code is affected by 2003 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now