CVE-2003-0050

EXPLOITED

Apple Darwin Streaming Administration Server <4.1.2 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2003-0050 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including Metasploit, hdm, including a Metasploit module exploits/unix/webapp/qtss_parse_xml_exec.

AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in QuickTime Streaming Server's parse_xml.cgi script, allowing arbitrary command execution as root via a maliciously crafted POST request.

Description

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappscgi
https://www.exploit-db.com/exploits/16891

This Metasploit module exploits a command injection vulnerability in QuickTime Streaming Server's parse_xml.cgi script, allowing arbitrary command execution as root via a maliciously crafted POST request.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: QuickTime Streaming Server (parse_xml.cgi)
No auth needed
Prerequisites: Network access to the target server · parse_xml.cgi endpoint exposed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by hdm · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/qtss_parse_xml_exec.rb

This Metasploit module exploits a command injection vulnerability in QuickTime Streaming Server's parse_xml.cgi script, allowing arbitrary command execution as root via a maliciously crafted POST request.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: QuickTime Streaming Server (CVE-2003-0050)
No auth needed
Prerequisites: Network access to the target server · parse_xml.cgi script accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/11401.php
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=104618904330226&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6954

Scores

EPSS 0.8785
EPSS Percentile 99.5%

Details

VulnCheck KEV 2020-12-01
Status published
Products (2)
apple/darwin_streaming_server 4.1.2
apple/quicktime_streaming_server 4.1.1
Published Mar 07, 2003
Tracked Since Feb 18, 2026