Unrated severityNVD Advisory· Published Dec 15, 2003· Updated Apr 16, 2026
CVE-2003-0950
CVE-2003-0950
Description
PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (system time) name of the directory used to store the file, and directly requesting that file.
Affected products
16cpe:2.3:a:peoplesoft:peopletools:8.10:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:peoplesoft:peopletools:8.10:*:*:*:*:*:*:*
- cpe:2.3:a:peoplesoft:peopletools:8.11:*:*:*:*:*:*:*
- cpe:2.3:a:peoplesoft:peopletools:8.12:*:*:*:*:*:*:*
- cpe:2.3:a:peoplesoft:peopletools:8.13:*:*:*:*:*:*:*
- cpe:2.3:a:peoplesoft:peopletools:8.14:*:*:*:*:*:*:*
- cpe:2.3:a:peoplesoft:peopletools:8.15:*:*:*:*:*:*:*
- cpe:2.3:a:peoplesoft:peopletools:8.16:*:*:*:*:*:*:*
- cpe:2.3:a:peoplesoft:peopletools:8.17:*:*:*:*:*:*:*
- cpe:2.3:a:peoplesoft:peopletools:8.18:*:*:*:*:*:*:*
- cpe:2.3:a:peoplesoft:peopletools:8.19:*:*:*:*:*:*:*
- cpe:2.3:a:peoplesoft:peopletools:8.20:*:*:*:*:*:*:*
- cpe:2.3:a:peoplesoft:peopletools:8.4:*:*:*:*:*:*:*
- cpe:2.3:a:peoplesoft:peopletools:8.40:*:*:*:*:*:*:*
- cpe:2.3:a:peoplesoft:peopletools:8.41:*:*:*:*:*:*:*
- cpe:2.3:a:peoplesoft:peopletools:8.42:*:*:*:*:*:*:*
- cpe:2.3:a:peoplesoft:peopletools:8.43:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.