Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 328

Количество 372 328

nvd логотип

CVE-2004-2056

больше 21 года назад

SQL injection vulnerability in action.php in Nucleus CMS 3.01 allows remote attackers to execute arbitrary SQL statements via the itemid parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2055

около 22 лет назад

Cross-site scripting (XSS) vulnerability in search.php for PhpBB 2.0.4 and 2.0.9 allows remote attackers to inject arbitrary HTMl or web script via the search_author parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2054

больше 21 года назад

CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via (1) the mode parameter to privmsg.php or (2) the redirect parameter to login.php.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2053

около 22 лет назад

PHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitrary PHP code via the site parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2052

больше 21 года назад

eSeSIX Thintune thin clients running firmware 2.4.38 and earlier accept any password that begins with the actual password, which makes it easier for users to conduct brute force password guessing.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2051

около 22 лет назад

The Phoenix browser in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allows local users to read arbitrary files via a file:/// URL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2050

больше 21 года назад

eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allow local users to gain privileges by pressing CTRL-SHIFT-ALT-DEL and entering the "maertsJ" password, which is hard-coded into lshell.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-2049

больше 21 года назад

eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain access.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-2048

больше 21 года назад

radmin in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier starts a process port 25072 that can be accessed with a default "jstwo" password, which allows remote attackers to gain access.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-2047

около 22 лет назад

Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the pathext parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2046

больше 21 года назад

Unknown vulnerability in APC PowerChute Business Edition 6.0 through 7.0.1 allows remote attackers to cause a denial of service via unknown attack vectors.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2045

больше 21 года назад

The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of service (device reboot) via an HTTP request with a long username.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2044

около 22 лет назад

PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER['PHP_SELF'] to identify the calling script, which allows remote attackers to directly access scripts, obtain path information via a PHP error message, and possibly gain access, as demonstrated using an HTTP request that contains the "admin.php" string.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2004-2043

больше 22 лет назад

Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows remote attackers to cause a denial of service (crash) via a long database name, as demonstrated using the gsec command.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-2042

около 22 лет назад

Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via (1) content parameter to content.php, (2) content_id parameter to content.php, or (3) list parameter to news.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2041

около 22 лет назад

PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modifying the p parameter to reference a URL on a remote web server that contains the code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-2040

около 22 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 parameter to clock_menu.php, (2) "email article to a friend" field, (3) "submit news" field, or (4) avmsg parameter to usersettings.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2039

около 22 лет назад

e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php, (4) counter_menu.php, (5) login_menu.php, and other files, which reveal the full path in a PHP error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-2038

около 22 лет назад

Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a BBcode img tag in (1) functions.php, (2) header.php or (3) auth.inc.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-2037

больше 22 лет назад

Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long CWD command, as demonstrated in one example by using the "cd" command in an interactive FTP client.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-2056

SQL injection vulnerability in action.php in Nucleus CMS 3.01 allows remote attackers to execute arbitrary SQL statements via the itemid parameter.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2055

Cross-site scripting (XSS) vulnerability in search.php for PhpBB 2.0.4 and 2.0.9 allows remote attackers to inject arbitrary HTMl or web script via the search_author parameter.

CVSS2: 4.3
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-2054

CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via (1) the mode parameter to privmsg.php or (2) the redirect parameter to login.php.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2053

PHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitrary PHP code via the site parameter.

CVSS2: 7.5
3%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-2052

eSeSIX Thintune thin clients running firmware 2.4.38 and earlier accept any password that begins with the actual password, which makes it easier for users to conduct brute force password guessing.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2051

The Phoenix browser in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allows local users to read arbitrary files via a file:/// URL.

CVSS2: 5
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-2050

eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allow local users to gain privileges by pressing CTRL-SHIFT-ALT-DEL and entering the "maertsJ" password, which is hard-coded into lshell.

CVSS2: 4.6
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2049

eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain access.

CVSS2: 4.6
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2048

radmin in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier starts a process port 25072 that can be accessed with a default "jstwo" password, which allows remote attackers to gain access.

CVSS2: 10
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2047

Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the pathext parameter.

CVSS2: 5
8%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-2046

Unknown vulnerability in APC PowerChute Business Edition 6.0 through 7.0.1 allows remote attackers to cause a denial of service via unknown attack vectors.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2045

The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of service (device reboot) via an HTTP request with a long username.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-2044

PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER['PHP_SELF'] to identify the calling script, which allows remote attackers to directly access scripts, obtain path information via a PHP error message, and possibly gain access, as demonstrated using an HTTP request that contains the "admin.php" string.

CVSS2: 7.5
11%
Средний
около 22 лет назад
nvd логотип
CVE-2004-2043

Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows remote attackers to cause a denial of service (crash) via a long database name, as demonstrated using the gsec command.

CVSS2: 5
12%
Средний
больше 22 лет назад
nvd логотип
CVE-2004-2042

Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via (1) content parameter to content.php, (2) content_id parameter to content.php, or (3) list parameter to news.php.

CVSS2: 7.5
2%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-2041

PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modifying the p parameter to reference a URL on a remote web server that contains the code.

CVSS2: 7.5
2%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-2040

Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 parameter to clock_menu.php, (2) "email article to a friend" field, (3) "submit news" field, or (4) avmsg parameter to usersettings.php.

CVSS2: 4.3
5%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-2039

e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php, (4) counter_menu.php, (5) login_menu.php, and other files, which reveal the full path in a PHP error message.

CVSS2: 5
2%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-2038

Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a BBcode img tag in (1) functions.php, (2) header.php or (3) auth.inc.php.

CVSS2: 4.3
3%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-2037

Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long CWD command, as demonstrated in one example by using the "cd" command in an interactive FTP client.

CVSS2: 7.5
7%
Низкий
больше 22 лет назад

Уязвимостей на страницу