|
278581
|
- |
|
justice_media
|
guestbook
|
Cross-site scripting (XSS) vulnerability in jgb.php3 in Justice Guestbook 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) homepage, (3) aim, (4) yim, (5) loca…
|
CWE-79
Cross-site Scripting
|
CVE-2003-1534
|
2018-10-20 00:29 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278582
|
- |
|
justice_media
|
guestbook
|
Justice Guestbook 1.3 allows remote attackers to obtain the full installation path via a direct request to cfooter.php3, which leaks the path in an error message.
|
CWE-200
Information Exposure
|
CVE-2003-1535
|
2018-10-20 00:29 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278583
|
- |
|
wfchat
|
wfchat
|
WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain authentication information via a direct request to (1) !pwds…
|
CWE-200
Information Exposure
|
CVE-2003-1540
|
2018-10-20 00:29 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278584
|
- |
|
planetmoon
|
guestbook
|
PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin script password, and other passwords, vi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2003-1541
|
2018-10-20 00:29 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278585
|
- |
|
nukestyles phpnuke
|
viewpage nukestyles_viewpage_module
|
Absolute path traversal vulnerability in nukestyles.com viewpage.php addon for PHP-Nuke allows remote attackers to read arbitrary files via a full pathname in the file parameter. NOTE: This was orig…
|
CWE-22
Path Traversal
|
CVE-2003-1545
|
2018-10-20 00:29 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278586
|
- |
|
francisco_burzi
|
php-nuke
|
Cross-site scripting (XSS) vulnerability in block-Forums.php in the Splatt Forum module for PHP-Nuke 6.x allows remote attackers to inject arbitrary web script or HTML via the subject parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2003-1547
|
2018-10-20 00:29 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278587
|
- |
|
myabracadaweb
|
myabracadaweb
|
MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other parameter, which reveals the installation path in an error message.
|
CWE-200
Information Exposure
|
CVE-2003-1548
|
2018-10-20 00:29 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278588
|
- |
|
myabracadaweb
|
myabracadaweb
|
Cross-site scripting (XSS) vulnerability in header.php in MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the ma_kw parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2003-1549
|
2018-10-20 00:29 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278589
|
- |
|
graeme
|
uploader
|
Unrestricted file upload vulnerability in uploader.php in Uploader 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a dire…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2003-1552
|
2018-10-20 00:29 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278590
|
- |
|
sips
|
sips
|
Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and oth…
|
CWE-200
Information Exposure
|
CVE-2003-1553
|
2018-10-20 00:29 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|