Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 309 416

Количество 309 416

nvd логотип

CVE-2004-1844

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in Member Management System 2.1 allows remote attackers to inject arbitrary web script or HTML via (1) the err parameter to error.asp or (2) register.asp.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1843

больше 21 года назад

SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1) resend.asp or (2) news_view.asp.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1842

больше 20 лет назад

Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2004-1841

больше 20 лет назад

SQL injection vulnerability in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL via the referer field in an HTTP request.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1840

больше 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) screen parameter to modules.php, (2) module_name parameter to title.php, (3) sortby parameter to modules.php, or (4) overview parameter to modules.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1839

больше 21 года назад

MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php, or (3) title.php, which reveal the full path in a PHP error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1838

больше 21 года назад

Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the URL.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-1837

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in Mod_survey 3.0.x before 3.0.16-pre2 and 3.2.x before 3.2.0-pre4 allows remote attackers to inject arbitrary web script or HTML via the certain survey fields or error messages for malformed query strings.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1836

больше 20 лет назад

SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments action.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1835

больше 20 лет назад

Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1834

больше 21 года назад

mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-1833

больше 21 года назад

The admin.ib file in Borland Interbase 7.1 for Linux has default world writable permissions, which allows local users to gain database administrative privileges.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1832

больше 20 лет назад

Buffer overflow in the GUI admin service in Mac OS X Server 10.3 allows remote attackers to cause a denial of service (crash and restart) via a large amount of data to TCP port 660.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1831

больше 20 лет назад

Buffer overflow in Chrome 1.2.0.0 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large length value, which leads to a null dereference or out-of-bounds read.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1830

больше 21 года назад

error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a PHP error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1829

больше 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in error.php in Gijza.net Error Manager 2.1 for PHP-Nuke 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pagetitle or (2) error parameters, or (3) certain parameters in the error log.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1828

больше 20 лет назад

Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and delete database tables via a direct request to uninstall.php.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1827

больше 21 года назад

Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1826

больше 21 года назад

SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1825

больше 21 года назад

Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-1844

Cross-site scripting (XSS) vulnerability in Member Management System 2.1 allows remote attackers to inject arbitrary web script or HTML via (1) the err parameter to error.asp or (2) register.asp.

CVSS2: 4.3
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1843

SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1) resend.asp or (2) news_view.asp.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1842

Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php.

CVSS3: 8.8
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1841

SQL injection vulnerability in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL via the referer field in an HTTP request.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1840

Multiple cross-site scripting (XSS) vulnerabilities in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) screen parameter to modules.php, (2) module_name parameter to title.php, (3) sortby parameter to modules.php, or (4) overview parameter to modules.php.

CVSS2: 4.3
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1839

MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php, or (3) title.php, which reveal the full path in a PHP error message.

CVSS2: 5
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1838

Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the URL.

CVSS2: 5
13%
Средний
больше 21 года назад
nvd логотип
CVE-2004-1837

Cross-site scripting (XSS) vulnerability in Mod_survey 3.0.x before 3.0.16-pre2 and 3.2.x before 3.2.0-pre4 allows remote attackers to inject arbitrary web script or HTML via the certain survey fields or error messages for malformed query strings.

CVSS2: 4.3
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1836

SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments action.

CVSS2: 7.5
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1835

Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1834

mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1833

The admin.ib file in Borland Interbase 7.1 for Linux has default world writable permissions, which allows local users to gain database administrative privileges.

CVSS2: 7.5
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1832

Buffer overflow in the GUI admin service in Mac OS X Server 10.3 allows remote attackers to cause a denial of service (crash and restart) via a large amount of data to TCP port 660.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1831

Buffer overflow in Chrome 1.2.0.0 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large length value, which leads to a null dereference or out-of-bounds read.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1830

error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a PHP error message.

CVSS2: 5
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1829

Multiple cross-site scripting (XSS) vulnerabilities in error.php in Gijza.net Error Manager 2.1 for PHP-Nuke 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pagetitle or (2) error parameters, or (3) certain parameters in the error log.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1828

Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and delete database tables via a direct request to uninstall.php.

CVSS2: 5
3%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1827

Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1826

SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1825

Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters.

CVSS2: 4.3
2%
Низкий
больше 21 года назад

Уязвимостей на страницу