Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 309 169

Количество 309 169

nvd логотип

CVE-2004-1516

больше 20 лет назад

CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the block_username parameter in the user module.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1515

больше 20 лет назад

SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1514

больше 20 лет назад

04WebServer 1.42 allows remote attackers to cause a denial of service (fail to restart properly) via an HTTP request for an MS-DOS device name such as COM2.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1513

больше 20 лет назад

04WebServer 1.42 does not adequately filter data that is written to log files, which could allow remote attackers to inject carriage return characters into the log file and spoof log entries.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1512

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in Response_default.html in 04WebServer 1.42 allows remote attackers to execute arbitrary web script or HTML via script code in the URL, which is not quoted in the resulting default error page.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1511

больше 20 лет назад

Hotfoon 4.0 does not notify users before opening links in web browsers, which could allow remote attackers to execute arbitrary code via a certain link sent in a chat window.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1510

больше 20 лет назад

WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upcoming.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1509

больше 20 лет назад

validate.php in WebCalendar allows remote attackers to gain sensitive information via an invalid encoded_login parameter, which reveals the full path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1508

больше 20 лет назад

init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1507

больше 20 лет назад

CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and perform HTTP Response Splitting attacks to modify expected HTML content from the server.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1506

больше 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar allow remote attackers to inject arbitrary web script via (1) view_entry.php, (2) view_d.php, (3) usersel.php, (4) datesel.php, (5) trailer.php, or (6) styles.php, as demonstrated using img srg tags.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1505

больше 20 лет назад

Directory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to read arbitrary files and possibly execute PHP code via a .. (dot dot) in the show parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1504

больше 20 лет назад

The displaycontent function in config.php for Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to gain sensitive information via a blank show parameter, which reveals the installation path in an error message, as demonstrated using index.php.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1503

больше 20 лет назад

Integer overflow in the InitialDirContext in Java Runtime Environment (JRE) 1.4.2, 1.5.0 and possibly other versions allows remote attackers to cause a denial of service (Java exception and failed DNS requests) via a large number of DNS requests, which causes the xid variable to wrap around and become negative.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1502

больше 20 лет назад

The Telnet proxy in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (socket exhaustion) via a Telnet request to an IP address of the proxy's network interface, which causes a loop.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1501

больше 20 лет назад

The webmail service in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) by sending a POST request with a large Content-Length value, then disconnecting without sending that amount of data.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1500

больше 20 лет назад

Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-1499

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1498

больше 20 лет назад

SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1497

больше 20 лет назад

Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-1516

CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the block_username parameter in the user module.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1515

SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.

CVSS2: 7.5
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1514

04WebServer 1.42 allows remote attackers to cause a denial of service (fail to restart properly) via an HTTP request for an MS-DOS device name such as COM2.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1513

04WebServer 1.42 does not adequately filter data that is written to log files, which could allow remote attackers to inject carriage return characters into the log file and spoof log entries.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1512

Cross-site scripting (XSS) vulnerability in Response_default.html in 04WebServer 1.42 allows remote attackers to execute arbitrary web script or HTML via script code in the URL, which is not quoted in the resulting default error page.

CVSS2: 4.3
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1511

Hotfoon 4.0 does not notify users before opening links in web browsers, which could allow remote attackers to execute arbitrary code via a certain link sent in a chat window.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1510

WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upcoming.php.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1509

validate.php in WebCalendar allows remote attackers to gain sensitive information via an invalid encoded_login parameter, which reveals the full path in an error message.

CVSS2: 5
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1508

init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1507

CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and perform HTTP Response Splitting attacks to modify expected HTML content from the server.

CVSS2: 5
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1506

Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar allow remote attackers to inject arbitrary web script via (1) view_entry.php, (2) view_d.php, (3) usersel.php, (4) datesel.php, (5) trailer.php, or (6) styles.php, as demonstrated using img srg tags.

CVSS2: 4.3
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1505

Directory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to read arbitrary files and possibly execute PHP code via a .. (dot dot) in the show parameter.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1504

The displaycontent function in config.php for Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to gain sensitive information via a blank show parameter, which reveals the installation path in an error message, as demonstrated using index.php.

CVSS2: 5
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1503

Integer overflow in the InitialDirContext in Java Runtime Environment (JRE) 1.4.2, 1.5.0 and possibly other versions allows remote attackers to cause a denial of service (Java exception and failed DNS requests) via a large number of DNS requests, which causes the xid variable to wrap around and become negative.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1502

The Telnet proxy in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (socket exhaustion) via a Telnet request to an IP address of the proxy's network interface, which causes a loop.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1501

The webmail service in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) by sending a POST request with a large Content-Length value, then disconnecting without sending that amount of data.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1500

Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.

CVSS2: 2.1
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1499

Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.

CVSS2: 4.3
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1498

SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2004-1497

Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges.

CVSS2: 4.6
0%
Низкий
больше 20 лет назад

Уязвимостей на страницу