Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 878

Количество 331 878

nvd логотип

CVE-2004-2007

почти 22 года назад

Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to inject arbitrary HTML or web script via the (1) cat parameter in a CatView function or (2) jokeid parameter in a JokeView function.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2006

почти 22 года назад

Trend Micro OfficeScan 3.0 - 6.0 has default permissions of "Everyone Full Control" on the installation directory and registry keys, which allows local users to disable virus protection.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-2005

почти 22 года назад

Buffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-mail with (1) a link to a long URL to the C drive or (2) a long attachment name.

CVSS2: 5.1
EPSS: Средний
nvd логотип

CVE-2004-2004

почти 22 года назад

The Live CD in SUSE LINUX 9.1 Personal edition is configured without a password for root, which allows remote attackers to gain privileges via SSH.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-2003

почти 22 года назад

Buffer overflow in the ssl_prcert function in the SSLway filter (sslway.c) for DeleGate 8.9.2 and earlier allows remote attackers to execute arbitrary code via a certificate with a long (1) subject or (2) issuer name field.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2002

почти 22 года назад

Unknown vulnerability in SGI IRIX 6.5 through 6.5.22m allows remote attackers to cause a denial of service via a certain UDP packet.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2001

почти 22 года назад

ifconfig "-arp" in SGI IRIX 6.5 through 6.5.22m does not properly disable ARP requests from being sent or received.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-2000

почти 22 года назад

SQL injection vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL via the (1) orderby or (2) sid parameters to modules.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1999

почти 22 года назад

Cross-site scripting (XSS) vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to inject arbitrary HTML and web script via the (1) ttitle or (2) sid parameters to modules.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1998

почти 22 года назад

The Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to gain sensitive information via an invalid show parameter to modules.php, which reveals the full path in a PHP error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1997

почти 22 года назад

Kolab stores OpenLDAP passwords in plaintext in the slapd.conf file, which may be installed world-readable, which allows local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-1996

почти 22 года назад

Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size tag.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1995

около 21 года назад

Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2004-1994

почти 22 года назад

FuseTalk 4.0 allows remote attackers to ban other users via a direct request to banning.cfm.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1993

почти 22 года назад

The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as "`" (backticks) in the password.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-1992

почти 22 года назад

Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-1991

почти 22 года назад

Directory traversal vulnerability in Aldo's Web Server (aweb) 1.5 allows remote attackers to view arbitrary files via a .. (dot dot) in an HTTP GET request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1990

почти 22 года назад

Aldo's Web Server (aweb) 1.5 allows remote attackers to gain sensitive information via an arbitrary character, which reveals the full path and the user running the aweb process, possibly due to a malformed request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1989

почти 22 года назад

PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modifying the THEME_DIR parameter to reference a URL on a remote web server that contains user_list_info_box.inc.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1988

почти 22 года назад

PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by modifying the CPG_M_DIR to reference a URL on a remote web server that contains functions.inc.php.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-2007

Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to inject arbitrary HTML or web script via the (1) cat parameter in a CatView function or (2) jokeid parameter in a JokeView function.

CVSS2: 4.3
0%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-2006

Trend Micro OfficeScan 3.0 - 6.0 has default permissions of "Everyone Full Control" on the installation directory and registry keys, which allows local users to disable virus protection.

CVSS2: 4.6
0%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-2005

Buffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-mail with (1) a link to a long URL to the C drive or (2) a long attachment name.

CVSS2: 5.1
21%
Средний
почти 22 года назад
nvd логотип
CVE-2004-2004

The Live CD in SUSE LINUX 9.1 Personal edition is configured without a password for root, which allows remote attackers to gain privileges via SSH.

CVSS2: 10
1%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-2003

Buffer overflow in the ssl_prcert function in the SSLway filter (sslway.c) for DeleGate 8.9.2 and earlier allows remote attackers to execute arbitrary code via a certificate with a long (1) subject or (2) issuer name field.

CVSS2: 7.5
7%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-2002

Unknown vulnerability in SGI IRIX 6.5 through 6.5.22m allows remote attackers to cause a denial of service via a certain UDP packet.

CVSS2: 5
1%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-2001

ifconfig "-arp" in SGI IRIX 6.5 through 6.5.22m does not properly disable ARP requests from being sent or received.

CVSS2: 4.6
0%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-2000

SQL injection vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL via the (1) orderby or (2) sid parameters to modules.php.

CVSS2: 7.5
3%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1999

Cross-site scripting (XSS) vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to inject arbitrary HTML and web script via the (1) ttitle or (2) sid parameters to modules.php.

CVSS2: 4.3
1%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1998

The Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to gain sensitive information via an invalid show parameter to modules.php, which reveals the full path in a PHP error message.

CVSS2: 5
0%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1997

Kolab stores OpenLDAP passwords in plaintext in the slapd.conf file, which may be installed world-readable, which allows local users to gain privileges.

CVSS2: 4.6
0%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1996

Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size tag.

CVSS2: 4.3
0%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1995

Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.

CVSS3: 6.5
5%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1994

FuseTalk 4.0 allows remote attackers to ban other users via a direct request to banning.cfm.

CVSS2: 5
1%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1993

The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as "`" (backticks) in the password.

CVSS2: 10
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1992

Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read.

CVSS2: 5
11%
Средний
почти 22 года назад
nvd логотип
CVE-2004-1991

Directory traversal vulnerability in Aldo's Web Server (aweb) 1.5 allows remote attackers to view arbitrary files via a .. (dot dot) in an HTTP GET request.

CVSS2: 5
3%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1990

Aldo's Web Server (aweb) 1.5 allows remote attackers to gain sensitive information via an arbitrary character, which reveals the full path and the user running the aweb process, possibly due to a malformed request.

CVSS2: 5
1%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1989

PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modifying the THEME_DIR parameter to reference a URL on a remote web server that contains user_list_info_box.inc.

CVSS2: 7.5
0%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1988

PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by modifying the CPG_M_DIR to reference a URL on a remote web server that contains functions.inc.php.

CVSS2: 7.5
0%
Низкий
почти 22 года назад

Уязвимостей на страницу