Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2003-0747

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SAP Internet Transaction Server (ITS)是一款基于Internet的事务服务程序。 SAO ITS服务器由于没有正确处理畸形请求,远程攻击者可以利用这个漏洞获得本地系统敏感信息。 问题存在于wgate.dll问中,由于不充分处理用户提交的各种参数,攻击者可以提交包含非法输入参数的WEB请求,可导致服务器返回包含各种系统信息,目录结构的敏感信息给客户端,攻击者可以利用这些信息进一步对系统进行攻击。

AI Predicted 5.3 Difficulty: Trivial EPSS 3.15% · P87

Public Exploits 1

ExploitDB · 1 EDB-23069 [remote]
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2003-0747

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
wgate.dll in SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to obtain potentially sensitive information such as directory structure and operating system via incorrect parameters (1) ~service, (2) ~templatelanguage, (3) ~language, (4) ~theme, or (5) ~template, which leaks the information in the resulting error message.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
SAP Internet Transaction Server远程信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SAP Internet Transaction Server (ITS)是一款基于Internet的事务服务程序。 SAO ITS服务器由于没有正确处理畸形请求,远程攻击者可以利用这个漏洞获得本地系统敏感信息。 问题存在于wgate.dll问中,由于不充分处理用户提交的各种参数,攻击者可以提交包含非法输入参数的WEB请求,可导致服务器返回包含各种系统信息,目录结构的敏感信息给客户端,攻击者可以利用这些信息进一步对系统进行攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2003-0747

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2003-0747

登录查看更多情报信息。

Vendor Advisories for CVE-2003-0747 (2)

Mailing List Discussions for CVE-2003-0747 (1)

Same Patch Batch · n/a · 2003-09-06 · 15 CVEs total

CVE-2003-0743 Exim畸形EHLO/HELO命令远程堆破坏漏洞
CVE-2003-0744 Leafnode fetchnews远程拒绝服务攻击漏洞
CVE-2003-0745 Castle Rock Computing SNMPc v5/v6未授权远程访问漏洞
CVE-2003-0746 分布式计算环境(DCE)服务拒绝漏洞
CVE-2003-0748 SAP Internet Transaction Server远程目录遍历漏洞
CVE-2003-0749 SAP Internet Transaction Server跨站脚本执行漏洞
CVE-2003-0750 PY-Membres漏洞
CVE-2003-0751 PY-Membres SQL注入漏洞
CVE-2003-0752 global.php3 of AttilaPHP SQL注入漏洞
CVE-2003-0753 newsPHP nphpd.php漏洞
CVE-2003-0754 newsPHP nphpd.php漏洞
CVE-2003-0755 gtkftpd缓冲区溢出漏洞
CVE-2003-0756 SiteBuilder目录遍历漏洞
CVE-2003-0757 Check Point Firewall-1 SecuRemote内部接口地址信息泄露漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2003-0747

No comments yet


Leave a comment