Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2003-0050

5 documents5 sources
Severity
7.5HIGH
EPSS
87.9%
top 0.52%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMar 7
Latest updateApr 29

Description

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
GHSA-hx3w-96xp-pcxm: parse_xml2022-04-29
CVEList
CVE-2003-0050: parse_xml2004-09-01
VulnCheck
Apple darwin_streaming_server Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2003

💥Exploits & PoCs

1
Exploit-DB
QuickTime Streaming Server - 'parse_xml.cgi' Remote Execution (Metasploit)2010-07-03