Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 328

Количество 372 328

nvd логотип

CVE-2004-1996

около 22 лет назад

Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size tag.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1995

больше 21 года назад

Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2004-1994

около 22 лет назад

FuseTalk 4.0 allows remote attackers to ban other users via a direct request to banning.cfm.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1993

около 22 лет назад

The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as "`" (backticks) in the password.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-1992

больше 22 лет назад

Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-1991

около 22 лет назад

Directory traversal vulnerability in Aldo's Web Server (aweb) 1.5 allows remote attackers to view arbitrary files via a .. (dot dot) in an HTTP GET request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1990

больше 22 лет назад

Aldo's Web Server (aweb) 1.5 allows remote attackers to gain sensitive information via an arbitrary character, which reveals the full path and the user running the aweb process, possibly due to a malformed request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1989

больше 22 лет назад

PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modifying the THEME_DIR parameter to reference a URL on a remote web server that contains user_list_info_box.inc.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1988

больше 22 лет назад

PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by modifying the CPG_M_DIR to reference a URL on a remote web server that contains functions.inc.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1987

больше 22 лет назад

picmgmtbatch.inc.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to execute arbitrary commands via shell metacharacters in the (1) $CONFIG['impath'] or (2) $CONFIG['jpeg_qual'] parameters.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2004-1986

больше 22 лет назад

Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the startdir parameter.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-1985

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1984

больше 22 лет назад

Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) phpinfo.php, (2) addpic.php, (3) config.php, (4) db_input.php, (5) displayecard.php, (6) ecard.php, (7) crop.inc.php, which reveal the full path in a PHP error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1983

больше 22 лет назад

The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local users to cause a denial of service (infinite loop) via unknown attack vectors.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-1982

около 22 лет назад

Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subject field.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1981

больше 22 лет назад

The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting reports without retrieving the associated image files, which are not cleared from the image file folder.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1980

больше 22 лет назад

Directory traversal vulnerability in glossary.php in PROPS 0.6.1 allows remote attackers to view arbitrary files via a .. (dot dot) in (1) module or (2) format variables.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1979

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in do_search.php in PROPS 0.6.1 allows remote attackers to inject arbitrary HTML or web script via the search_string parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1978

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script via the text parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1977

больше 22 лет назад

3com NBX IP VOIP NetSet Configuration Manager allows remote attackers to cause a denial of service (crash) via a Nessus scan in safeChecks mode.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-1996

Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size tag.

CVSS2: 4.3
2%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-1995

Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.

CVSS3: 6.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1994

FuseTalk 4.0 allows remote attackers to ban other users via a direct request to banning.cfm.

CVSS2: 5
2%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-1993

The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such as "`" (backticks) in the password.

CVSS2: 10
5%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-1992

Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read.

CVSS2: 5
11%
Средний
больше 22 лет назад
nvd логотип
CVE-2004-1991

Directory traversal vulnerability in Aldo's Web Server (aweb) 1.5 allows remote attackers to view arbitrary files via a .. (dot dot) in an HTTP GET request.

CVSS2: 5
3%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-1990

Aldo's Web Server (aweb) 1.5 allows remote attackers to gain sensitive information via an arbitrary character, which reveals the full path and the user running the aweb process, possibly due to a malformed request.

CVSS2: 5
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1989

PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modifying the THEME_DIR parameter to reference a URL on a remote web server that contains user_list_info_box.inc.

CVSS2: 7.5
9%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1988

PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by modifying the CPG_M_DIR to reference a URL on a remote web server that contains functions.inc.php.

CVSS2: 7.5
9%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1987

picmgmtbatch.inc.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to execute arbitrary commands via shell metacharacters in the (1) $CONFIG['impath'] or (2) $CONFIG['jpeg_qual'] parameters.

CVSS2: 7.5
10%
Средний
больше 22 лет назад
nvd логотип
CVE-2004-1986

Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the startdir parameter.

CVSS2: 5
11%
Средний
больше 22 лет назад
nvd логотип
CVE-2004-1985

Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter.

CVSS2: 4.3
4%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1984

Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) phpinfo.php, (2) addpic.php, (3) config.php, (4) db_input.php, (5) displayecard.php, (6) ecard.php, (7) crop.inc.php, which reveal the full path in a PHP error message.

CVSS2: 5
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1983

The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local users to cause a denial of service (infinite loop) via unknown attack vectors.

CVSS2: 2.1
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1982

Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subject field.

CVSS2: 5
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2004-1981

The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting reports without retrieving the associated image files, which are not cleared from the image file folder.

CVSS2: 5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1980

Directory traversal vulnerability in glossary.php in PROPS 0.6.1 allows remote attackers to view arbitrary files via a .. (dot dot) in (1) module or (2) format variables.

CVSS2: 5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1979

Cross-site scripting (XSS) vulnerability in do_search.php in PROPS 0.6.1 allows remote attackers to inject arbitrary HTML or web script via the search_string parameter.

CVSS2: 4.3
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1978

Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script via the text parameter.

CVSS2: 4.3
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1977

3com NBX IP VOIP NetSet Configuration Manager allows remote attackers to cause a denial of service (crash) via a Nessus scan in safeChecks mode.

CVSS2: 5
3%
Низкий
больше 22 лет назад

Уязвимостей на страницу