Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 115

Количество 372 115

nvd логотип

CVE-2004-0249

больше 21 года назад

PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another userID.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0248

больше 21 года назад

Cross-site scripting vulnerability (XSS) in PHPX 3.2.3 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into (1) keywords argument of main.inc.php, (2) body argument of help.inc.php, or (3) the subject field in Personal Messages and Forum.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2004-0247

больше 21 года назад

The client and server of Chaser 1.50 and earlier allow remote attackers to cause a denial of service (crash via exception) via a UDP packet with a length field that is greater than the actual data length, which causes Chaser to read unexpected memory.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0246

больше 21 года назад

Multiple PHP remote file inclusion vulnerabilities in (1) fonctions.lib.php, (2) derniers_commentaires.php, and (3) admin.php in Les Commentaires 2.0 allow remote attackers to execute arbitrary PHP code via the rep parameter.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0245

больше 21 года назад

Web Crossing 4.x and 5.x allows remote attackers to cause a denial of service (crash) by sending a HTTP POST request with a large or negative Content-Length, which causes an integer divide-by-zero.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0244

больше 21 года назад

Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allow local users to cause a denial of service (hang or reset) by sending a layer 2 frame packet that encapsulates a layer 3 packet, but has inconsistent length values with that packet.

CVSS2: 4.7
EPSS: Низкий
nvd логотип

CVE-2004-0243

больше 21 года назад

AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0242

больше 21 года назад

X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0241

больше 21 года назад

X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0240

больше 21 года назад

Directory traversal vulnerability in X-Cart 3.4.3 allows remote attackers to view arbitrary files via a .. (dot dot) in the shop_closed_file argument to auth.php.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0239

больше 21 года назад

SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0238

больше 21 года назад

Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the client via a long HOME environment variable in the (1) load_cfg and (2) save_cfg functions; possibly allow remote attackers to execute arbitrary code via long strings to (3) the send_message function; and, in the server, via (4) the parse_command_line function.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2004-0237

больше 21 года назад

Directory traversal vulnerability in index.php in Aprox PHP Portal allows remote attackers to read arbitrary files via a full pathname in the show parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0236

больше 21 года назад

SQL injection vulnerability in login.asp in thePHOTOtool allows remote attackers to gain unauthorized access via the password field.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0235

почти 22 года назад

Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2004-0234

почти 22 года назад

Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2004-0233

почти 22 года назад

Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-0232

почти 22 года назад

Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2004-0231

почти 22 года назад

Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2004-0230

почти 22 года назад

TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.

CVSS2: 5
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2004-0249

PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another userID.

CVSS2: 10
5%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0248

Cross-site scripting vulnerability (XSS) in PHPX 3.2.3 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into (1) keywords argument of main.inc.php, (2) body argument of help.inc.php, or (3) the subject field in Personal Messages and Forum.

CVSS2: 6.8
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0247

The client and server of Chaser 1.50 and earlier allow remote attackers to cause a denial of service (crash via exception) via a UDP packet with a length field that is greater than the actual data length, which causes Chaser to read unexpected memory.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0246

Multiple PHP remote file inclusion vulnerabilities in (1) fonctions.lib.php, (2) derniers_commentaires.php, and (3) admin.php in Les Commentaires 2.0 allow remote attackers to execute arbitrary PHP code via the rep parameter.

CVSS2: 10
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0245

Web Crossing 4.x and 5.x allows remote attackers to cause a denial of service (crash) by sending a HTTP POST request with a large or negative Content-Length, which causes an integer divide-by-zero.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0244

Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allow local users to cause a denial of service (hang or reset) by sending a layer 2 frame packet that encapsulates a layer 3 packet, but has inconsistent length values with that packet.

CVSS2: 4.7
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0243

AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0242

X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command.

CVSS2: 5
7%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0241

X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php.

CVSS2: 10
6%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0240

Directory traversal vulnerability in X-Cart 3.4.3 allows remote attackers to view arbitrary files via a .. (dot dot) in the shop_closed_file argument to auth.php.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0239

SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.

CVSS2: 10
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0238

Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the client via a long HOME environment variable in the (1) load_cfg and (2) save_cfg functions; possibly allow remote attackers to execute arbitrary code via long strings to (3) the send_message function; and, in the server, via (4) the parse_command_line function.

CVSS2: 7.2
5%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0237

Directory traversal vulnerability in index.php in Aprox PHP Portal allows remote attackers to read arbitrary files via a full pathname in the show parameter.

CVSS2: 5
7%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0236

SQL injection vulnerability in login.asp in thePHOTOtool allows remote attackers to gain unauthorized access via the password field.

CVSS2: 10
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2004-0235

Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").

CVSS2: 6.4
4%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0234

Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.

CVSS2: 10
10%
Средний
почти 22 года назад
nvd логотип
CVE-2004-0233

Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.

CVSS2: 2.1
1%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0232

Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.

CVSS2: 5
3%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0231

Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."

CVSS2: 2.1
0%
Низкий
почти 22 года назад
nvd логотип
CVE-2004-0230

TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.

CVSS2: 5
80%
Высокий
почти 22 года назад

Уязвимостей на страницу