Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 115

Количество 372 115

nvd логотип

CVE-2004-1581

больше 21 года назад

BlackBoard 1.5.1 allows remote attackers to gain sensitive information via a direct request to (1) checkdb.inc.php, (2) admin.inc.php or (3) cp.inc.php, which reveals the path in a PHP error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1580

больше 21 года назад

SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1579

больше 21 года назад

index.php in CubeCart 2.0.1 allows remote attackers to gain sensitive information via an HTTP request with an invalid cat_id parameter, which reveals the full path in a PHP error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1578

больше 21 года назад

Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1577

больше 21 года назад

index.php in PHP Links allows remote attackers to gain sensitive information via an invalid show parameter, which reveals the full path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1576

больше 21 года назад

Format string vulnerability in Judge Dredd: Dredd vs. Death 1.01 and earlier allows remote attackers to cause a denial of service (application crash) via format string specifiers in a chat message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1575

больше 21 года назад

The XML parser in Xerces-C++ 2.5.0 allows remote attackers to cause a denial of service (CPU consumption) via XML attributes in a crafted XML document.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1574

больше 21 года назад

Buffer overflow in Vypress Messenger 3.5.1 and earlier allows remote attackers to execute arbitrary code via a message with a long first field.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1573

больше 21 года назад

The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbitrary PHP code and gain privileges as the administrator.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-1572

больше 21 года назад

AJ-Fork 167 does not restrict access to directories such as (1) data, (2) inc, (3) plugins, (4) skins, or (5) tools, which allows remote attackers to list files in those directories via a direct HTTP request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1571

больше 21 года назад

AJ-Fork 167 allows remote attackers to gain sensitive information via a direct request to (1) auto-acronyms.php, (2) auto-archive.php, (3) ount-article-views.php, (4) kses.php, (5) custom-quick-tags.php, (6) disable-all-comments.php, (7) easy-date-format.php, (8) enable-disable-comments.php, (9) filter-by-author.php, (10) format-switcher.php, (11) long-to-short.php, (12) prospective-posting.php, or (13) sort-by-xfield.php, which displays the full path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1570

больше 21 года назад

SQL injection vulnerability in bBlog 0.7.2 and 0.7.3 allows remote attackers to execute arbitrary SQL commands via the p parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1569

больше 21 года назад

Buffer overflow in (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe in dBpowerAMP Audio Player 2.0 and dbPowerAmp Music Converter 10.0 allows remote attackers to cause a denial of service or execute arbitrary code via a .pls or .m3u playlist that contains long File1 (filename) fields.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2004-1568

больше 21 года назад

Directory traversal vulnerability in ParaChat Server 5.5 allows remote attackers to read arbitrary files via a ..%5C (hex-encoded dot dot) in the URL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1567

больше 21 года назад

profile.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to gain privileges by setting the mail parameter to 1, which is the value for an administrator.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-1566

больше 21 года назад

Cross-site scripting (XSS) vulnerability in index.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to execute arbitrary web script or HTML via the module parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1565

больше 21 года назад

list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1564

больше 21 года назад

CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the thread parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-1563

больше 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web script or HTML via the (1) thread parameter to download_thread.php, (2) loginuser parameter to login.php, or (3) userid parameter to forgot_password.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2004-1562

больше 21 года назад

SQL injection vulnerability in redir_url.php in w-Agora 4.1.6a allows remote attackers to execute arbitrary SQL commands via the key parameter.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-1581

BlackBoard 1.5.1 allows remote attackers to gain sensitive information via a direct request to (1) checkdb.inc.php, (2) admin.inc.php or (3) cp.inc.php, which reveals the path in a PHP error message.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1580

SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1579

index.php in CubeCart 2.0.1 allows remote attackers to gain sensitive information via an HTTP request with an invalid cat_id parameter, which reveals the full path in a PHP error message.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1578

Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1577

index.php in PHP Links allows remote attackers to gain sensitive information via an invalid show parameter, which reveals the full path in an error message.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1576

Format string vulnerability in Judge Dredd: Dredd vs. Death 1.01 and earlier allows remote attackers to cause a denial of service (application crash) via format string specifiers in a chat message.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1575

The XML parser in Xerces-C++ 2.5.0 allows remote attackers to cause a denial of service (CPU consumption) via XML attributes in a crafted XML document.

CVSS2: 5
6%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1574

Buffer overflow in Vypress Messenger 3.5.1 and earlier allows remote attackers to execute arbitrary code via a message with a long first field.

CVSS2: 7.5
5%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1573

The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbitrary PHP code and gain privileges as the administrator.

CVSS2: 7.2
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1572

AJ-Fork 167 does not restrict access to directories such as (1) data, (2) inc, (3) plugins, (4) skins, or (5) tools, which allows remote attackers to list files in those directories via a direct HTTP request.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1571

AJ-Fork 167 allows remote attackers to gain sensitive information via a direct request to (1) auto-acronyms.php, (2) auto-archive.php, (3) ount-article-views.php, (4) kses.php, (5) custom-quick-tags.php, (6) disable-all-comments.php, (7) easy-date-format.php, (8) enable-disable-comments.php, (9) filter-by-author.php, (10) format-switcher.php, (11) long-to-short.php, (12) prospective-posting.php, or (13) sort-by-xfield.php, which displays the full path in an error message.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1570

SQL injection vulnerability in bBlog 0.7.2 and 0.7.3 allows remote attackers to execute arbitrary SQL commands via the p parameter.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1569

Buffer overflow in (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe in dBpowerAMP Audio Player 2.0 and dbPowerAmp Music Converter 10.0 allows remote attackers to cause a denial of service or execute arbitrary code via a .pls or .m3u playlist that contains long File1 (filename) fields.

CVSS2: 4
5%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1568

Directory traversal vulnerability in ParaChat Server 5.5 allows remote attackers to read arbitrary files via a ..%5C (hex-encoded dot dot) in the URL.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1567

profile.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to gain privileges by setting the mail parameter to 1, which is the value for an administrator.

CVSS2: 7.5
7%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1566

Cross-site scripting (XSS) vulnerability in index.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to execute arbitrary web script or HTML via the module parameter.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1565

list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1564

CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the thread parameter.

CVSS2: 5
6%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1563

Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web script or HTML via the (1) thread parameter to download_thread.php, (2) loginuser parameter to login.php, or (3) userid parameter to forgot_password.php.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-1562

SQL injection vulnerability in redir_url.php in w-Agora 4.1.6a allows remote attackers to execute arbitrary SQL commands via the key parameter.

CVSS2: 7.5
1%
Низкий
больше 21 года назад

Уязвимостей на страницу