Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2003-12-31 CVE-2003-1527 BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.
network
ibm iss
4.3
2003-12-31 CVE-2003-1526 Information Exposure vulnerability in Francisco Burzi PHP-Nuke 7.0
PHP-Nuke 7.0 allows remote attackers to obtain the installation path via certain characters such as (1) ", (2) ', or (3) > in the search field, which reveals the path in an error message.
network
low complexity
francisco-burzi CWE-200
5.0
2003-12-31 CVE-2003-1524 Permissions, Privileges, and Access Controls vulnerability in Pgpi Pgpdisk 6.0.2I
PGPi PGPDisk 6.0.2i does not unmount a PGP partition when the switch user function in Windows XP is used, which could allow local users to access data on another user's PGP partition.
local
pgpi CWE-264
6.3
2003-12-31 CVE-2003-1522 Cross-Site Scripting vulnerability in Pscs Vpop3 web Mail Server 2.0E/2.0F
Cross-site scripting (XSS) vulnerability in PSCS VPOP3 Web Mail server 2.0e and 2.0f allows remote attackers to inject arbitrary web script or HTML via the redirect parameter to the admin/index.html page.
network
pscs CWE-79
4.3
2003-12-31 CVE-2003-1521 Unspecified vulnerability in SUN Java Plug-In
Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.
network
low complexity
sun
6.4
2003-12-31 CVE-2003-1520 SQL Injection vulnerability in Fuzzymonkey Myclassifieds 2.11
SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email parameter.
6.8
2003-12-31 CVE-2003-1519 Cross-Site Scripting vulnerability in Vivisimo Clustering Engine 0
Cross-site scripting (XSS) vulnerability in Vivisimo clustering engine allows remote attackers to inject arbitrary web script or HTML via the query parameter to the search program.
network
vivisimo CWE-79
4.3
2003-12-31 CVE-2003-1517 Information Exposure vulnerability in Dansie Shopping Cart
cart.pl in Dansie shopping cart allows remote attackers to obtain the installation path via an invalid db parameter, which leaks the path in an error message.
network
low complexity
dansie CWE-200
5.0
2003-12-31 CVE-2003-1516 Cross-Site Applet Sandbox Security Model Violation vulnerability in SUN Java Plug-In 1.4.201
The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.
network
sun
6.8
2003-12-31 CVE-2003-1513 Cross-Site Scripting vulnerability in Caucho Technology Resin
Multiple cross-site scripting (XSS) vulnerabilities in example scripts in Caucho Technology Resin 2.0 through 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) env.jsp, (2) form.jsp, (3) session.jsp, (4) the move parameter to tictactoe.jsp, or the (5) name or (6) comment fields to guestbook.jsp.
4.3