|
313851
|
5.1 |
MEDIUM
|
microsoft
|
windows_xp windows_server_2003
|
Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not qu…
|
CWE-88
Argument Injection
|
CVE-2003-0907
|
2024-02-14 03:00 |
2004-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313852
|
7.5 |
HIGH
|
microsoft
|
outlook office
|
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers…
|
CWE-88
Argument Injection
|
CVE-2004-0121
|
2024-02-14 03:00 |
2004-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313853
|
7.5 |
HIGH
|
php openpkg
|
php openpkg
|
Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th…
|
CWE-88
Argument Injection
|
CVE-2002-0985
|
2024-02-14 03:00 |
2002-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313854
|
7.5 |
HIGH
|
microsoft
|
internet_explorer
|
Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command …
|
CWE-88
Argument Injection
|
CVE-2001-0667
|
2024-02-14 02:56 |
2001-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313855
|
5.1 |
MEDIUM
|
microsoft
|
internet_explorer
|
Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE …
|
CWE-88
Argument Injection
|
CVE-2001-0150
|
2024-02-14 02:56 |
2001-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313856
|
10.0 |
HIGH
|
ibm
|
aix
|
Some implementations of rlogin allow root access if given a -froot parameter.
|
CWE-88
Argument Injection
|
CVE-1999-0113
|
2024-02-14 02:55 |
1994-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313857
|
7.5 |
HIGH
|
beagle_project
|
beagle
|
Argument injection vulnerability in Beagle before 0.2.5 allows attackers to execute arbitrary commands via crafted filenames that inject command line arguments when Beagle launches external helper ap…
|
CWE-88
Argument Injection
|
CVE-2006-1865
|
2024-02-14 02:54 |
2006-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313858
|
6.4 |
MEDIUM
|
kimihia
|
tellme
|
Argument injection vulnerability in TellMe 1.2 and earlier allows remote attackers to modify command line arguments for the Whois program and obtain sensitive information via "--" style options in th…
|
CWE-88
Argument Injection
|
CVE-2005-4699
|
2024-02-14 02:53 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313859
|
10.0 |
HIGH
|
ibm
|
lotus_notes
|
Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC network share pathname to provide an alternate not…
|
CWE-88
Argument Injection
|
CVE-2004-0480
|
2024-02-14 02:52 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313860
|
7.6 |
HIGH
|
apple
|
mac_os_x
|
Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier allows remote attackers to (1) execute arbitrary code via the ProxyCommand option or (2) conduct port f…
|
CWE-88
Argument Injection
|
CVE-2004-0489
|
2024-02-14 02:52 |
2004-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313861
|
5.0 |
MEDIUM
|
microsoft
|
outlook
|
Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a ma…
|
CWE-88
Argument Injection
|
CVE-2006-2055
|
2024-02-14 02:51 |
2006-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313862
|
5.0 |
MEDIUM
|
microsoft
|
internet_explorer
|
Argument injection vulnerability in Internet Explorer 6 for Windows XP SP2 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) charac…
|
CWE-88
Argument Injection
|
CVE-2006-2056
|
2024-02-14 02:51 |
2006-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313863
|
5.0 |
MEDIUM
|
mozilla
|
firefox
|
Argument injection vulnerability in Mozilla Firefox 1.0.6 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto:…
|
CWE-88
Argument Injection
|
CVE-2006-2057
|
2024-02-14 02:51 |
2006-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313864
|
5.0 |
MEDIUM
|
avantbrowser
|
avant_browser
|
Argument injection vulnerability in Avant Browser 10.1 Build 17 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a m…
|
CWE-88
Argument Injection
|
CVE-2006-2058
|
2024-02-14 02:51 |
2006-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313865
|
7.1 |
HIGH
|
winscp
|
winscp
|
Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI.
|
CWE-88
Argument Injection
|
CVE-2006-3015
|
2024-02-14 02:49 |
2006-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313866
|
2.6 |
LOW
|
skype
|
skype
|
Argument injection vulnerability in the URI handler in Skype 2.0.*.104 and 2.5.*.0 through 2.5.*.78 for Windows allows remote authorized attackers to download arbitrary files via a URL that contains …
|
CWE-88
Argument Injection
|
CVE-2006-2312
|
2024-02-14 02:47 |
2006-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313867
|
5.0 |
MEDIUM
|
freebsd
|
freebsd
|
The ipfw firewall in FreeBSD 6.0-RELEASE allows remote attackers to cause a denial of service (firewall crash) via ICMP IP fragments that match a reset, reject or unreach action, which leads to an ac…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2006-0054
|
2024-02-14 02:43 |
2006-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313868
|
5.1 |
MEDIUM
|
microsoft
|
windows_2000
|
The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which co…
|
CWE-295
Improper Certificate Validation
|
CVE-2005-3170
|
2024-02-14 02:43 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313869
|
5.0 |
MEDIUM
|
openldap
|
openldap
|
ldbm_back_exop_passwd in the back-ldbm backend in passwd.c for OpenLDAP 2.1.12 and earlier, when the slap_passwd_parse function does not return LDAP_SUCCESS, attempts to free an uninitialized pointer…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2003-1201
|
2024-02-14 02:43 |
2003-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313870
|
7.5 |
HIGH
Network
|
cisco
|
unified_wireless_ip_phone_7920_firmware
|
Cisco IP Phone (VoIP) 7920 1.0(8) contains certain hard-coded ("fixed") public and private SNMP community strings that cannot be changed, which allows remote attackers to obtain sensitive information.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2005-3803
|
2024-02-14 01:48 |
2005-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313871
|
7.5 |
HIGH
Network
|
utstarcom
|
f1000_wi-fi_firmware
|
The SNMP daemon in UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 has hard-coded public credentials that cannot be changed, which allows attackers to obtain sensitive…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2005-3716
|
2024-02-14 01:48 |
2005-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313872
|
9.8 |
CRITICAL
Network
|
arkeia
|
network_backup
|
Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2005-0496
|
2024-02-14 01:48 |
2005-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313873
|
7.5 |
HIGH
|
iisprotect
|
iisprotect
|
SQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote attackers to insert arbitrary SQL and execute code via certai…
|
CWE-89
SQL Injection
|
CVE-2003-0377
|
2024-02-14 01:47 |
2003-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313874
|
9.8 |
CRITICAL
Network
|
linksys
|
wap54g_firmware
|
Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitr…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2010-1573
|
2024-02-14 01:43 |
2010-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313875
|
5.5 |
MEDIUM
Local
|
pgp
|
personal_privacy
|
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" option is checked, "Alw…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2002-1696
|
2024-02-14 01:20 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313876
|
10.0 |
HIGH
|
cgiscript
|
cssearch_professional
|
csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file th…
|
CWE-94
Code Injection
|
CVE-2002-0495
|
2024-02-14 01:20 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313877
|
9.8 |
CRITICAL
Network
|
xitami
|
xitami
|
Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readable, which allows remote attackers to gain privileges.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2001-1481
|
2024-02-14 01:20 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313878
|
7.5 |
HIGH
Network
|
ipswitch
|
imail
|
IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2005-2160
|
2024-02-14 01:19 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313879
|
4.4 |
MEDIUM
|
cutephp
|
cutenews
|
Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a temp…
|
CWE-94
Code Injection
|
CVE-2005-1876
|
2024-02-14 01:19 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313880
|
7.5 |
HIGH
|
flatnuke
|
flatnuke
|
Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be…
|
CWE-94
Code Injection
|
CVE-2005-1894
|
2024-02-14 01:19 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313881
|
7.5 |
HIGH
Network
|
symfony
|
twig
|
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication inform…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2001-1537
|
2024-02-14 01:19 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313882
|
7.5 |
HIGH
Network
|
dlink
|
dsl-504t_firmware
|
D-Link DSL-504T stores usernames and passwords in cleartext in the router configuration file, which allows remote attackers to obtain sensitive information.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2005-1828
|
2024-02-14 01:17 |
2005-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313883
|
7.5 |
HIGH
Network
|
broadcom
|
bluecoat_security_gateway
|
The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which all…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2004-2397
|
2024-02-14 01:17 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313884
|
7.5 |
HIGH
|
myupb
|
ultimate_php_board
|
Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is execute…
|
CWE-94
Code Injection
|
CVE-2003-0395
|
2024-02-14 01:14 |
2003-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313885
|
5.5 |
MEDIUM
Local
|
capturix
|
scanshare
|
Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2005-2209
|
2024-02-14 01:09 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313886
|
- |
-
|
-
|
-
|
Rejected reason: **REJECT** Not a valid vulnerability.
|
-
|
CVE-2024-0707
|
2024-02-13 23:15 |
2024-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313887
|
- |
-
|
-
|
-
|
Rejected reason: **REJECT** This is a duplicate of CVE-2024-1049. Please use CVE-2024-1049 instead.
|
-
|
CVE-2024-1420
|
2024-02-13 00:15 |
2024-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313888
|
7.5 |
HIGH
Network
|
phprank
|
phprank
|
phpRank 1.8 stores the administrative password in plaintext on the server and in the "ap" cookie, which allows remote attackers to retrieve the administrative password.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2002-1800
|
2024-02-10 12:06 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313889
|
7.5 |
HIGH
Network
|
audiogalaxy
|
audiogalaxy
|
Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2001-1536
|
2024-02-10 12:04 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313890
|
- |
-
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. All references and descriptions in this record have been removed to prevent accidental usage.
|
-
|
CVE-2023-6716
|
2024-02-9 18:15 |
2024-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313891
|
4.3 |
MEDIUM
|
georgecurrums
|
open_guestbook
|
Cross-site scripting (XSS) vulnerability in header.php in Open Guestbook 0.5 allows remote attackers to inject arbitrary web script or HTML via the title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2006-3295
|
2024-02-9 12:26 |
2006-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313892
|
7.5 |
HIGH
|
sun oracle
|
jsse java_web_start jre
|
X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 …
|
CWE-295
Improper Certificate Validation
|
CVE-2003-1229
|
2024-02-9 12:26 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313893
|
10.0 |
HIGH
|
rtfm
|
ssldump
|
Buffer underflow in ssldump 0.9b2 and earlier allows remote attackers to cause a denial of service (memory corruption) via a crafted SSLv2 challenge value.
|
CWE-787
Out-of-bounds Write
|
CVE-2002-2227
|
2024-02-9 12:26 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313894
|
6.8 |
MEDIUM
|
microsoft
|
windows_xp windows_2000 windows_98 windows_me windows_98se windows_nt internet_explorer office outlook_express
|
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Ma…
|
CWE-295
Improper Certificate Validation
|
CVE-2002-0862
|
2024-02-9 12:26 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313895
|
4.3 |
MEDIUM
|
cjguestbook_project
|
cjguestbook
|
Cross-site scripting (XSS) vulnerability in sign.php in cjGuestbook 1.3 and earlier allows remote attackers to inject Javascript code via a javascript URI in an img bbcode tag in the comments paramet…
|
CWE-79
Cross-site Scripting
|
CVE-2006-3211
|
2024-02-9 12:21 |
2006-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313896
|
4.3 |
MEDIUM
|
fantastic_guestbook_project
|
fantastic_guestbook
|
Multiple cross-site scripting (XSS) vulnerabilities in guestbook.php in Fantastic Guestbook 2.0.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the…
|
CWE-79
Cross-site Scripting
|
CVE-2006-3568
|
2024-02-9 12:20 |
2006-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313897
|
7.5 |
HIGH
|
aol
|
aim
|
Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via a "buddyicon" command with a long "src" argument.
|
CWE-120
Classic Buffer Overflow
|
CVE-2000-1094
|
2024-02-9 12:20 |
2001-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313898
|
10.0 |
HIGH
|
sendmail netbsd hp windriver sun gentoo oracle
|
sendmail netbsd hp-ux bsdos sunos linux solaris alphaserver_sc platform_sa
|
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the …
|
CWE-120
Classic Buffer Overflow
|
CVE-2002-1337
|
2024-02-9 12:19 |
2003-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313899
|
10.0 |
HIGH
|
bsdi sun hp oracle debian ibm freebsd netbsd digital next
|
bsd_os sunos hp-ux solaris debian_linux aix freebsd netbsd ultrix nextstep
|
Buffer overflow of rlogin program using TERM environmental variable.
|
CWE-120
Classic Buffer Overflow
|
CVE-1999-0046
|
2024-02-9 12:19 |
1997-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313900
|
7.5 |
HIGH
|
terascript
|
wintango_application_server
|
Buffer overflow in WiTango Application Server and Tango 2000 allows remote attackers to execute arbitrary code via a long cookie to Witango_UserReference.
|
CWE-120
Classic Buffer Overflow
|
CVE-2003-0595
|
2024-02-9 12:18 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|