CVE-2003-1414
- EPSS 2.66%
- Veröffentlicht 31.12.2003 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter.
CVE-2003-0050
- EPSS 87.85%
- Veröffentlicht 07.03.2003 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.
- EPSS 0.7%
- Veröffentlicht 07.03.2003 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.
- EPSS 1.09%
- Veröffentlicht 07.03.2003 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.
CVE-2003-0053
- EPSS 0.5%
- Veröffentlicht 07.03.2003 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into...
CVE-2003-0054
- EPSS 0.79%
- Veröffentlicht 07.03.2003 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a lo...