Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 878

Количество 331 878

nvd логотип

CVE-2004-2067

больше 21 года назад

SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2066

больше 21 года назад

SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and bypass authentication via the (1) linpha_userid or (2) linpha_password cookies.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2065

около 21 года назад

DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension or . in the filename.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2064

больше 21 года назад

Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web script via the (1) Email or (2) Website fields.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2063

около 21 года назад

Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inject arbitrary HTML or web script via the feedback parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2062

около 21 года назад

SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2) parent_id, or (3) mode parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2061

больше 21 года назад

RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2004-2060

около 21 года назад

ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2059

около 21 года назад

Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SearchFor parameter in [TABLE-NAME]_search.asp, (2) SQL parameter in [TABLE-NAME]_edit.asp, (3) SearchFor parameter in [TABLE]_list.asp, or (4) SQL parameter in export.asp.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-2058

около 21 года назад

ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2057

около 21 года назад

SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2056

около 21 года назад

SQL injection vulnerability in action.php in Nucleus CMS 3.01 allows remote attackers to execute arbitrary SQL statements via the itemid parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2055

больше 21 года назад

Cross-site scripting (XSS) vulnerability in search.php for PhpBB 2.0.4 and 2.0.9 allows remote attackers to inject arbitrary HTMl or web script via the search_author parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2054

около 21 года назад

CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via (1) the mode parameter to privmsg.php or (2) the redirect parameter to login.php.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2053

больше 21 года назад

PHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitrary PHP code via the site parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2052

около 21 года назад

eSeSIX Thintune thin clients running firmware 2.4.38 and earlier accept any password that begins with the actual password, which makes it easier for users to conduct brute force password guessing.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2051

больше 21 года назад

The Phoenix browser in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allows local users to read arbitrary files via a file:/// URL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2050

около 21 года назад

eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allow local users to gain privileges by pressing CTRL-SHIFT-ALT-DEL and entering the "maertsJ" password, which is hard-coded into lshell.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-2049

около 21 года назад

eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain access.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-2048

около 21 года назад

radmin in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier starts a process port 25072 that can be accessed with a default "jstwo" password, which allows remote attackers to gain access.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-2067

SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.

CVSS2: 7.5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2066

SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and bypass authentication via the (1) linpha_userid or (2) linpha_password cookies.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2065

DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension or . in the filename.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2064

Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web script via the (1) Email or (2) Website fields.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2063

Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inject arbitrary HTML or web script via the feedback parameter.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2062

SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2) parent_id, or (3) mode parameters.

CVSS2: 7.5
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2061

RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.

CVSS3: 9.8
16%
Средний
больше 21 года назад
nvd логотип
CVE-2004-2060

ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.

CVSS2: 5
9%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2059

Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SearchFor parameter in [TABLE-NAME]_search.asp, (2) SQL parameter in [TABLE-NAME]_edit.asp, (3) SearchFor parameter in [TABLE]_list.asp, or (4) SQL parameter in export.asp.

CVSS2: 5
10%
Средний
около 21 года назад
nvd логотип
CVE-2004-2058

ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2057

SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2056

SQL injection vulnerability in action.php in Nucleus CMS 3.01 allows remote attackers to execute arbitrary SQL statements via the itemid parameter.

CVSS2: 7.5
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2055

Cross-site scripting (XSS) vulnerability in search.php for PhpBB 2.0.4 and 2.0.9 allows remote attackers to inject arbitrary HTMl or web script via the search_author parameter.

CVSS2: 4.3
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2054

CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via (1) the mode parameter to privmsg.php or (2) the redirect parameter to login.php.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2053

PHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitrary PHP code via the site parameter.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2052

eSeSIX Thintune thin clients running firmware 2.4.38 and earlier accept any password that begins with the actual password, which makes it easier for users to conduct brute force password guessing.

CVSS2: 7.5
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2051

The Phoenix browser in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allows local users to read arbitrary files via a file:/// URL.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2050

eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allow local users to gain privileges by pressing CTRL-SHIFT-ALT-DEL and entering the "maertsJ" password, which is hard-coded into lshell.

CVSS2: 4.6
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2049

eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain access.

CVSS2: 4.6
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-2048

radmin in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier starts a process port 25072 that can be accessed with a default "jstwo" password, which allows remote attackers to gain access.

CVSS2: 10
3%
Низкий
около 21 года назад

Уязвимостей на страницу