Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2003-12-31 CVE-2003-1313 Remote File Include vulnerability in Eternalmart Mailing List Manager 1.32
Multiple PHP remote file inclusion vulnerabilities in EternalMart Mailing List Manager (EMLM) 1.32 allow remote attackers to execute arbitrary PHP code via a URL in (1) the emml_admin_path parameter to admin/auth.php or (2) the emml_path parameter to emml_email_func.php.
network
low complexity
eternalmart
7.5
2003-12-31 CVE-2003-1286 Open Proxy Authentication Bypass vulnerability in Sambar
HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attackers to send proxy HTTP requests to the Sambar Server's administrative interface and external web servers, by making a "Connection: keep-alive" request before the proxy requests.
network
low complexity
sambar
7.5
2003-12-31 CVE-2003-1283 Local Zone vulnerability in Kazaa Media Desktop 2.0
KaZaA Media Desktop (KMD) 2.0 launches advertisements in the Internet Explorer (IE) local security zone, which could allow remote attackers to view local files and possibly execute arbitrary code.
network
low complexity
kazaa
7.5
2003-12-31 CVE-2003-1268 SQL Injection vulnerability in Urlogy A.Shop.Kart 2.0.3
Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive information via the zip, state, country, phone, and fax parameters.
network
low complexity
urlogy
7.5
2003-12-31 CVE-2003-1260 Buffer Overflow vulnerability in Globalscape Cuteftp 5.0
Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command.
network
high complexity
globalscape
7.6
2003-12-31 CVE-2003-1259 Buffer Overflow vulnerability in GlobalScape CuteFTP Long FTP Banner
Buffer overflow in CuteFTP 4.2 and 5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.
network
low complexity
globalscape
7.5
2003-12-31 CVE-2003-1258 Remote Security vulnerability in Versatilebulletinboard 0.9.5/0.9.6
activate.php in versatileBulletinBoard (vBB) 0.9.5 and 0.9.6 allows remote attackers to gain unauthorized administrative access via a URL request with the uid parameter set to the webmaster uid.
network
low complexity
versatilebulletinboard
7.5
2003-12-31 CVE-2003-1253 Code Injection vulnerability in Sangwan KIM Bookmark4U 1.8.3
PHP remote file inclusion vulnerability in Bookmark4U 1.8.3 allows remote attackers to execute arbitrary PHP code viaa URL in the prefix parameter to (1) dbase.php, (2) config.php, or (3) common.load.php.
network
low complexity
sangwan-kim CWE-94
7.5
2003-12-31 CVE-2003-1252 Remote Command Execution vulnerability in Kelli Shaver S8Forum 3.0
register.php in S8Forum 3.0 allows remote attackers to execute arbitrary PHP commands by creating a user whose name ends in a .php extension and entering the desired commands into the E-mail field, which creates a web-accessible .php file that can be called by the attacker, as demonstrated using a "system($cmd)" E-mail address with a "any_name.php" username.
network
low complexity
kelli-shaver
7.5
2003-12-31 CVE-2003-1251 Remote File Include vulnerability in NX N X web Content Management System 2002 Prerelease1
The (1) menu.inc.php, (2) datasets.php and (3) mass_operations.inc.php (mistakenly referred to as mass_opeations.inc.php) scripts in N/X 2002 allow remote attackers to execute arbitrary PHP code via a c_path that references a URL on a remote web server that contains the code.
network
low complexity
nx
7.5