LiveActive security incident?Get immediate response
CVE archive

October 2003

Browse CVE records published in October 2003, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 269 matching CVEs · Page 4 of 6.

Unknown · CVSS Not scored

CVE-2003-1340: Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 5.6 and 6.5 allow remote authenticated u...

Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 5.6 and 6.5 allow remote authenticated users to execute arbitrary SQL commands via (1) a uid (user) cookie to modules.php; and allow remote attackers to execute arbitrary SQL commands via an aid (admin) cookie to the Web_Links module in a (2) viewlink, (3) MostPopular, or (4) NewLinksDate action, different vectors than CVE-2003-0279.

Published Oct 1, 2007 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2003-1379: clarkconnectd in ClarkConnect Linux 1.2 allows remote attackers to obtain sensitive information about the s...

clarkconnectd in ClarkConnect Linux 1.2 allows remote attackers to obtain sensitive information about the server via the characters (1) A, which reveals the date and time, (2) F, (3) M, which reveals 'ifconfig' information, (4) P, which lists the processes, (5) Y, which reveals the snort log files, or (6) b, which reveals /var/log/messages.

Published Oct 19, 2007 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2003-1365: The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characte...

The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return, which could allow remote attackers to read or write arbitrary files, or execute arbitrary commands, in shell scripts that rely on CGI::Lite to filter such dangerous inputs.

Published Oct 17, 2007 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2003-1307: The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send s...

The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP.

Published Oct 23, 2006 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2003-1233: Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as ro...

Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using the NtCreateSymbolicLinkObject function to create a symbolic link to (1) \Device\PhysicalMemory or (2) to a drive letter using the subst command.

Published Oct 28, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2003-0896: The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK...

The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox restrictions and execute arbitrary code via a loaded class name that contains "/" (slash) instead of "." (dot) characters, which bypasses a call to the Security Manager's checkPackageAccess method.

Published Oct 25, 2003 · Updated Aug 8, 2024