|
343801
|
5.0 |
MEDIUM
|
coolphp
|
coolphp
|
index.php in CoolPHP 1.0-stable allows remote attackers to gain sensitive information via an invalid op parameter, which reveals the path in an error message.
|
NVD-CWE-Other
|
CVE-2004-1600
|
2017-07-11 10:31 |
2004-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343802
|
7.5 |
HIGH
|
coolphp
|
coolphp_web_portal
|
Directory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files and execute local PHP scripts via a .. (dot dot) in the op parameter.
|
NVD-CWE-Other
|
CVE-2004-1601
|
2017-07-11 10:31 |
2004-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343803
|
7.5 |
HIGH
|
best_software saleslogix_corporation
|
saleslogix
|
SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator.
|
NVD-CWE-Other
|
CVE-2004-1605
|
2017-07-11 10:31 |
2004-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343804
|
6.4 |
MEDIUM
|
best_software saleslogix_corporation
|
saleslogix
|
slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the ErrorLogMsg cookie.
|
NVD-CWE-Other
|
CVE-2004-1606
|
2017-07-11 10:31 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343805
|
5.0 |
MEDIUM
|
best_software saleslogix_corporation
|
saleslogix
|
slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error mes…
|
NVD-CWE-Other
|
CVE-2004-1607
|
2017-07-11 10:31 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343806
|
7.5 |
HIGH
|
best_software saleslogix_corporation
|
saleslogix
|
SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation.
|
NVD-CWE-Other
|
CVE-2004-1608
|
2017-07-11 10:31 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343807
|
5.0 |
MEDIUM
|
best_software saleslogix_corporation
|
saleslogix
|
SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.
|
NVD-CWE-Other
|
CVE-2004-1609
|
2017-07-11 10:31 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343808
|
5.1 |
MEDIUM
|
best_software saleslogix_corporation
|
saleslogix
|
SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the s…
|
NVD-CWE-Other
|
CVE-2004-1611
|
2017-07-11 10:31 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343809
|
5.0 |
MEDIUM
|
saleslogix_corporation
|
saleslogix
|
Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.
|
NVD-CWE-Other
|
CVE-2004-1612
|
2017-07-11 10:31 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343810
|
5.0 |
MEDIUM
|
links
|
links
|
Links allows remote attackers to cause a denial of service (memory consumption) via a web page or HTML email that contains a table with a td element and a large rowspan value,as demonstrated by mangl…
|
NVD-CWE-Other
|
CVE-2004-1616
|
2017-07-11 10:31 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343811
|
5.0 |
MEDIUM
|
vypress
|
tonecast
|
Vypress Tonecast 1.3 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed mp2 stream.
|
NVD-CWE-Other
|
CVE-2004-1618
|
2017-07-11 10:31 |
2004-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343812
|
7.5 |
HIGH
|
akella
|
privateers_bounty_age_of_sail_ii
|
Buffer overflow in Privateer's Bounty: Age of Sail II allows remote attackers to execute arbitrary code via a long nickname.
|
NVD-CWE-Other
|
CVE-2004-1619
|
2017-07-11 10:31 |
2004-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343813
|
5.0 |
MEDIUM
|
s9y
|
serendipity
|
CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the url parameter in (…
|
NVD-CWE-Other
|
CVE-2004-1620
|
2017-07-11 10:31 |
2004-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343814
|
7.5 |
HIGH
|
ubbcentral
|
ubb.threads
|
SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.
|
NVD-CWE-Other
|
CVE-2004-1622
|
2017-07-11 10:31 |
2004-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343815
|
5.0 |
MEDIUM
|
microsoft
|
windows_xp
|
The WAV file property handler in Windows XP SP1 allows remote attackers to cause a denial of service (infinite loop in Explorer) via a WAV file with an invalid file header whose fmt chunk length is s…
|
NVD-CWE-Other
|
CVE-2004-1623
|
2017-07-11 10:31 |
2004-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343816
|
7.2 |
HIGH
|
altiris
|
carbon_copy
|
Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in C…
|
NVD-CWE-Other
|
CVE-2004-1624
|
2017-07-11 10:31 |
2004-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343817
|
5.0 |
MEDIUM
|
code-crafters
|
ability_server
|
Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long STOR command.
|
NVD-CWE-Other
|
CVE-2004-1626
|
2017-07-11 10:31 |
2004-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343818
|
7.5 |
HIGH
|
code-crafters
|
ability_server
|
Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long APPE command.
|
NVD-CWE-Other
|
CVE-2004-1627
|
2017-07-11 10:31 |
2004-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343819
|
7.5 |
HIGH
|
-
|
-
|
Multiple SQL injection vulnerabilities in Dwc_articles 1.6 and earlier allow remote attackers to execute arbitrary SQL statements.
|
NVD-CWE-Other
|
CVE-2004-1629
|
2017-07-11 10:31 |
2004-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343820
|
4.3 |
MEDIUM
|
openwfe
|
work_flow_engine
|
Cross-site scripting (XSS) vulnerability in the login form in Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to execute arbitrary web script or HTML via the url parameter.
|
NVD-CWE-Other
|
CVE-2004-1630
|
2017-07-11 10:31 |
2004-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343821
|
5.0 |
MEDIUM
|
openwfe
|
work_flow_engine
|
Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to conduct port scans of remote hosts by specifying the target in an rmi:// Worklist URL, then using the response times to infer the resul…
|
NVD-CWE-Other
|
CVE-2004-1631
|
2017-07-11 10:31 |
2004-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343822
|
4.3 |
MEDIUM
|
moniwiki
|
moniwiki
|
Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the arguments to wiki.php.
|
NVD-CWE-Other
|
CVE-2004-1632
|
2017-07-11 10:31 |
2004-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343823
|
5.0 |
MEDIUM
|
mozilla
|
bugzilla
|
process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenticated users to modify the keywords in a bug via th…
|
NVD-CWE-Other
|
CVE-2004-1633
|
2017-07-11 10:31 |
2004-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343824
|
5.0 |
MEDIUM
|
mozilla
|
bugzilla
|
show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private,…
|
NVD-CWE-Other
|
CVE-2004-1634
|
2017-07-11 10:31 |
2004-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343825
|
5.0 |
MEDIUM
|
-
|
-
|
Bugzilla 2.17.1 through 2.18rc2 and 2.19 from cvs, when using the insidergroup feature, does not sufficiently protect private attachments when there are changes to the metadata, such as filename, des…
|
NVD-CWE-Other
|
CVE-2004-1635
|
2017-07-11 10:31 |
2004-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343826
|
10.0 |
HIGH
|
net_integration_technologies_inc.
|
wvtftp
|
Heap-based buffer overflow in the WvTFTPServer::new_connection function in wvtftpserver.cc for WvTftp 0.9 allows remote attackers to execute arbitrary code via a long option string in a TFTP packet.
|
NVD-CWE-Other
|
CVE-2004-1636
|
2017-07-11 10:31 |
2004-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343827
|
7.5 |
HIGH
|
hawking_technology
|
har11a_dsl_router
|
The Hawking Technologies HAR11A modem/router allows remote attackers to obtain sensitive information by connecting to port 254, which displays a management interface and information on established co…
|
NVD-CWE-Other
|
CVE-2004-1637
|
2017-07-11 10:31 |
2004-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343828
|
7.5 |
HIGH
|
-
|
-
|
Buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long (1) EHLO and possibly (2) HELO command.
|
NVD-CWE-Other
|
CVE-2004-1638
|
2017-07-11 10:31 |
2004-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343829
|
5.0 |
MEDIUM
|
-
|
-
|
Mozilla Firefox before 0.10, Mozilla 5.0, and Gecko 20040913 allows remote attackers to cause a denial of service (application crash or memory consumption) via a large binary file with a .html extens…
|
NVD-CWE-Other
|
CVE-2004-1639
|
2017-07-11 10:31 |
2004-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343830
|
4.3 |
MEDIUM
|
-
|
-
|
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 0.94 and 1.0 allow remote attackers to execute arbitrary web script and HTML via the (1) terme parameter to search.php or (2) letter param…
|
NVD-CWE-Other
|
CVE-2004-1640
|
2017-07-11 10:31 |
2004-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343831
|
5.0 |
MEDIUM
|
south_river_technologies
|
titan_ftp_server
|
Heap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) via a long FTP command such as (1) CWD, (2) STAT, or (3) LIST.
|
NVD-CWE-Other
|
CVE-2004-1641
|
2017-07-11 10:31 |
2004-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343832
|
5.0 |
MEDIUM
|
texas_imperial_software
|
wftpd
|
WFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST commands.
|
NVD-CWE-Other
|
CVE-2004-1642
|
2017-07-11 10:31 |
2004-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343833
|
5.0 |
MEDIUM
|
jerod_moemeka
|
xedus
|
Xedus 1.0 allows remote attackers to cause a denial of service (refuse connections) by connecting multiple times from the same IP address.
|
NVD-CWE-Other
|
CVE-2004-1644
|
2017-07-11 10:31 |
2004-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343834
|
4.3 |
MEDIUM
|
jerod_moemeka
|
xedus
|
Cross-site scripting (XSS) vulnerability in Xedus 1.0 allows remote attackers to execute arbitrary web script or HTML via the (1) username parameter to test.x, (2) username parameter to TestServer.x,…
|
NVD-CWE-Other
|
CVE-2004-1645
|
2017-07-11 10:31 |
2004-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343835
|
5.0 |
MEDIUM
|
jerod_moemeka
|
xedus
|
Directory traversal vulnerability in Xedus 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
|
NVD-CWE-Other
|
CVE-2004-1646
|
2017-07-11 10:31 |
2004-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343836
|
7.2 |
HIGH
|
microsoft
|
windows_2000
|
Buffer overflow in Microsoft Msinfo32.exe might allow local users to execute arbitrary code via a long filename in the msinfo_file command line parameter. NOTE: this issue might not cross security b…
|
NVD-CWE-Other
|
CVE-2004-1649
|
2017-07-11 10:31 |
2004-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343837
|
7.5 |
HIGH
|
d-link
|
dcs-900_internet_camera
|
D-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the IP address of the camera via a UDP broadcast packet.
|
NVD-CWE-Other
|
CVE-2004-1650
|
2017-07-11 10:31 |
2004-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343838
|
4.3 |
MEDIUM
|
brickhost
|
phpscheduleit
|
Multiple cross-site scripting (XSS) vulnerabilities in the registration page in phpScheduleIt 1.0.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Lastname …
|
NVD-CWE-Other
|
CVE-2004-1651
|
2017-07-11 10:31 |
2004-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343839
|
7.5 |
HIGH
|
brickhost
|
phpscheduleit
|
phpScheduleIt 1.0.0 RC1 does not clear administrative privileges if the administrator logs in as a normal user, which allows users with physical access to gain administrative privileges.
|
NVD-CWE-Other
|
CVE-2004-1652
|
2017-07-11 10:31 |
2004-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343840
|
6.4 |
MEDIUM
|
openbsd
|
openssh
|
The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonC…
|
NVD-CWE-Other
|
CVE-2004-1653
|
2017-07-11 10:31 |
2004-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343841
|
7.5 |
HIGH
|
phpwebsite
|
phpwebsite
|
SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commands via cal_template.
|
NVD-CWE-Other
|
CVE-2004-1654
|
2017-07-11 10:31 |
2004-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343842
|
4.3 |
MEDIUM
|
phpwebsite
|
phpwebsite
|
Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) CM_pid parameter in the comments module or (2) th…
|
NVD-CWE-Other
|
CVE-2004-1655
|
2017-07-11 10:31 |
2004-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343843
|
5.0 |
MEDIUM
|
comersus_open_technologies
|
comersus_cart
|
CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl pa…
|
NVD-CWE-Other
|
CVE-2004-1656
|
2017-07-11 10:31 |
2004-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343844
|
4.3 |
MEDIUM
|
newtelligence
|
dasblog
|
Cross-site scripting (XSS) vulnerability in the Activity and Events Viewer for Newtelligence DasBlog allows remote attackers to inject arbitrary web script or HTML via the (1) User Agent or (2) Refer…
|
NVD-CWE-Other
|
CVE-2004-1657
|
2017-07-11 10:31 |
2004-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343845
|
4.6 |
MEDIUM
|
kerio
|
personal_firewall
|
Kerio Personal Firewall 4.0 (KPF4) allows local users with administrative privileges to bypass the Application Security feature and execute arbitrary processes by directly writing to \device\physical…
|
NVD-CWE-Other
|
CVE-2004-1658
|
2017-07-11 10:31 |
2004-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343846
|
4.3 |
MEDIUM
|
cutephp
|
cutenews
|
Cross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Administrator, Editor, Journalist or Commenter privileges to inject arbitrary web scri…
|
NVD-CWE-Other
|
CVE-2004-1659
|
2017-07-11 10:31 |
2004-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343847
|
7.5 |
HIGH
|
cutephp
|
cutenews
|
PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath parameter to (1) show_archives.php or (2) show_news.php.
|
NVD-CWE-Other
|
CVE-2004-1660
|
2017-07-11 10:31 |
2004-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343848
|
7.5 |
HIGH
|
sitecubed
|
mailworks_professional
|
MailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains "auth=1" and "uId=1."
|
NVD-CWE-Other
|
CVE-2004-1661
|
2017-07-11 10:31 |
2004-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343849
|
5.0 |
MEDIUM
|
-
|
-
|
YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in a PHP error message.
|
NVD-CWE-Other
|
CVE-2004-1662
|
2017-07-11 10:31 |
2004-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343850
|
5.0 |
MEDIUM
|
activision
|
call_of_duty call_of_duty_united_offensive
|
Call of Duty 1.4 and earlier allows remote attackers to cause a denial of service (game end) via a large (1) query or (2) reply packet, which is not properly handled by the buffer overflow protection…
|
NVD-CWE-Other
|
CVE-2004-1664
|
2017-07-11 10:31 |
2004-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|