CVE Vulnerabilities

CVE-2003-0628

Published: Dec 15, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and earlier allows remote attackers to obtain the full pathnames for server-side include (SSI) files via an HTTP request with an invalid value.

Affected Software

NameVendorStart VersionEnd Version
PeopletoolsPeoplesoft8.4 (including)8.4 (including)
PeopletoolsPeoplesoft8.10 (including)8.10 (including)
PeopletoolsPeoplesoft8.11 (including)8.11 (including)
PeopletoolsPeoplesoft8.12 (including)8.12 (including)
PeopletoolsPeoplesoft8.13 (including)8.13 (including)
PeopletoolsPeoplesoft8.14 (including)8.14 (including)
PeopletoolsPeoplesoft8.15 (including)8.15 (including)
PeopletoolsPeoplesoft8.16 (including)8.16 (including)
PeopletoolsPeoplesoft8.17 (including)8.17 (including)
PeopletoolsPeoplesoft8.18 (including)8.18 (including)
PeopletoolsPeoplesoft8.19 (including)8.19 (including)
PeopletoolsPeoplesoft8.20 (including)8.20 (including)
PeopletoolsPeoplesoft8.40 (including)8.40 (including)
PeopletoolsPeoplesoft8.41 (including)8.41 (including)
PeopletoolsPeoplesoft8.42 (including)8.42 (including)
PeopletoolsPeoplesoft8.43 (including)8.43 (including)

References