Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 115

Количество 372 115

nvd логотип

CVE-2004-1661

почти 22 года назад

MailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains "auth=1" and "uId=1."

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1660

почти 22 года назад

PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath parameter to (1) show_archives.php or (2) show_news.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1659

почти 22 года назад

Cross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Administrator, Editor, Journalist or Commenter privileges to inject arbitrary web script or HTML via the mod parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1658

почти 22 года назад

Kerio Personal Firewall 4.0 (KPF4) allows local users with administrative privileges to bypass the Application Security feature and execute arbitrary processes by directly writing to \device\physicalmemory to restore the running kernel's SDT ServiceTable.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2004-1657

почти 22 года назад

Cross-site scripting (XSS) vulnerability in the Activity and Events Viewer for Newtelligence DasBlog allows remote attackers to inject arbitrary web script or HTML via the (1) User Agent or (2) Referrer HTTP headers.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1656

почти 22 года назад

CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1655

почти 22 года назад

Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) CM_pid parameter in the comments module or (2) the subject or message fields in the notes module.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1654

почти 22 года назад

SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commands via cal_template.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1653

почти 22 года назад

The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS.

CVSS2: 6.4
EPSS: Средний
nvd логотип

CVE-2004-1652

почти 22 года назад

phpScheduleIt 1.0.0 RC1 does not clear administrative privileges if the administrator logs in as a normal user, which allows users with physical access to gain administrative privileges.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1651

почти 22 года назад

Multiple cross-site scripting (XSS) vulnerabilities in the registration page in phpScheduleIt 1.0.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Lastname fields during new user registration, or (3) the Schedule Name field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1650

почти 22 года назад

D-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the IP address of the camera via a UDP broadcast packet.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1649

почти 22 года назад

Buffer overflow in Microsoft Msinfo32.exe might allow local users to execute arbitrary code via a long filename in the msinfo_file command line parameter. NOTE: this issue might not cross security boundaries, so it may be REJECTED in the future.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-1648

почти 22 года назад

Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1647

почти 22 года назад

SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, OPass, or NPass to CPassChangePassword.asp, (3) users_edit.asp, or (4) users_add.asp.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1646

почти 22 года назад

Directory traversal vulnerability in Xedus 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1645

почти 22 года назад

Cross-site scripting (XSS) vulnerability in Xedus 1.0 allows remote attackers to execute arbitrary web script or HTML via the (1) username parameter to test.x, (2) username parameter to TestServer.x, or (3) param parameter to testgetrequest.x.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1644

почти 22 года назад

Xedus 1.0 allows remote attackers to cause a denial of service (refuse connections) by connecting multiple times from the same IP address.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1643

почти 22 года назад

WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that contains an invalid path with a "../" sequence.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1642

почти 22 года назад

WFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST commands.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-1661

MailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains "auth=1" and "uId=1."

CVSS2: 7.5
3%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1660

PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath parameter to (1) show_archives.php or (2) show_news.php.

CVSS2: 7.5
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1659

Cross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Administrator, Editor, Journalist or Commenter privileges to inject arbitrary web script or HTML via the mod parameter.

CVSS2: 4.3
4%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1658

Kerio Personal Firewall 4.0 (KPF4) allows local users with administrative privileges to bypass the Application Security feature and execute arbitrary processes by directly writing to \device\physicalmemory to restore the running kernel's SDT ServiceTable.

CVSS2: 4.6
1%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1657

Cross-site scripting (XSS) vulnerability in the Activity and Events Viewer for Newtelligence DasBlog allows remote attackers to inject arbitrary web script or HTML via the (1) User Agent or (2) Referrer HTTP headers.

CVSS2: 4.3
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1656

CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter.

CVSS2: 5
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1655

Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) CM_pid parameter in the comments module or (2) the subject or message fields in the notes module.

CVSS2: 4.3
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1654

SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commands via cal_template.

CVSS2: 7.5
1%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1653

The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS.

CVSS2: 6.4
12%
Средний
почти 22 года назад
nvd логотип
CVE-2004-1652

phpScheduleIt 1.0.0 RC1 does not clear administrative privileges if the administrator logs in as a normal user, which allows users with physical access to gain administrative privileges.

CVSS2: 7.5
1%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1651

Multiple cross-site scripting (XSS) vulnerabilities in the registration page in phpScheduleIt 1.0.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Lastname fields during new user registration, or (3) the Schedule Name field.

CVSS2: 4.3
1%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1650

D-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the IP address of the camera via a UDP broadcast packet.

CVSS2: 7.5
3%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1649

Buffer overflow in Microsoft Msinfo32.exe might allow local users to execute arbitrary code via a long filename in the msinfo_file command line parameter. NOTE: this issue might not cross security boundaries, so it may be REJECTED in the future.

CVSS2: 7.2
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1648

Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter.

CVSS2: 4.3
1%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1647

SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, OPass, or NPass to CPassChangePassword.asp, (3) users_edit.asp, or (4) users_add.asp.

CVSS2: 7.5
1%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1646

Directory traversal vulnerability in Xedus 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

CVSS2: 5
7%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1645

Cross-site scripting (XSS) vulnerability in Xedus 1.0 allows remote attackers to execute arbitrary web script or HTML via the (1) username parameter to test.x, (2) username parameter to TestServer.x, or (3) param parameter to testgetrequest.x.

CVSS2: 4.3
4%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1644

Xedus 1.0 allows remote attackers to cause a denial of service (refuse connections) by connecting multiple times from the same IP address.

CVSS2: 5
2%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1643

WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that contains an invalid path with a "../" sequence.

CVSS2: 5
8%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-1642

WFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST commands.

CVSS2: 5
3%
Низкий
почти 22 года назад

Уязвимостей на страницу