Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 309 416

Количество 309 416

nvd логотип

CVE-2004-1804

больше 20 лет назад

wMCam server 2.1.348 allows remote attackers to cause a denial of service (no new connections) via multiple malformed HTTP requests without the GET command.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1802

больше 20 лет назад

Chat Anywhere 2.72 and earlier allows remote attackers to hide their IP address by using %00 before the nickname, which causes the IP address to be displayed as $IP$ on the administration web page.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1801

больше 20 лет назад

Directory traversal vulnerability in PWebServer 0.3.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1800

больше 20 лет назад

Unknown vulnerability in Sysbotz SimpleData 4.0.1 and possibly earlier versions allows remote attackers to gain access via a crafted URL and a certain cookie.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1799

больше 20 лет назад

PF in certain OpenBSD versions, when stateful filtering is enabled, does not limit packets for a session to the original interface, which allows remote attackers to bypass intended packet filters via spoofed packets to other interfaces.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1798

больше 20 лет назад

RealOne player 6.0.11.868 allows remote attackers to execute arbitrary script in the "My Computer" zone via a Synchronized Multimedia Integration Language (SMIL) presentation with a "file:javascript:" URL, which is executed in the security context of the previously loaded URL, a different vulnerability than CVE-2003-0726.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2004-1797

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1796

больше 20 лет назад

PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header] parameter to hotnews-engine.inc.php3 or (2) config[incdir] parameter to hnmain.inc.php3.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2004-1795

больше 20 лет назад

Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-1794

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in the VCard4J Toolkit allows remote attackers to inject arbitrary web script or HTML via the NICKNAME tag in a vCard.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1793

больше 20 лет назад

Stack-based buffer overflow in swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote authenticated users to execute arbitrary code via a long message parameter in a SendMsg action to action.htm.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1792

больше 20 лет назад

swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a long packet with two CRLF sequences to the service management port (TCP 8000).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1791

больше 20 лет назад

The web management interface in Edimax AR-6004 ADSL Routers uses a default administrator name and password, which also appear as the default login text for the management interface, which allows remote attackers to gain access.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1790

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in the web management interface in Edimax AR-6004 ADSL Routers allows remote attackers to inject arbitrary web script or HTML via the URL.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1789

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to inject arbitrary web script or HTML via the rpAuth_1 page.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1788

больше 20 лет назад

ASP-Nuke 1.3 and earlier places user credentials under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to main.mdb.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1787

больше 20 лет назад

SQL injection vulnerability in PostCalendar 4.0.0 allows remote attackers to execute arbitrary SQL commands via search queries.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1786

больше 21 года назад

PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1785

больше 21 года назад

SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1784

больше 21 года назад

Buffer overflow in the web server of Webcam Watchdog 3.63 allows remote attackers to execute arbitrary code via a long HTTP GET request.

CVSS2: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-1804

wMCam server 2.1.348 allows remote attackers to cause a denial of service (no new connections) via multiple malformed HTTP requests without the GET command.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1802

Chat Anywhere 2.72 and earlier allows remote attackers to hide their IP address by using %00 before the nickname, which causes the IP address to be displayed as $IP$ on the administration web page.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1801

Directory traversal vulnerability in PWebServer 0.3.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

CVSS2: 5
7%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1800

Unknown vulnerability in Sysbotz SimpleData 4.0.1 and possibly earlier versions allows remote attackers to gain access via a crafted URL and a certain cookie.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1799

PF in certain OpenBSD versions, when stateful filtering is enabled, does not limit packets for a session to the original interface, which allows remote attackers to bypass intended packet filters via spoofed packets to other interfaces.

CVSS2: 7.5
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1798

RealOne player 6.0.11.868 allows remote attackers to execute arbitrary script in the "My Computer" zone via a Synchronized Multimedia Integration Language (SMIL) presentation with a "file:javascript:" URL, which is executed in the security context of the previously loaded URL, a different vulnerability than CVE-2003-0726.

CVSS2: 5.1
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1797

Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.

CVSS2: 4.3
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1796

PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header] parameter to hotnews-engine.inc.php3 or (2) config[incdir] parameter to hnmain.inc.php3.

CVSS2: 7.5
13%
Средний
больше 20 лет назад
nvd логотип
CVE-2004-1795

Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI.

CVSS2: 2.1
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1794

Cross-site scripting (XSS) vulnerability in the VCard4J Toolkit allows remote attackers to inject arbitrary web script or HTML via the NICKNAME tag in a vCard.

CVSS2: 4.3
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1793

Stack-based buffer overflow in swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote authenticated users to execute arbitrary code via a long message parameter in a SendMsg action to action.htm.

CVSS2: 7.5
10%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1792

swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a long packet with two CRLF sequences to the service management port (TCP 8000).

CVSS2: 5
7%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1791

The web management interface in Edimax AR-6004 ADSL Routers uses a default administrator name and password, which also appear as the default login text for the management interface, which allows remote attackers to gain access.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1790

Cross-site scripting (XSS) vulnerability in the web management interface in Edimax AR-6004 ADSL Routers allows remote attackers to inject arbitrary web script or HTML via the URL.

CVSS2: 4.3
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1789

Cross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to inject arbitrary web script or HTML via the rpAuth_1 page.

CVSS2: 4.3
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1788

ASP-Nuke 1.3 and earlier places user credentials under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to main.mdb.

CVSS2: 5
5%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1787

SQL injection vulnerability in PostCalendar 4.0.0 allows remote attackers to execute arbitrary SQL commands via search queries.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1786

PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb.

CVSS2: 5
5%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1785

SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1784

Buffer overflow in the web server of Webcam Watchdog 3.63 allows remote attackers to execute arbitrary code via a long HTTP GET request.

CVSS2: 7.5
10%
Средний
больше 21 года назад

Уязвимостей на страницу