Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 328

Количество 372 328

nvd логотип

CVE-2004-2716

больше 21 года назад

Multiple SQL injection vulnerabilities in usersL.php3 in PHPMyChat 0.14.5 allow remote attackers to execute arbitrary SQL commands via the (1) sortBy, (2) sortOrder, (3) startReg, (4) U, (5) LastCheck , and (6) R parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2715

больше 21 года назад

edituser.php3 in PHPMyChat 0.14.5 allow remote attackers to bypass authentication and gain administrative privileges by setting the do_not_login parameter to false.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2714

больше 21 года назад

Unspecified vulnerability in Window Maker 0.80.2 and earlier allows attackers to perform unknown actions via format string specifiers in a font specification in WMGLOBAL, probably a format string vulnerability.

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2004-2713

больше 21 года назад

Zone Alarm Pro 1.0 through 5.1 gives full access to %windir%\Internet Logs\* to the EVERYONE group, which allows local users to cause a denial of service by modifying the folder contents or permissions. NOTE: this issue has been disputed by the vendor, who claims that it does not affect product functionality since the same information is also saved in a protected file

CVSS2: 1.9
EPSS: Низкий
nvd логотип

CVE-2004-2712

больше 21 года назад

Buffer overflow in Gyach Enhanced (Gyach-E) before 1.0.0-SneakPeek-3 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to "URL data."

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2711

больше 21 года назад

Multiple buffer overflows in Gyach Enhanced (Gyach-E) before 1.0.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to "avatar retrieval."

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2710

больше 21 года назад

Multiple buffer overflows in Gyach Enhanced (Gyach-E) before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) sending certain typing statuses or (2) setting the chat room status bar to the current chat room name.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2709

больше 21 года назад

Buffer overflow in the strip_html_tags method for Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown vectors involving HTML tags.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2708

больше 21 года назад

Gyach Enhanced (Gyach-E) before 1.0.0 stores passwords in plaintext, which allows attackers to obtain user passwords by reading the configuration file.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2707

больше 21 года назад

Multiple unspecified vulnerabilities in Gyach Enhanced (Gyach-E) before 1.0.5 have unknown impact and attack vectors related to "several security flaws," probably related to buffer overflows in HTTP server responses.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2706

больше 21 года назад

Unspecified vulnerability in Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service (crash) via conference packets with error messages.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2705

больше 21 года назад

Unspecified vulnerability in Player vs. Player Gaming Network (PvPGN) before 1.6.4 allows remote attackers to obtain attributes of arbitrary accounts, including the password hash, via certain statsreq packets.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2704

больше 21 года назад

Hastymail 1.0.1 and earlier (stable) and 1.1 and earlier (development) does not send the "attachment" parameter in the Content-Disposition field for attachments, which causes the attachment to be rendered inline by Internet Explorer when the victim clicks the download link, which facilitates cross-site scripting (XSS) and possibly other attacks.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2703

больше 21 года назад

Clearswift MIMEsweeper 5.0.5, when it has been upgraded from MAILsweeper for SMTP version 4.3 or MAILsweeper Business Suite I or II, allows remote attackers to bypass scanning by including encrypted data in a mail message, which causes the message to be marked as "Clean" instead of "Encrypted".

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2702

больше 21 года назад

Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter. NOTE: this might be the same vector as CVE-2006-6451.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2701

больше 21 года назад

Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2700

больше 21 года назад

Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx.

CVSS2: 9
EPSS: Низкий
nvd логотип

CVE-2004-2699

больше 21 года назад

deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2698

больше 21 года назад

Race condition in IMWheel 1.0.0pre11 and earlier, when running with the -k option, allows local users to cause a denial of service (IMWheel crash) and possibly modify arbitrary files via a symlink attack on the imwheel.pid file.

CVSS2: 6.9
EPSS: Низкий
nvd логотип

CVE-2004-2697

больше 21 года назад

The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a command line argument (log file). NOTE: this might be related to CVE-2006-5002.

CVSS2: 6.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-2716

Multiple SQL injection vulnerabilities in usersL.php3 in PHPMyChat 0.14.5 allow remote attackers to execute arbitrary SQL commands via the (1) sortBy, (2) sortOrder, (3) startReg, (4) U, (5) LastCheck , and (6) R parameters.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2715

edituser.php3 in PHPMyChat 0.14.5 allow remote attackers to bypass authentication and gain administrative privileges by setting the do_not_login parameter to false.

CVSS2: 7.5
5%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2714

Unspecified vulnerability in Window Maker 0.80.2 and earlier allows attackers to perform unknown actions via format string specifiers in a font specification in WMGLOBAL, probably a format string vulnerability.

CVSS2: 6
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2713

Zone Alarm Pro 1.0 through 5.1 gives full access to %windir%\Internet Logs\* to the EVERYONE group, which allows local users to cause a denial of service by modifying the folder contents or permissions. NOTE: this issue has been disputed by the vendor, who claims that it does not affect product functionality since the same information is also saved in a protected file

CVSS2: 1.9
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2712

Buffer overflow in Gyach Enhanced (Gyach-E) before 1.0.0-SneakPeek-3 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to "URL data."

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2711

Multiple buffer overflows in Gyach Enhanced (Gyach-E) before 1.0.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to "avatar retrieval."

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2710

Multiple buffer overflows in Gyach Enhanced (Gyach-E) before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) sending certain typing statuses or (2) setting the chat room status bar to the current chat room name.

CVSS2: 7.5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2709

Buffer overflow in the strip_html_tags method for Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown vectors involving HTML tags.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2708

Gyach Enhanced (Gyach-E) before 1.0.0 stores passwords in plaintext, which allows attackers to obtain user passwords by reading the configuration file.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2707

Multiple unspecified vulnerabilities in Gyach Enhanced (Gyach-E) before 1.0.5 have unknown impact and attack vectors related to "several security flaws," probably related to buffer overflows in HTTP server responses.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2706

Unspecified vulnerability in Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service (crash) via conference packets with error messages.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2705

Unspecified vulnerability in Player vs. Player Gaming Network (PvPGN) before 1.6.4 allows remote attackers to obtain attributes of arbitrary accounts, including the password hash, via certain statsreq packets.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2704

Hastymail 1.0.1 and earlier (stable) and 1.1 and earlier (development) does not send the "attachment" parameter in the Content-Disposition field for attachments, which causes the attachment to be rendered inline by Internet Explorer when the victim clicks the download link, which facilitates cross-site scripting (XSS) and possibly other attacks.

CVSS2: 4.3
5%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2703

Clearswift MIMEsweeper 5.0.5, when it has been upgraded from MAILsweeper for SMTP version 4.3 or MAILsweeper Business Suite I or II, allows remote attackers to bypass scanning by including encrypted data in a mail message, which causes the message to be marked as "Clean" instead of "Encrypted".

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2702

Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter. NOTE: this might be the same vector as CVE-2006-6451.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2701

Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2700

Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx.

CVSS2: 9
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2699

deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2698

Race condition in IMWheel 1.0.0pre11 and earlier, when running with the -k option, allows local users to cause a denial of service (IMWheel crash) and possibly modify arbitrary files via a symlink attack on the imwheel.pid file.

CVSS2: 6.9
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2697

The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a command line argument (log file). NOTE: this might be related to CVE-2006-5002.

CVSS2: 6.9
1%
Низкий
больше 21 года назад

Уязвимостей на страницу