Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
peoplesoft peopletools 8.42 vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2003-0627
psdoccgi.exe in PeopleSoft PeopleTools 8.4 up to and including 8.43 allows remote malicious users to cause a denial of service (application crash), possibly via the headername and footername arguments.
Peoplesoft Peopletools 8.43
Peoplesoft Peopletools 8.40
Peoplesoft Peopletools 8.41
Peoplesoft Peopletools 8.42
2.1
CVSSv2
CVE-2006-0584
The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack that compares output strings.
Peoplesoft Peopletools 8.40
Peoplesoft Peopletools 8.41
Peoplesoft Peopletools 8.42
Peoplesoft Peopletools 8.43
Peoplesoft Peopletools 8.4
Peoplesoft Peopletools 8.45.5
Peoplesoft Peopletools 8.46.3
4.3
CVSSv2
CVE-2003-0629
Cross-site scripting (XSS) vulnerability in PeopleSoft IScript environment for PeopleTools 8.43 and previous versions allows remote malicious users to insert arbitrary web script via a certain HTTP request to IScript.
Peoplesoft Peopletools 8.10
Peoplesoft Peopletools 8.11
Peoplesoft Peopletools 8.18
Peoplesoft Peopletools 8.19
Peoplesoft Peopletools 8.16
Peoplesoft Peopletools 8.17
Peoplesoft Peopletools 8.42
Peoplesoft Peopletools 8.43
Peoplesoft Peopletools 8.12
Peoplesoft Peopletools 8.13
Peoplesoft Peopletools 8.20
Peoplesoft Peopletools 8.4
Peoplesoft Peopletools 8.14
Peoplesoft Peopletools 8.15
Peoplesoft Peopletools 8.40
Peoplesoft Peopletools 8.41
5
CVSSv2
CVE-2003-0626
psdoccgi.exe in PeopleSoft PeopleTools 8.4 up to and including 8.43 allows remote malicious users to read arbitrary files via the (1) headername or (2) footername arguments.
Peoplesoft Peopletools 8.15
Peoplesoft Peopletools 8.16
Peoplesoft Peopletools 8.42
Peoplesoft Peopletools 8.43
Peoplesoft Peopletools 8.13
Peoplesoft Peopletools 8.14
Peoplesoft Peopletools 8.40
Peoplesoft Peopletools 8.41
Peoplesoft Peopletools 8.10
Peoplesoft Peopletools 8.17
Peoplesoft Peopletools 8.18
Peoplesoft Peopletools 8.11
Peoplesoft Peopletools 8.12
Peoplesoft Peopletools 8.19
Peoplesoft Peopletools 8.20
Peoplesoft Peopletools 8.4
5
CVSSv2
CVE-2003-0628
PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and previous versions allows remote malicious users to obtain the full pathnames for server-side include (SSI) files via an HTTP request with an invalid value.
Peoplesoft Peopletools 8.10
Peoplesoft Peopletools 8.11
Peoplesoft Peopletools 8.18
Peoplesoft Peopletools 8.19
Peoplesoft Peopletools 8.16
Peoplesoft Peopletools 8.17
Peoplesoft Peopletools 8.43
Peoplesoft Peopletools 8.12
Peoplesoft Peopletools 8.13
Peoplesoft Peopletools 8.20
Peoplesoft Peopletools 8.4
Peoplesoft Peopletools 8.14
Peoplesoft Peopletools 8.15
Peoplesoft Peopletools 8.40
Peoplesoft Peopletools 8.41
Peoplesoft Peopletools 8.42
7.5
CVSSv2
CVE-2003-0950
PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote malicious users to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (system time) name of the directory used to store the file, and directly requesting that file.
Peoplesoft Peopletools 8.10
Peoplesoft Peopletools 8.11
Peoplesoft Peopletools 8.19
Peoplesoft Peopletools 8.20
Peoplesoft Peopletools 8.17
Peoplesoft Peopletools 8.18
Peoplesoft Peopletools 8.43
Peoplesoft Peopletools 8.12
Peoplesoft Peopletools 8.13
Peoplesoft Peopletools 8.4
Peoplesoft Peopletools 8.40
Peoplesoft Peopletools 8.14
Peoplesoft Peopletools 8.15
Peoplesoft Peopletools 8.16
Peoplesoft Peopletools 8.41
Peoplesoft Peopletools 8.42
5
CVSSv2
CVE-2003-0841
The grid option in PeopleSoft 8.42 stores temporary .xls files in guessable directories under the web document root, which allows remote malicious users to steal search results by directly accessing the files via a URL request.
Oracle Peopletools 8.42
10
CVSSv2
CVE-2005-3461
Unspecified vulnerability in PeopleTools in Oracle PeopleSoft Enterprise 8.42 up to 8.45.17 has unknown impact and attack vectors, as identified by Oracle Vuln# PSE01.
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3380
CVE-2024-1694
local file inclusion
CVE-2024-5645
CVE-2024-24919
XSS
CVE-2024-36774
CVE-2024-21306
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started