VendorsPeoplesoftpeopletools8.40
Vulnerabilities

Peoplesoft Peopletools 8.40

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2003-0950
PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (system time) name of the directory used to store the file, and directly requesting that file.
Published 2003-11-18 · Modified
7.5EPSS 0.021
CVE-2003-0104
Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet.
Published 2004-09-01 · Modified
5.0EPSS 0.018
CVE-2003-0627
psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to cause a denial of service (application crash), possibly via the headername and footername arguments.
Published 2005-04-14 · Modified
5.0EPSS 0.016
CVE-2003-0626
psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to read arbitrary files via the (1) headername or (2) footername arguments.
Published 2005-04-14 · Modified
5.0EPSS 0.015
CVE-2003-0628
PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and earlier allows remote attackers to obtain the full pathnames for server-side include (SSI) files via an HTTP request with an invalid value.
Published 2003-11-18 · Modified
5.0EPSS 0.012
CVE-2003-0629
Cross-site scripting (XSS) vulnerability in PeopleSoft IScript environment for PeopleTools 8.43 and earlier allows remote attackers to insert arbitrary web script via a certain HTTP request to IScript.
Published 2003-11-18 · Modified
4.3EPSS 0.009
CVE-2006-0584
The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack that compares output strings.
Published 2006-02-08 · Modified
2.1EPSS 0.003