Lucene search

K

Peoplesoft Security Vulnerabilities

cve
cve

CVE-2006-0584

The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack that compares output...

6.3AI Score

0.0004EPSS

2006-02-08 01:02 AM
25
cve
cve

CVE-2004-2435

Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources Management System (HRMS) 7.0, when "web enabled" using HTML Access, allows remote attackers to inject arbitrary web script or HTML via unspecified (1) debugging or (2) utility...

6AI Score

0.011EPSS

2005-08-20 04:00 AM
20
cve
cve

CVE-2003-0626

psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to read arbitrary files via the (1) headername or (2) footername...

6.8AI Score

0.009EPSS

2005-04-14 04:00 AM
19
cve
cve

CVE-2003-0627

psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to cause a denial of service (application crash), possibly via the headername and footername...

6.8AI Score

0.014EPSS

2005-04-14 04:00 AM
20
cve
cve

CVE-2002-1252

The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the SimpleFileHandler...

7.2AI Score

0.004EPSS

2004-09-01 04:00 AM
19
cve
cve

CVE-2003-0104

Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer...

7.2AI Score

0.006EPSS

2004-09-01 04:00 AM
44
cve
cve

CVE-2003-0950

PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (system time) name of the directory used to store the file, and directly requesting that...

8AI Score

0.013EPSS

2003-12-15 05:00 AM
21
cve
cve

CVE-2003-0629

Cross-site scripting (XSS) vulnerability in PeopleSoft IScript environment for PeopleTools 8.43 and earlier allows remote attackers to insert arbitrary web script via a certain HTTP request to...

5.9AI Score

0.001EPSS

2003-12-15 05:00 AM
29
cve
cve

CVE-2003-0628

PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and earlier allows remote attackers to obtain the full pathnames for server-side include (SSI) files via an HTTP request with an invalid...

6.7AI Score

0.007EPSS

2003-12-15 05:00 AM
17