Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 703

Количество 331 703

nvd логотип

CVE-2004-1550

около 21 года назад

Motorola Wireless Router WR850G running firmware 4.03 allows remote attackers to bypass authentication, log on as an administrator, and obtain sensitive information by repeatedly making an HTTP request for ver.asp until an administrator logs on.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2004-1549

около 21 года назад

The conference menu in ActivePost Standard 3.1 sends passwords of password-protected rooms in cleartext, which could allow remote attackers to gain sensitive information by sniffing the network connection.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1548

около 21 года назад

Directory traversal vulnerability in the file server in ActivePost Standard 3.1 allows remote authenticated users to upload arbitrary files via a .. (dot dot) in the filename.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1547

около 21 года назад

The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to cause a denial of service (application crash) via a long filename, possibly triggering a buffer overflow.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1546

около 21 года назад

Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a long (1) SAML, SOML, SEND, or MAIL command to the SMTP server or (2) LIST command to the IMAP server.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-1545

около 21 года назад

UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1544

около 21 года назад

Cross-site scripting (XSS) vulnerability in Search.jsp in JSPWiki 2.1.120-cvs and earlier allows remote attackers to execute arbitrary web script as other users via the query parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1543

около 21 года назад

Directory traversal vulnerability in viewimg.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1542

около 21 года назад

Buffer overflow in Soldier of Fortune II 1.03 Gold and earlier allows remote attackers to cause a denial of service (server or client crash) via a long (1) query or (2) reply.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1541

около 21 года назад

SecureCRT 4.0, 4.1, and possibly other versions, allows remote attackers to execute arbitrary commands via a telnet:// URL that uses the /F option to specify a configuration file on a samba share.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1540

около 21 года назад

ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to access rpFWUpload.html, which allows remote attackers to reset the router configuration file.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1539

около 21 года назад

Halo: Combat Evolved 1.05 and earlier allows remote game servers to cause a denial of service (client crash) via a long value in a game server reply, which triggers a NULL dereference.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1538

около 21 года назад

SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1537

около 21 года назад

Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web script via the img parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1536

около 21 года назад

SQL injection vulnerability in index.php in the ibProArcade module for Invision Power Board (IPB) 1.x and 2.x allows remote attackers to execute arbitrary SQL commands via the cat parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1535

около 21 года назад

PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_path parameter to reference a URL on a remote web server that contains the code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1534

около 21 года назад

ZoneAlarm and ZoneAlarm Pro before 5.5.062, with ad-blocking enabled, allows remote web sites to cause a denial of service (application instability or system hang) via certain JavaScript.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1533

около 21 года назад

Buffer overflow in pop3svr.exe for DMS POP3 1.5.3.27 and earlier allows remote attackers to cause a denial of service (service crash) via a long (1) username or (2) password.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1532

около 21 года назад

AppServ 2.5.x and earlier installs a default username and password, which allows remote attackers to gain access.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1531

около 21 года назад

SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-1550

Motorola Wireless Router WR850G running firmware 4.03 allows remote attackers to bypass authentication, log on as an administrator, and obtain sensitive information by repeatedly making an HTTP request for ver.asp until an administrator logs on.

CVSS2: 7.5
35%
Средний
около 21 года назад
nvd логотип
CVE-2004-1549

The conference menu in ActivePost Standard 3.1 sends passwords of password-protected rooms in cleartext, which could allow remote attackers to gain sensitive information by sniffing the network connection.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1548

Directory traversal vulnerability in the file server in ActivePost Standard 3.1 allows remote authenticated users to upload arbitrary files via a .. (dot dot) in the filename.

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1547

The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to cause a denial of service (application crash) via a long filename, possibly triggering a buffer overflow.

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1546

Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a long (1) SAML, SOML, SEND, or MAIL command to the SMTP server or (2) LIST command to the IMAP server.

CVSS2: 5
49%
Средний
около 21 года назад
nvd логотип
CVE-2004-1545

UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1544

Cross-site scripting (XSS) vulnerability in Search.jsp in JSPWiki 2.1.120-cvs and earlier allows remote attackers to execute arbitrary web script as other users via the query parameter.

CVSS2: 4.3
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1543

Directory traversal vulnerability in viewimg.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter.

CVSS2: 5
6%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1542

Buffer overflow in Soldier of Fortune II 1.03 Gold and earlier allows remote attackers to cause a denial of service (server or client crash) via a long (1) query or (2) reply.

CVSS2: 5
6%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1541

SecureCRT 4.0, 4.1, and possibly other versions, allows remote attackers to execute arbitrary commands via a telnet:// URL that uses the /F option to specify a configuration file on a samba share.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1540

ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to access rpFWUpload.html, which allows remote attackers to reset the router configuration file.

CVSS2: 5
5%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1539

Halo: Combat Evolved 1.05 and earlier allows remote game servers to cause a denial of service (client crash) via a long value in a game server reply, which triggers a NULL dereference.

CVSS2: 5
7%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1538

SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1537

Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web script via the img parameter.

CVSS2: 4.3
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1536

SQL injection vulnerability in index.php in the ibProArcade module for Invision Power Board (IPB) 1.x and 2.x allows remote attackers to execute arbitrary SQL commands via the cat parameter.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1535

PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_path parameter to reference a URL on a remote web server that contains the code.

CVSS2: 7.5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1534

ZoneAlarm and ZoneAlarm Pro before 5.5.062, with ad-blocking enabled, allows remote web sites to cause a denial of service (application instability or system hang) via certain JavaScript.

CVSS2: 5
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1533

Buffer overflow in pop3svr.exe for DMS POP3 1.5.3.27 and earlier allows remote attackers to cause a denial of service (service crash) via a long (1) username or (2) password.

CVSS2: 5
7%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1532

AppServ 2.5.x and earlier installs a default username and password, which allows remote attackers to gain access.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1531

SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter.

CVSS2: 7.5
1%
Низкий
около 21 года назад

Уязвимостей на страницу