Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2003-12-31 CVE-2003-1400 Cross-Site Scripting vulnerability in Francisco Burzi PHP-Nuke
Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar parameter.
4.3
2003-12-31 CVE-2003-1397 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Opera Browser 6.05/7.0/7.01
The PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP request containing a long string that gets passed to the ShowDocument method.
network
opera CWE-119
4.3
2003-12-31 CVE-2003-1396 Out-of-bounds Write vulnerability in Opera Browser
Heap-based buffer overflow in Opera 6.05 through 7.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a filename with a long extension.
network
opera CWE-787
6.8
2003-12-31 CVE-2003-1394 Credentials Management vulnerability in Coffeecup Software Coffeecup Password Wizard
CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file.
network
low complexity
coffeecup-software CWE-255
5.0
2003-12-31 CVE-2003-1392 Cryptographic Issues vulnerability in multiple products
CryptoBuddy 1.0 and 1.2 does not use the user-supplied passphrase to encrypt data, which could allow local users to use their own passphrase to decrypt the data.
6.6
2003-12-31 CVE-2003-1386 Permissions, Privileges, and Access Controls vulnerability in Axis 2400 Video Server and 2401 Video Server
AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displays the server's /var/log/messages file.
network
low complexity
axis CWE-264
6.4
2003-12-31 CVE-2003-1385 Code Injection vulnerability in Invision Power Services Invision Power Board 1.1.1
ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.
6.8
2003-12-31 CVE-2003-1384 Cross-Site Scripting vulnerability in PY Software Py-Livredor 1.0
Cross-site scripting (XSS) vulnerability in index.php in PY-Livredor 1.0 allows remote attackers to insert arbitrary web script or HTML via the (1) titre, (2) Votre pseudo, (3) Votre e-mail, or (4) Votre message fields.
4.3
2003-12-31 CVE-2003-1381 USE of Externally-Controlled Format String vulnerability in Amxmod.Net AMX MOD 0.9.2
Format string vulnerability in AMX 0.9.2 and earlier, a plugin for Valve Software's Half-Life Server, allows remote attackers to execute arbitrary commands via format string specifiers in the amx_say command.
6.8
2003-12-31 CVE-2003-1379 Information Exposure vulnerability in Point Clark Networks Clarkconnect 1.2
clarkconnectd in ClarkConnect Linux 1.2 allows remote attackers to obtain sensitive information about the server via the characters (1) A, which reveals the date and time, (2) F, (3) M, which reveals 'ifconfig' information, (4) P, which lists the processes, (5) Y, which reveals the snort log files, or (6) b, which reveals /var/log/messages.
network
low complexity
point-clark-networks CWE-200
5.0