Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2004-04-15 CVE-2003-0513 Unspecified vulnerability in Microsoft IE and Internet Explorer
Microsoft Internet Explorer allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Internet Explorer to send the cookie outside the specified URL subsets, e.g.
network
low complexity
microsoft
7.5
2004-04-15 CVE-2003-0257 Unspecified vulnerability in IBM AIX
Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges.
local
low complexity
ibm
7.2
2004-04-15 CVE-2002-1578 Unspecified vulnerability in SAP R 3
The default installation of SAP R/3, when using Oracle and SQL*net V2 3.x, 4.x, and 6.10, allows remote attackers to obtain arbitrary, sensitive SAP data by directly connecting to the Oracle database and executing queries against the database, which is not password-protected.
network
low complexity
sap
7.5
2004-04-15 CVE-2002-1577 Remote Security vulnerability in SAP R 3 2.0Bto4.6D
SAP R/3 2.0B to 4.6D installs several clients with default users and passwords, which allows remote attackers to gain privileges via the (1) SAP*, (2) SAPCPIC, (3) DDIC, (4) EARLYWATCH, or (5) TMSADM accounts.
network
low complexity
sap
7.5
2004-04-15 CVE-2002-1576 Symbolic Link vulnerability in SAP DB 7.3.00
lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users to gain privileges with a malicious lserversrv that is called from a directory that has a symlink to the lserver program.
local
low complexity
sap
7.2
2004-04-14 CVE-2004-1936 Unspecified vulnerability in Zonelabs Zonealarm
ZoneAlarm Pro 4.5.538.001 and possibly other versions allows remote attackers to bypass e-mail protection via attachments whose names contain certain non-English characters.
network
low complexity
zonelabs
7.5
2004-04-13 CVE-2004-1929 SQL Injection vulnerability in PHP-Nuke
SQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass authentication and gain access by injecting base64-encoded SQL code into the user parameter.
network
low complexity
francisco-burzi
7.5
2004-04-12 CVE-2004-1932 SQL-Injection vulnerability in PHP-Nuke
SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.
network
low complexity
francisco-burzi
7.5
2004-04-12 CVE-2004-1928 Improper Input Validation vulnerability in Tiki Tikiwiki Cms/Groupware 1.6.1/1.8.1
The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL.
network
low complexity
tiki CWE-20
7.5
2004-04-12 CVE-2004-1925 SQL Injection vulnerability in Tiki Tikiwiki Cms/Groupware 1.6.1/1.8.1
Multiple SQL injection vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sort_mode parameter in (1) tiki-usermenu.php, (2) tiki-list_file_gallery.php, (3) tiki-directory_ranking.php, (4) tiki-browse_categories.php, (5) tiki-index.php, (6) tiki-user_tasks.php, (7) tiki-directory_ranking.php, (8) tiki-directory_search.php, (9) tiki-file_galleries.php, (10) tiki-list_faqs.php, (11) tiki-list_trackers.php, (12) tiki-list_blogs.php, or via the offset parameter in (13) tiki-usermenu.php, (14) tiki-browse_categories.php, (15) tiki-index.php, (16) tiki-user_tasks.php, (17) tiki-list_faqs.php, (18) tiki-list_trackers.php, or (19) tiki-list_blogs.php.
network
low complexity
tiki CWE-89
7.5