|
343751
|
5.0 |
MEDIUM
|
korweblog
|
korweblog
|
Directory traversal vulnerability in viewimg.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter.
|
NVD-CWE-Other
|
CVE-2004-1543
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343752
|
4.3 |
MEDIUM
|
jspwiki
|
jspwiki
|
Cross-site scripting (XSS) vulnerability in Search.jsp in JSPWiki 2.1.120-cvs and earlier allows remote attackers to execute arbitrary web script as other users via the query parameter.
|
NVD-CWE-Other
|
CVE-2004-1544
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343753
|
5.0 |
MEDIUM
|
moniwiki
|
moniwiki
|
UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and …
|
NVD-CWE-Other
|
CVE-2004-1545
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343754
|
5.0 |
MEDIUM
|
alt-n
|
mdaemon
|
Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a long (1) SAML, SOML, SEND, or MAIL command to the SMTP server or (2) LIST comm…
|
NVD-CWE-Other
|
CVE-2004-1546
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343755
|
5.0 |
MEDIUM
|
onnuri_infotek
|
activepost_standard
|
The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to cause a denial of service (application crash) via a long filename, possibly triggering a buffer overflow.
|
NVD-CWE-Other
|
CVE-2004-1547
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343756
|
5.0 |
MEDIUM
|
onnuri_infotek
|
activepost_standard
|
Directory traversal vulnerability in the file server in ActivePost Standard 3.1 allows remote authenticated users to upload arbitrary files via a .. (dot dot) in the filename.
|
NVD-CWE-Other
|
CVE-2004-1548
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343757
|
5.0 |
MEDIUM
|
onnuri_infotek
|
activepost_standard
|
The conference menu in ActivePost Standard 3.1 sends passwords of password-protected rooms in cleartext, which could allow remote attackers to gain sensitive information by sniffing the network conne…
|
NVD-CWE-Other
|
CVE-2004-1549
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343758
|
7.5 |
HIGH
|
motorola
|
wr850g
|
Motorola Wireless Router WR850G running firmware 4.03 allows remote attackers to bypass authentication, log on as an administrator, and obtain sensitive information by repeatedly making an HTTP reque…
|
NVD-CWE-Other
|
CVE-2004-1550
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343759
|
4.3 |
MEDIUM
|
php_arena
|
pafiledb
|
Cross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute arbitrary web script or HTML via the id parameter.
|
NVD-CWE-Other
|
CVE-2004-1551
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343760
|
7.5 |
HIGH
|
alexphpteam
|
alex_guestbook
|
PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitrary PHP code by modifying the chem_absolu parameter to reference a URL on a rem…
|
NVD-CWE-Other
|
CVE-2004-1554
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343761
|
7.5 |
HIGH
|
broadboard_instant
|
asp_message_board
|
Multiple SQL injection vulnerabilities in BroadBoard Instant ASP Message Board allow remote attackers to run arbitrary SQL commands via the (1) keywords parameter to search.asp, (2) handle parameter …
|
NVD-CWE-Other
|
CVE-2004-1555
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343762
|
5.0 |
MEDIUM
|
mywebserver
|
mywebserver
|
MyWebServer 1.0.3 allows remote attackers to cause a denial of service (application crash) via a large number of connections within a short time.
|
NVD-CWE-Other
|
CVE-2004-1556
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343763
|
6.4 |
MEDIUM
|
mywebserver
|
mywebserver
|
MyWebServer 1.0.3 allows remote attackers to bypass authentication, modify configuration, and read arbitrary files via a direct HTTP request to (1) /admin or (2) ServerProperties.html.
|
NVD-CWE-Other
|
CVE-2004-1557
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343764
|
7.5 |
HIGH
|
ypops
|
ypops
|
Multiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) POP3 USE…
|
NVD-CWE-Other
|
CVE-2004-1558
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343765
|
4.3 |
MEDIUM
|
wordpress
|
wordpress
|
Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to…
|
NVD-CWE-Other
|
CVE-2004-1559
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343766
|
5.0 |
MEDIUM
|
microsoft
|
sql_server
|
Microsoft SQL Server 7.0 allows remote attackers to cause a denial of service (mssqlserver service halt) via a long request to TCP port 1433, possibly triggering a buffer overflow.
|
NVD-CWE-Other
|
CVE-2004-1560
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343767
|
7.5 |
HIGH
|
icecast
|
icecast
|
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a large number of headers.
|
NVD-CWE-Other
|
CVE-2004-1561
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343768
|
7.5 |
HIGH
|
w-agora
|
w-agora
|
SQL injection vulnerability in redir_url.php in w-Agora 4.1.6a allows remote attackers to execute arbitrary SQL commands via the key parameter.
|
NVD-CWE-Other
|
CVE-2004-1562
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343769
|
4.3 |
MEDIUM
|
w-agora
|
w-agora
|
Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web script or HTML via the (1) thread parameter to download_thread.php, (2) loginuser…
|
NVD-CWE-Other
|
CVE-2004-1563
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343770
|
5.0 |
MEDIUM
|
w-agora
|
w-agora
|
CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the threa…
|
NVD-CWE-Other
|
CVE-2004-1564
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343771
|
4.3 |
MEDIUM
|
silent-storm
|
silent-storm_portal
|
Cross-site scripting (XSS) vulnerability in index.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to execute arbitrary web script or HTML via the module parameter.
|
NVD-CWE-Other
|
CVE-2004-1566
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343772
|
7.5 |
HIGH
|
-
|
-
|
profile.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to gain privileges by setting the mail parameter to 1, which is the value for an administrator.
|
NVD-CWE-Other
|
CVE-2004-1567
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343773
|
5.0 |
MEDIUM
|
parachat
|
parachat_server
|
Directory traversal vulnerability in ParaChat Server 5.5 allows remote attackers to read arbitrary files via a ..%5C (hex-encoded dot dot) in the URL.
|
NVD-CWE-Other
|
CVE-2004-1568
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343774
|
4.0 |
MEDIUM
|
illustrate
|
dbpoweramp_audio_player dbpoweramp_music_converter
|
Buffer overflow in (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe in dBpowerAMP Audio Player 2.0 and dbPowerAmp Music Converter 10.0 allows remote attackers to cause a denial of service or…
|
NVD-CWE-Other
|
CVE-2004-1569
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343775
|
7.5 |
HIGH
|
eaden_mckee
|
bblog
|
SQL injection vulnerability in bBlog 0.7.2 and 0.7.3 allows remote attackers to execute arbitrary SQL commands via the p parameter.
|
NVD-CWE-Other
|
CVE-2004-1570
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343776
|
5.0 |
MEDIUM
|
aj-fork
|
aj-fork
|
AJ-Fork 167 allows remote attackers to gain sensitive information via a direct request to (1) auto-acronyms.php, (2) auto-archive.php, (3) ount-article-views.php, (4) kses.php, (5) custom-quick-tags.…
|
NVD-CWE-Other
|
CVE-2004-1571
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343777
|
5.0 |
MEDIUM
|
aj-fork
|
aj-fork
|
AJ-Fork 167 does not restrict access to directories such as (1) data, (2) inc, (3) plugins, (4) skins, or (5) tools, which allows remote attackers to list files in those directories via a direct HTTP…
|
NVD-CWE-Other
|
CVE-2004-1572
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343778
|
7.2 |
HIGH
|
aj-fork cutephp
|
aj-fork cutenews
|
The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbitrary PHP code and gain privileges as the administrator.
|
NVD-CWE-Other
|
CVE-2004-1573
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343779
|
7.5 |
HIGH
|
-
|
-
|
Buffer overflow in Vypress Messenger 3.5.1 and earlier allows remote attackers to execute arbitrary code via a message with a long first field.
|
NVD-CWE-Other
|
CVE-2004-1574
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343780
|
5.0 |
MEDIUM
|
apache
|
xerces-c\+\+
|
The XML parser in Xerces-C++ 2.5.0 allows remote attackers to cause a denial of service (CPU consumption) via XML attributes in a crafted XML document.
|
NVD-CWE-Other
|
CVE-2004-1575
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343781
|
5.0 |
MEDIUM
|
-
|
-
|
Format string vulnerability in Judge Dredd: Dredd vs. Death 1.01 and earlier allows remote attackers to cause a denial of service (application crash) via format string specifiers in a chat message.
|
NVD-CWE-Other
|
CVE-2004-1576
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343782
|
5.0 |
MEDIUM
|
greg_donald
|
phplinks
|
index.php in PHP Links allows remote attackers to gain sensitive information via an invalid show parameter, which reveals the full path in an error message.
|
NVD-CWE-Other
|
CVE-2004-1577
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343783
|
4.3 |
MEDIUM
|
invision_power_services
|
invision_power_board
|
Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header.
|
NVD-CWE-Other
|
CVE-2004-1578
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343784
|
5.0 |
MEDIUM
|
devellion
|
cubecart
|
index.php in CubeCart 2.0.1 allows remote attackers to gain sensitive information via an HTTP request with an invalid cat_id parameter, which reveals the full path in a PHP error message.
|
NVD-CWE-Other
|
CVE-2004-1579
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343785
|
7.5 |
HIGH
|
devellion
|
cubecart
|
SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
|
NVD-CWE-Other
|
CVE-2004-1580
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343786
|
5.0 |
MEDIUM
|
blackboard
|
blackboard
|
BlackBoard 1.5.1 allows remote attackers to gain sensitive information via a direct request to (1) checkdb.inc.php, (2) admin.inc.php or (3) cp.inc.php, which reveals the path in a PHP error message.
|
NVD-CWE-Other
|
CVE-2004-1581
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343787
|
5.0 |
MEDIUM
|
wordpress
|
wordpress
|
CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter.
|
NVD-CWE-Other
|
CVE-2004-1584
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343788
|
5.0 |
MEDIUM
|
jera_technology
|
flash_messaging
|
Flash Messaging 5.2.0g (rev 1.1.2) and earlier allows remote attackers to cause a denial of service (application crash) via certain wide characters.
|
NVD-CWE-Other
|
CVE-2004-1585
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343789
|
5.0 |
MEDIUM
|
monolith_productions
|
alien_versus_predator blood no_one_lives_forever shogo
|
Buffer overflow in Monolith games including (1) Alien versus Predator 2 1.0.9.6 and earlier, (2) Blood 2 2.1 and earlier, (3) No one lives forever 1.004 and earlier and (4) Shogo 2.2 and earlier allo…
|
NVD-CWE-Other
|
CVE-2004-1587
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343790
|
7.5 |
HIGH
|
gosmart
|
gosmart_message_board
|
SQL injection vulnerability in GoSmart Message Board allows remote attackers to execute arbitrary SQL code via the (1) QuestionNumber and Category parameters to Forum.asp or (2) Username and Password…
|
NVD-CWE-Other
|
CVE-2004-1588
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343791
|
4.3 |
MEDIUM
|
gosmart
|
gosmart_message_board
|
Cross-site scripting (XSS) vulnerability in GoSmart Message Board allows remote attackers to execute inject web script or HTML via the (1) Category parameter to Forum.asp or (2) MainMessageID paramet…
|
NVD-CWE-Other
|
CVE-2004-1589
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343792
|
5.0 |
MEDIUM
|
clientexec
|
clientexec
|
Clientexec allows remote attackers to gain sensitive information via an HTTP request to phpinfo.php, which calls the phpinfo function.
|
NVD-CWE-Other
|
CVE-2004-1590
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343793
|
7.5 |
HIGH
|
micronet
|
sp916bm
|
The web interface for Micronet Wireless Broadband Router SP916BM running firmware before 1.9 08/04/2004 resets the password to the default password when the router is shut off, which could allow remo…
|
NVD-CWE-Other
|
CVE-2004-1591
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343794
|
7.5 |
HIGH
|
ocportal
|
ocportal
|
PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the req_path parameter to reference a URL on a re…
|
NVD-CWE-Other
|
CVE-2004-1592
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343795
|
4.3 |
MEDIUM
|
sct_corporation
|
campus_pipeline
|
Cross-site scripting (XSS) vulnerability in render.UserLayoutRootNode.uP in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via the utf parameter.
|
NVD-CWE-Other
|
CVE-2004-1593
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343796
|
4.3 |
MEDIUM
|
e-zone_media_inc.
|
fusetalk
|
Cross-site scripting (XSS) vulnerability in FuseTalk 4.0 allows remote attackers to execute arbitrary web script via an img src tag.
|
NVD-CWE-Other
|
CVE-2004-1594
|
2017-07-11 10:31 |
2004-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343797
|
7.5 |
HIGH
|
shixxnote
|
shixxnote
|
Buffer overflow in ShixxNote 6.net build 117 allows remote attackers to execute arbitrary code via a long font field.
|
NVD-CWE-Other
|
CVE-2004-1595
|
2017-07-11 10:31 |
2004-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343798
|
7.5 |
HIGH
|
3com
|
3cradsl72
|
The 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as passwords and router settings via a direct HTTP request to app_sta.stm.
|
NVD-CWE-Other
|
CVE-2004-1596
|
2017-07-11 10:31 |
2004-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343799
|
5.0 |
MEDIUM
|
adobe
|
acrobat acrobat_reader
|
Adobe Acrobat and Acrobat Reader 6.0 allow remote attackers to read arbitrary files via a PDF file that contains an embedded Shockwave (swf) file that references files outside of the temporary direct…
|
NVD-CWE-Other
|
CVE-2004-1598
|
2017-07-11 10:31 |
2004-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343800
|
4.3 |
MEDIUM
|
coolphp
|
coolphpweb_portal
|
Cross-site scripting (XSS) vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to execute arbitrary web script or HTML via the (1) query or (2) nick parameters.
|
NVD-CWE-Other
|
CVE-2004-1599
|
2017-07-11 10:31 |
2004-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|