Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 328

Количество 372 328

nvd логотип

CVE-2004-1956

больше 22 лет назад

PostNuke 0.7.2.6 allows remote attackers to gain information via a direct HTTP request to files in the (1) includes/blocks directory, (2) pnadodb directory, (3) NS-NewUser module, (4) NS-Your_Account, (5) NS-LostPassword module, or (6) NS-User module which reveals the path to the web server in a PHP error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1955

больше 21 года назад

SQL injection vulnerability in modules.php in phProfession 2.5 allows remote attackers to execute arbitrary SQL code via the offset parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1954

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML via the jcode parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1953

больше 21 года назад

phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1952

больше 22 лет назад

SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1951

больше 21 года назад

xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1950

больше 22 лет назад

phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1949

больше 21 года назад

SQL injection vulnerability in PostNuke 7.2.6 and earlier allows remote attackers to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset parameter to changeinfo.php in the Your_Account module.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1948

больше 22 лет назад

NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which displays the URL in the process list.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-1947

больше 22 лет назад

The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or (2) use the RequestFile method to download and execute arbitrary code via an object codebase that uses bitdefender.cab.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1946

больше 22 лет назад

Format string vulnerability in the PRINT_ERROR function in common.c for Cherokee Web Server 0.4.16 and earlier allows local users to execute arbitrary code via format string specifiers in the -C command line argument. NOTE: it is not clear whether this issue could be exploited remotely, or if Cherokee is running at escalated privileges. Therefore it might not be a vulnerability.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-1945

больше 22 лет назад

Buffer overflow in Kinesphere eXchange POP3 allows remote attackers to execute arbitrary code via a long MAIL FROM field.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1944

больше 22 лет назад

Eudora 6.1 and 6.0.3 for Windows allows remote attackers to cause a denial of service (crash) via a deeply nested multipart MIME message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1943

больше 22 лет назад

PHP remote file inclusion vulnerability in album_portal.php in phpBB modified by Przemo 1.8 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1942

больше 22 лет назад

The Solaris 9 patches 113579-02 through 113579-05, and 114342-02 through 114342-05, prevent ypserv and ypxfrd from properly restricting access to secure NIS maps, which allows local users to use ypcat or ypmatch to extract the contents of a secure map such as passwd.adjunct.byname.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1941

больше 22 лет назад

Fastream NETFile FTP/Web Server 6.5.1.980 allows remote attackers to cause a denial of service via a username that does not exist.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1940

больше 21 года назад

sipclient.cpp in KPhone 4.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a STUN response packet with a large attrLen value that causes an out-of-bounds read.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1939

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows remote attackers to inject arbitrary web script or HTML via double encoded slashes (%252F) in the key parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1938

больше 22 лет назад

SQL injection vulnerability in userlogin.php in Phorum 3.4.7 allows remote attackers to execute arbitrary SQL commands via doubly hex-encoded characters such as "%2527", which is translated to "'", as demonstrated using the phorum_uriauth parameter to list.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1937

больше 21 года назад

Multiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote attackers to read or include arbitrary files via .. sequences in (1) the user_langue parameter to index.php or (2) the langue parameter to update.php, or modify arbitrary GLOBAL variables by causing globals.php to be loaded before conf.inc.php via (3) .. sequences in the file parameter with the page parameter set to globals, or (4) ../globals.php in the user_langue parameter, as demonstrated by modifying $nuked[prefix] in the Suggest module.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-1956

PostNuke 0.7.2.6 allows remote attackers to gain information via a direct HTTP request to files in the (1) includes/blocks directory, (2) pnadodb directory, (3) NS-NewUser module, (4) NS-Your_Account, (5) NS-LostPassword module, or (6) NS-User module which reveals the path to the web server in a PHP error message.

CVSS2: 5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1955

SQL injection vulnerability in modules.php in phProfession 2.5 allows remote attackers to execute arbitrary SQL code via the offset parameter.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1954

Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML via the jcode parameter.

CVSS2: 4.3
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1953

phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error message.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1952

SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password.

CVSS2: 7.5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1951

xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link.

CVSS2: 5
8%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1950

phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1949

SQL injection vulnerability in PostNuke 7.2.6 and earlier allows remote attackers to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset parameter to changeinfo.php in the Your_Account module.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1948

NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which displays the URL in the process list.

CVSS2: 4.6
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1947

The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or (2) use the RequestFile method to download and execute arbitrary code via an object codebase that uses bitdefender.cab.

CVSS2: 5
7%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1946

Format string vulnerability in the PRINT_ERROR function in common.c for Cherokee Web Server 0.4.16 and earlier allows local users to execute arbitrary code via format string specifiers in the -C command line argument. NOTE: it is not clear whether this issue could be exploited remotely, or if Cherokee is running at escalated privileges. Therefore it might not be a vulnerability.

CVSS2: 4.6
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1945

Buffer overflow in Kinesphere eXchange POP3 allows remote attackers to execute arbitrary code via a long MAIL FROM field.

CVSS2: 7.5
7%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1944

Eudora 6.1 and 6.0.3 for Windows allows remote attackers to cause a denial of service (crash) via a deeply nested multipart MIME message.

CVSS2: 5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1943

PHP remote file inclusion vulnerability in album_portal.php in phpBB modified by Przemo 1.8 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.

CVSS2: 7.5
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1942

The Solaris 9 patches 113579-02 through 113579-05, and 114342-02 through 114342-05, prevent ypserv and ypxfrd from properly restricting access to secure NIS maps, which allows local users to use ypcat or ypmatch to extract the contents of a secure map such as passwd.adjunct.byname.

CVSS2: 7.5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1941

Fastream NETFile FTP/Web Server 6.5.1.980 allows remote attackers to cause a denial of service via a username that does not exist.

CVSS2: 5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1940

sipclient.cpp in KPhone 4.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a STUN response packet with a large attrLen value that causes an out-of-bounds read.

CVSS2: 5
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1939

Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows remote attackers to inject arbitrary web script or HTML via double encoded slashes (%252F) in the key parameter.

CVSS2: 4.3
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1938

SQL injection vulnerability in userlogin.php in Phorum 3.4.7 allows remote attackers to execute arbitrary SQL commands via doubly hex-encoded characters such as "%2527", which is translated to "'", as demonstrated using the phorum_uriauth parameter to list.php.

CVSS2: 7.5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1937

Multiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote attackers to read or include arbitrary files via .. sequences in (1) the user_langue parameter to index.php or (2) the langue parameter to update.php, or modify arbitrary GLOBAL variables by causing globals.php to be loaded before conf.inc.php via (3) .. sequences in the file parameter with the page parameter set to globals, or (4) ../globals.php in the user_langue parameter, as demonstrated by modifying $nuked[prefix] in the Suggest module.

CVSS2: 5
8%
Низкий
больше 21 года назад

Уязвимостей на страницу