Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 328

Количество 372 328

nvd логотип

CVE-2004-1895

больше 21 года назад

YaST Online Update (YOU) in SuSE 8.2 and 9.0 allows local users to overwrite arbitrary files via a symlink attack on you-$USER/cookies.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-1894

больше 21 года назад

TEXutil in ConTEXt, when executed with the --silent option, allows local users to overwrite arbitrary files via a symlink attack on texutil.log.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-1893

больше 21 года назад

Dreamweaver MX, when "Using Driver On Testing Server" or "Using DSN on Testing Server" is selected, uploads the mmhttpdb.asp script to the web site but does not require authentication, which allows remote attackers to obtain sensitive information and possibly execute arbitrary SQL commands via a direct request to mmhttpdb.asp.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1892

больше 21 года назад

Stack-based buffer overflow in DecodeBase16 function, as used in the (1) IRC module and (2) web server in eMule 0.42d, allows remote attackers to execute arbitrary code via a long string.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2004-1891

больше 21 года назад

The ftp_syslog function in ftpd in SGI IRIX 6.5.20 "doesn't work with anonymous FTP," which has an unknown impact, possibly preventing the actions of anonymous users from being logged.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1890

больше 22 лет назад

Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via the PORT mode.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1889

больше 21 года назад

Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via a link failure with Microsoft Windows.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1888

больше 21 года назад

display.cgi in Aborior Encore WebForum allows remote to execute arbitrary commands via shell metacharacters in the file variable.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1887

больше 21 года назад

Ada Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a trailing %00 (null).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1886

больше 22 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-1848. Reason: This candidate is a duplicate of CVE-2004-1848. Notes: All CVE users should reference CVE-2004-1848 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий
nvd логотип

CVE-2004-1885

больше 21 года назад

Ipswitch WS_FTP Server 4.0.2 allows remote authenticated users to execute arbitrary programs as SYSTEM by using the SITE command to modify certain iFtpSvc options that are handled by iftpmgr.exe.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-1884

больше 22 лет назад

Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1883

больше 21 года назад

Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code by causing a large error string to be generated by the ALLO handler, or (2) may allow remote FTP administrators to execute arbitrary code by causing a long hostname or username to be inserted into a reply to a STAT command while a file is being transferred.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-1882

больше 21 года назад

Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or HTML via the strImageTag parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1881

больше 21 года назад

SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via the strItems parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1880

больше 21 года назад

Memory leak in the back-bdb backend for OpenLDAP 2.1.12 and earlier allows remote attackers to cause a denial of service (memory consumption).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1879

больше 21 года назад

Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HTML via forum messages.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1878

больше 22 лет назад

LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl preceded by // (double leading slash).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1877

больше 22 лет назад

The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2004-1876

больше 22 лет назад

The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.

CVSS2: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-1895

YaST Online Update (YOU) in SuSE 8.2 and 9.0 allows local users to overwrite arbitrary files via a symlink attack on you-$USER/cookies.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1894

TEXutil in ConTEXt, when executed with the --silent option, allows local users to overwrite arbitrary files via a symlink attack on texutil.log.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1893

Dreamweaver MX, when "Using Driver On Testing Server" or "Using DSN on Testing Server" is selected, uploads the mmhttpdb.asp script to the web site but does not require authentication, which allows remote attackers to obtain sensitive information and possibly execute arbitrary SQL commands via a direct request to mmhttpdb.asp.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1892

Stack-based buffer overflow in DecodeBase16 function, as used in the (1) IRC module and (2) web server in eMule 0.42d, allows remote attackers to execute arbitrary code via a long string.

CVSS2: 7.5
10%
Средний
больше 21 года назад
nvd логотип
CVE-2004-1891

The ftp_syslog function in ftpd in SGI IRIX 6.5.20 "doesn't work with anonymous FTP," which has an unknown impact, possibly preventing the actions of anonymous users from being logged.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1890

Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via the PORT mode.

CVSS2: 5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1889

Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via a link failure with Microsoft Windows.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1888

display.cgi in Aborior Encore WebForum allows remote to execute arbitrary commands via shell metacharacters in the file variable.

CVSS2: 7.5
9%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1887

Ada Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a trailing %00 (null).

CVSS2: 5
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1886

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-1848. Reason: This candidate is a duplicate of CVE-2004-1848. Notes: All CVE users should reference CVE-2004-1848 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

больше 22 лет назад
nvd логотип
CVE-2004-1885

Ipswitch WS_FTP Server 4.0.2 allows remote authenticated users to execute arbitrary programs as SYSTEM by using the SITE command to modify certain iFtpSvc options that are handled by iftpmgr.exe.

CVSS2: 7.2
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1884

Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access.

CVSS2: 7.5
6%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1883

Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code by causing a large error string to be generated by the ALLO handler, or (2) may allow remote FTP administrators to execute arbitrary code by causing a long hostname or username to be inserted into a reply to a STAT command while a file is being transferred.

CVSS2: 7.2
5%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1882

Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or HTML via the strImageTag parameter.

CVSS2: 4.3
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1881

SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via the strItems parameter.

CVSS2: 7.5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1880

Memory leak in the back-bdb backend for OpenLDAP 2.1.12 and earlier allows remote attackers to cause a denial of service (memory consumption).

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1879

Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HTML via forum messages.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1878

LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl preceded by // (double leading slash).

CVSS2: 5
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1877

The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.

CVSS2: 2.6
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2004-1876

The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.

CVSS2: 4.6
1%
Низкий
больше 22 лет назад

Уязвимостей на страницу