Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 703

Количество 331 703

nvd логотип

CVE-2004-1530

около 21 года назад

SQL injection vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the (1) eid or (2) cid parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1529

около 21 года назад

Cross-site scripting (XSS) vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary web script via the (1) type, (2) day, (3) month, or (4) year parameters in a Preview operation, or (5) event comments.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1528

около 21 года назад

The Event Calendar module 2.13 for PHP-Nuke allows remote attackers to gain sensitive information via an HTTP request to (1) config.php, (2) index.php, or (3) submit.php, which reveal the full path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1527

около 21 года назад

Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribute, which can cause it to modify cookies in other domains when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, which allows remote attackers to hijack web sessions.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1526

около 21 года назад

Hired Team: Trial 2.0 and earlier and 2.200 does not limit how game players can kick other players off the server, including the administrator.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1525

около 21 года назад

Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via the status command.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1524

около 21 года назад

Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (game interruption) via a malformed UDP packet sent to a game port, such as port 29200.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1523

около 21 года назад

Format string vulnerability in the game console in Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via format string specifiers in a message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1522

около 21 года назад

Format string vulnerability in Army Men RTS 1.0 allows remote attackers to cause a denial of service (application crash) via a nickname that contains format strings.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1521

около 21 года назад

Eudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable encoded attachments, which makes it easier for remote attackers to read arbitrary files via spoofed "Converted" headers.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1520

около 21 года назад

Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command.

CVSS2: 4.6
EPSS: Высокий
nvd логотип

CVE-2004-1519

около 21 года назад

SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands via (1) the bug_id parameter in a viewvotes operation or (2) the project parameter in an add operation.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1518

около 21 года назад

SQL injection vulnerability in follow.php in Phorum 5.0.12 and earlier allows remote authenticated users to execute arbitrary SQL command via the forum_id parameter.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-1517

около 21 года назад

Zone Labs IMsecure and IMsecure Pro before 1.5 allow remote attackers to bypass Active Link Filtering via an instant message containing a URL with hex encoded file extensions.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1516

около 21 года назад

CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the block_username parameter in the user module.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1515

около 21 года назад

SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1514

около 21 года назад

04WebServer 1.42 allows remote attackers to cause a denial of service (fail to restart properly) via an HTTP request for an MS-DOS device name such as COM2.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1513

около 21 года назад

04WebServer 1.42 does not adequately filter data that is written to log files, which could allow remote attackers to inject carriage return characters into the log file and spoof log entries.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1512

около 21 года назад

Cross-site scripting (XSS) vulnerability in Response_default.html in 04WebServer 1.42 allows remote attackers to execute arbitrary web script or HTML via script code in the URL, which is not quoted in the resulting default error page.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1511

около 21 года назад

Hotfoon 4.0 does not notify users before opening links in web browsers, which could allow remote attackers to execute arbitrary code via a certain link sent in a chat window.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-1530

SQL injection vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the (1) eid or (2) cid parameters.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1529

Cross-site scripting (XSS) vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary web script via the (1) type, (2) day, (3) month, or (4) year parameters in a Preview operation, or (5) event comments.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1528

The Event Calendar module 2.13 for PHP-Nuke allows remote attackers to gain sensitive information via an HTTP request to (1) config.php, (2) index.php, or (3) submit.php, which reveal the full path in an error message.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1527

Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribute, which can cause it to modify cookies in other domains when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, which allows remote attackers to hijack web sessions.

CVSS2: 5
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1526

Hired Team: Trial 2.0 and earlier and 2.200 does not limit how game players can kick other players off the server, including the administrator.

CVSS2: 7.5
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1525

Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via the status command.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1524

Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (game interruption) via a malformed UDP packet sent to a game port, such as port 29200.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1523

Format string vulnerability in the game console in Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via format string specifiers in a message.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1522

Format string vulnerability in Army Men RTS 1.0 allows remote attackers to cause a denial of service (application crash) via a nickname that contains format strings.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1521

Eudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable encoded attachments, which makes it easier for remote attackers to read arbitrary files via spoofed "Converted" headers.

CVSS2: 5
3%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1520

Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command.

CVSS2: 4.6
89%
Высокий
около 21 года назад
nvd логотип
CVE-2004-1519

SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands via (1) the bug_id parameter in a viewvotes operation or (2) the project parameter in an add operation.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1518

SQL injection vulnerability in follow.php in Phorum 5.0.12 and earlier allows remote authenticated users to execute arbitrary SQL command via the forum_id parameter.

CVSS2: 4.6
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1517

Zone Labs IMsecure and IMsecure Pro before 1.5 allow remote attackers to bypass Active Link Filtering via an instant message containing a URL with hex encoded file extensions.

CVSS2: 7.5
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1516

CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the block_username parameter in the user module.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1515

SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.

CVSS2: 7.5
0%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1514

04WebServer 1.42 allows remote attackers to cause a denial of service (fail to restart properly) via an HTTP request for an MS-DOS device name such as COM2.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1513

04WebServer 1.42 does not adequately filter data that is written to log files, which could allow remote attackers to inject carriage return characters into the log file and spoof log entries.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1512

Cross-site scripting (XSS) vulnerability in Response_default.html in 04WebServer 1.42 allows remote attackers to execute arbitrary web script or HTML via script code in the URL, which is not quoted in the resulting default error page.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2004-1511

Hotfoon 4.0 does not notify users before opening links in web browsers, which could allow remote attackers to execute arbitrary code via a certain link sent in a chat window.

CVSS2: 5
1%
Низкий
около 21 года назад

Уязвимостей на страницу