Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2003-10-25 CVE-2003-1148 Remote File Include vulnerability in LES Visiteurs LES Visiteurs 2.0.1
Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allow remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter to (1) config.inc.php or (2) new-visitor.inc.php in common/visiteurs/include/.
network
low complexity
les-visiteurs
7.5
2003-10-20 CVE-2003-0754 Security Bypass vulnerability in newsPHP
nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, which is used for authentication.
network
low complexity
newsphp
7.5
2003-10-20 CVE-2003-0752 SQL-Injection vulnerability in Attilaphp
SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to bypass authentication via a modified cook_id parameter.
network
low complexity
attila-php-net
7.5
2003-10-20 CVE-2003-0751 SQL-Injection vulnerability in Py-Membres 4.0/4.1/4.2
SQL injection vulnerability in pass_done.php for PY-Membres 4.2 and earlier allows remote attackers to execute arbitrary SQL queries via the email parameter.
network
low complexity
py-membres
7.5
2003-10-20 CVE-2003-0750 Security Bypass vulnerability in Py-Membres 4.0/4.1/4.2
secure.php in PY-Membres 4.2 and earlier allows remote attackers to bypass authentication by setting the adminpy parameter.
network
low complexity
py-membres
7.5
2003-10-20 CVE-2003-0743 Unspecified vulnerability in University of Cambridge Exim
Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL character and a newline, which is not properly trimmed before the "(no argument given)" string is appended to the buffer.
network
low complexity
university-of-cambridge
7.5
2003-10-20 CVE-2003-0738 USE of Externally-Controlled Format String vulnerability in PHPwebsite
The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter.
network
low complexity
phpwebsite CWE-134
7.8
2003-10-20 CVE-2003-0735 SQL-Injection vulnerability in Phpwebsite
SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries, as demonstrated using the year parameter.
network
low complexity
phpwebsite
7.5
2003-10-20 CVE-2003-0730 Integer Overflow vulnerability in XFree86
Multiple integer overflows in the font libraries for XFree86 4.3.0 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-based buffer overflow attacks.
network
low complexity
xfree86-project netbsd
7.5
2003-10-20 CVE-2003-0729 Unspecified vulnerability in Tellurian Tftpdnt 1.8/2.0
Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename.
network
low complexity
tellurian
7.5