Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 328

Количество 372 328

nvd логотип

CVE-2004-2076

больше 21 года назад

Cross-site scripting (XSS) vulnerability in search.php for Jelsoft vBulletin 3.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2075

больше 21 года назад

Sophos Anti-Virus 3.78 allows remote attackers to cause a denial of service (infinite loop) via a MIME header that is not properly terminated.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2074

больше 21 года назад

Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-2073

больше 22 лет назад

Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server via a modified chroot-again exploit using the chmod command.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-2072

больше 21 года назад

Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-2071

больше 21 года назад

Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authentication in the web interface via an HTTP GET request with two slashes ("//") after the server name.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2070

больше 21 года назад

The Altiris Client Service for Windows 5.6 SP1 Hotfix E (5.6.181) allows local users to execute arbitrary commands by opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2005-1590.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-2069

больше 21 года назад

sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceeding the LoginGraceTime setting, which leaves the connection open and allows remote attackers to cause a denial of service (connection consumption).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2068

больше 21 года назад

fetchnews in leafnode 1.9.47 and earlier allows remote attackers to cause a denial of service (process hang) via an empty NNTP news article with missing mandatory headers.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2067

около 22 лет назад

SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2066

около 22 лет назад

SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and bypass authentication via the (1) linpha_userid or (2) linpha_password cookies.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2065

больше 21 года назад

DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension or . in the filename.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2064

около 22 лет назад

Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web script via the (1) Email or (2) Website fields.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2063

больше 21 года назад

Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inject arbitrary HTML or web script via the feedback parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2062

больше 21 года назад

SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2) parent_id, or (3) mode parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2061

около 22 лет назад

RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2004-2060

больше 21 года назад

ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2059

больше 21 года назад

Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SearchFor parameter in [TABLE-NAME]_search.asp, (2) SQL parameter in [TABLE-NAME]_edit.asp, (3) SearchFor parameter in [TABLE]_list.asp, or (4) SQL parameter in export.asp.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2058

больше 21 года назад

ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2057

больше 21 года назад

SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-2076

Cross-site scripting (XSS) vulnerability in search.php for Jelsoft vBulletin 3.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2075

Sophos Anti-Virus 3.78 allows remote attackers to cause a denial of service (infinite loop) via a MIME header that is not properly terminated.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2074

Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands.

CVSS2: 5
36%
Средний
больше 21 года назад
nvd логотип
CVE-2004-2073

Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server via a modified chroot-again exploit using the chmod command.

CVSS2: 7.2
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-2072

Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter.

CVSS2: 6.8
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2071

Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authentication in the web interface via an HTTP GET request with two slashes ("//") after the server name.

CVSS2: 7.5
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2070

The Altiris Client Service for Windows 5.6 SP1 Hotfix E (5.6.181) allows local users to execute arbitrary commands by opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2005-1590.

CVSS2: 7.2
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2069

sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceeding the LoginGraceTime setting, which leaves the connection open and allows remote attackers to cause a denial of service (connection consumption).

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2068

fetchnews in leafnode 1.9.47 and earlier allows remote attackers to cause a denial of service (process hang) via an empty NNTP news article with missing mandatory headers.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2067

SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.

CVSS2: 7.5
3%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-2066

SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and bypass authentication via the (1) linpha_userid or (2) linpha_password cookies.

CVSS2: 7.5
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-2065

DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension or . in the filename.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2064

Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web script via the (1) Email or (2) Website fields.

CVSS2: 4.3
2%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-2063

Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inject arbitrary HTML or web script via the feedback parameter.

CVSS2: 4.3
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2062

SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2) parent_id, or (3) mode parameters.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2061

RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.

CVSS3: 9.8
6%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-2060

ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.

CVSS2: 5
8%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2059

Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SearchFor parameter in [TABLE-NAME]_search.asp, (2) SQL parameter in [TABLE-NAME]_edit.asp, (3) SearchFor parameter in [TABLE]_list.asp, or (4) SQL parameter in export.asp.

CVSS2: 5
9%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2058

ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2057

SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements.

CVSS2: 7.5
2%
Низкий
больше 21 года назад

Уязвимостей на страницу