|
343901
|
5.0 |
MEDIUM
|
merak
|
mail_server
|
The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an invalid HTTP request, which reveals the installation p…
|
NVD-CWE-Other
|
CVE-2004-1720
|
2017-07-11 10:31 |
2004-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343902
|
5.0 |
MEDIUM
|
merak
|
mail_server
|
The (1) function.php or (2) function.view.php scripts in Merak Mail Server 5.2.7 allow remote attackers to read arbitrary PHP files via a direct HTTP request to port 32000.
|
NVD-CWE-Other
|
CVE-2004-1721
|
2017-07-11 10:31 |
2004-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343903
|
7.5 |
HIGH
|
merak
|
mail_server
|
SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule parameter.
|
NVD-CWE-Other
|
CVE-2004-1722
|
2017-07-11 10:31 |
2004-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343904
|
5.0 |
MEDIUM
|
php_fusion
|
php_fusion
|
The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a direct HTTP request, which reveals the installation path in an …
|
NVD-CWE-Other
|
CVE-2004-1723
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343905
|
7.5 |
HIGH
|
php_fusion
|
php_fusion
|
The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execute (777), which allows remote attackers to downloa…
|
NVD-CWE-Other
|
CVE-2004-1724
|
2017-07-11 10:31 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343906
|
7.5 |
HIGH
|
john_bradley
|
xv
|
Stack-based buffer overflow in xvbmp.c in XV allows remote attackers to execute arbitrary code via a crafted image file.
|
NVD-CWE-Other
|
CVE-2004-1725
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343907
|
7.5 |
HIGH
|
john_bradley
|
xv
|
Multiple integer overflows in (1) xviris.c, (2) xvpcx.c, and (3) xvpm.c in XV allow remote attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow.
|
NVD-CWE-Other
|
CVE-2004-1726
|
2017-07-11 10:31 |
2004-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343908
|
5.0 |
MEDIUM
|
working_resources_inc.
|
badblue
|
BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address.
|
NVD-CWE-Other
|
CVE-2004-1727
|
2017-07-11 10:31 |
2004-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343909
|
7.5 |
HIGH
|
british_national_corpus
|
sara
|
Buffer overflow in British National Corpus SARA (sarad) allows remote attackers to execute arbitrary code by calling the client with a long string.
|
NVD-CWE-Other
|
CVE-2004-1728
|
2017-07-11 10:31 |
2004-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343910
|
4.3 |
MEDIUM
|
nihuo_software
|
web_log_analyzer
|
Cross-site scripting (XSS) vulnerability in Nihuo Web Log Analyzer 1.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.
|
NVD-CWE-Other
|
CVE-2004-1729
|
2017-07-11 10:31 |
2004-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343911
|
4.3 |
MEDIUM
|
mantis
|
mantis
|
Cross-site scripting (XSS) vulnerability in Mantis bugtracker allows remote attackers to inject arbitrary web script or HTML via (1) the return parameter to login_page.php, (2) e-mail field in signup…
|
NVD-CWE-Other
|
CVE-2004-1730
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343912
|
5.0 |
MEDIUM
|
mantis
|
mantis
|
signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail address.
|
NVD-CWE-Other
|
CVE-2004-1731
|
2017-07-11 10:31 |
2004-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343913
|
7.5 |
HIGH
|
mydms
|
mydms
|
SQL injection vulnerability in out.ViewFolder.php in MyDMS before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the folderid parameter.
|
NVD-CWE-Other
|
CVE-2004-1732
|
2017-07-11 10:31 |
2004-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343914
|
7.5 |
HIGH
|
mydms
|
mydms
|
This was fixed in version 1.4.2.
|
NVD-CWE-Other
|
CVE-2004-1732
|
2017-07-11 10:31 |
2004-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343915
|
5.0 |
MEDIUM
|
mydms
|
mydms
|
Directory traversal vulnerability in MyDMS 1.4.2 and other versions allows remote registered users to read arbitrary files via .. (dot dot) sequences in the URL.
|
NVD-CWE-Other
|
CVE-2004-1733
|
2017-07-11 10:31 |
2004-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343916
|
7.5 |
HIGH
|
mantis
|
mantis
|
PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_path parameter to bug_api.php or (2) t_core_dir parameter t…
|
NVD-CWE-Other
|
CVE-2004-1734
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343917
|
4.3 |
MEDIUM
|
sympa
|
sympa
|
Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject arbitrary web script or HTML via the description field.
|
NVD-CWE-Other
|
CVE-2004-1735
|
2017-07-11 10:31 |
2004-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343918
|
5.0 |
MEDIUM
|
the_cacti_group
|
cacti
|
Cacti 0.8.5a allows remote attackers to gain sensitive information via an HTTP request to (1) auth.php, (2) auth_login.php, (3) auth_changepassword.php, and possibly other php files, which reveal the…
|
NVD-CWE-Other
|
CVE-2004-1736
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343919
|
7.5 |
HIGH
|
the_cacti_group gentoo
|
cacti linux
|
SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.
|
NVD-CWE-Other
|
CVE-2004-1737
|
2017-07-11 10:31 |
2004-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343920
|
4.3 |
MEDIUM
|
jshop_e-commerce
|
jshop_server
|
Cross-site scripting (XSS) vulnerability in page.php in JShop allows remote attackers to inject arbitrary web script or HTML via the xPage parameter.
|
NVD-CWE-Other
|
CVE-2004-1738
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343921
|
5.0 |
MEDIUM
|
bird_chat
|
internet_chat_server
|
Bird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users.
|
NVD-CWE-Other
|
CVE-2004-1739
|
2017-07-11 10:31 |
2004-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343922
|
5.0 |
MEDIUM
|
bird_chat
|
internet_chat_server
|
This has been fixed in version 1.61 Security Release.
|
NVD-CWE-Other
|
CVE-2004-1739
|
2017-07-11 10:31 |
2004-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343923
|
5.0 |
MEDIUM
|
music_daemon
|
music_daemon
|
Music daemon (musicd) 0.0.3 and earlier allows remote attackers to read arbitrary files by calling LOAD with a full pathname, then calling SHOWLIST.
|
NVD-CWE-Other
|
CVE-2004-1740
|
2017-07-11 10:31 |
2004-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343924
|
5.0 |
MEDIUM
|
music_daemon
|
music_daemon
|
Music daemon (musicd) 0.0.3 and earlier allows remote attackers to cause a denial of service (crash) by calling LOAD with a binary file as an argument, then calling SHOWLIST.
|
NVD-CWE-Other
|
CVE-2004-1741
|
2017-07-11 10:31 |
2004-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343925
|
5.0 |
MEDIUM
|
web-app.org
|
webapp
|
Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a .. (dot dot) in the viewcat parameter.
|
NVD-CWE-Other
|
CVE-2004-1742
|
2017-07-11 10:31 |
2004-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343926
|
5.0 |
MEDIUM
|
efs_software
|
efs_web_server
|
Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to view arbitrary files via an HTTP request for the disk_c virtual folder.
|
NVD-CWE-Other
|
CVE-2004-1743
|
2017-07-11 10:31 |
2004-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343927
|
5.0 |
MEDIUM
|
efs_software
|
efs_web_server
|
Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to cause a denial of service (CPU consumption or crash) via many large HTTP requests.
|
NVD-CWE-Other
|
CVE-2004-1744
|
2017-07-11 10:31 |
2004-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343928
|
5.0 |
MEDIUM
|
people_can_fly
|
painkiller
|
Buffer overflow in Painkiller 1.3.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password.
|
NVD-CWE-Other
|
CVE-2004-1745
|
2017-07-11 10:31 |
2004-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343929
|
4.3 |
MEDIUM
|
php_code_snippet_library
|
php_code_snippet_library
|
Cross-site scripting (XSS) vulnerability in index.php in PHP Code Snippet Library allows remote attackers to inject arbitrary web script or HTML via the (1) cat_select or (2) show parameters.
|
NVD-CWE-Other
|
CVE-2004-1746
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343930
|
4.3 |
MEDIUM
|
network_everywhere
|
nr041
|
Cross-site scripting (XSS) vulnerability in NetworkEverywhere NR041 running firmware 1.2 Release 03 allows remote attackers to inject arbitrary web script or HTML via the DHCP HOSTNAME option.
|
NVD-CWE-Other
|
CVE-2004-1747
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343931
|
2.1 |
LOW
|
sysinternals
|
regmon
|
NtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid pointers to hook functions such as ZwSetQueryValue.
|
NVD-CWE-Other
|
CVE-2004-1748
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343932
|
5.0 |
MEDIUM
|
toplayer
|
attack_mitigator
|
Attack Mitigator IPS 5500 3.11.008, and possibly other versions, when configured in a one-armed routing configuration, allows remote attackers to cause a denial of service (CPU consumption) via a lar…
|
NVD-CWE-Other
|
CVE-2004-1749
|
2017-07-11 10:31 |
2004-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343933
|
5.0 |
MEDIUM
|
vnc
|
realvnc
|
RealVNC 4.0 and earlier allows remote attackers to cause a denial of service (crash) via a large number of connections to port 5900.
|
NVD-CWE-Other
|
CVE-2004-1750
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343934
|
5.0 |
MEDIUM
|
massive_entertainment
|
ground_control_ii_operation_exodus
|
Ground Control II: Operation Exodus 1.0.0.7 and earlier allows remote servers to cause a denial of service (client or server crash) via a large packet, which generates a "Message too long" socket err…
|
NVD-CWE-Other
|
CVE-2004-1751
|
2017-07-11 10:31 |
2004-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343935
|
7.5 |
HIGH
|
-
|
-
|
Stack-based buffer overflow in Gaucho 1.4 Build 145 allows remote attackers to execute arbitrary code via a POP3 email with a long Content-Type header.
|
NVD-CWE-Other
|
CVE-2004-1752
|
2017-07-11 10:31 |
2004-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343936
|
2.6 |
LOW
|
mozilla netscape
|
firefox mozilla navigator
|
The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allo…
|
NVD-CWE-Other
|
CVE-2004-1753
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343937
|
7.5 |
HIGH
|
-
|
-
|
The Web Services fat client for BEA WebLogic Server and Express 7.0 SP4 and earlier, when using 2-way SSL and multiple certificates to connect to the same URL, may use the incorrect identity after th…
|
NVD-CWE-Other
|
CVE-2004-1755
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343938
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic Server and WebLogic Express 8.1 SP2 and earlier, and 7.0 SP4 and earlier, when using 2-way SSL with a custom trust manager, may accept a certificate chain even if the trust manager rejec…
|
NVD-CWE-Other
|
CVE-2004-1756
|
2017-07-11 10:31 |
2004-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343939
|
4.6 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic Server and Express 8.1, SP1 and earlier, stores the administrator password in cleartext in config.xml, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2004-1757
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343940
|
4.6 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in co…
|
NVD-CWE-Other
|
CVE-2004-1758
|
2017-07-11 10:31 |
2004-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343941
|
5.0 |
MEDIUM
|
cisco ibm
|
emergency_responder ip_call_center_express_enhanced ip_call_center_express_standard ip_interactive_voice_response personal_assistant director_agent call_manager internet_service_…
|
Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 1…
|
CWE-399
Resource Management Errors
|
CVE-2004-1759
|
2017-07-11 10:31 |
2004-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343942
|
10.0 |
HIGH
|
cisco ibm
|
emergency_responder ip_call_center_express_enhanced ip_call_center_express_standard ip_interactive_voice_response personal_assistant director_agent call_manager internet_service_…
|
The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain adminis…
|
CWE-287
Improper Authentication
|
CVE-2004-1760
|
2017-07-11 10:31 |
2004-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343943
|
7.5 |
HIGH
|
f-secure
|
f-secure_anti-virus
|
Unknown vulnerability in F-Secure Anti-Virus (FSAV) 4.52 for Linux before Hotfix 3 allows the Sober.D worm to bypass FASV.
|
NVD-CWE-Other
|
CVE-2004-1762
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343944
|
10.0 |
HIGH
|
haht_commerce
|
hahtsite_scenario_server
|
Buffer overflow in hsrun.exe for HAHTsite Scenario Server 5.1 Patch 06 (build 91) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long project n…
|
NVD-CWE-Other
|
CVE-2004-1763
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343945
|
7.5 |
HIGH
|
mod_security
|
mod_security
|
Off-by-one buffer overflow in ModSecurity (mod_security) 1.7.4 for Apache 2.x, when SecFilterScanPost is enabled, allows remote attackers to execute arbitrary code via crafted POST requests.
|
NVD-CWE-Other
|
CVE-2004-1765
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343946
|
5.0 |
MEDIUM
|
-
|
-
|
The default installation of NetScreen-Security Manager before Feature Pack 1 does not enable encryption for communication with devices running ScreenOS 5.0, which allows remote attackers to obtain se…
|
NVD-CWE-Other
|
CVE-2004-1766
|
2017-07-11 10:31 |
2004-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343947
|
5.0 |
MEDIUM
|
symantec
|
brightmail_antispam
|
The character converters in the Spamhunter and Language ID modules for Symantec Brightmail AntiSpam 6.0.1 before patch 132 allow remote attackers to cause a denial of service (crash) via messages wit…
|
NVD-CWE-Other
|
CVE-2004-1768
|
2017-07-11 10:31 |
2004-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343948
|
10.0 |
HIGH
|
cpanel
|
cpanel
|
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the user parameter to res…
|
NVD-CWE-Other
|
CVE-2004-1769
|
2017-07-11 10:31 |
2004-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343949
|
10.0 |
HIGH
|
cpanel
|
cpanel
|
The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter.
|
NVD-CWE-Other
|
CVE-2004-1770
|
2017-07-11 10:31 |
2004-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343950
|
5.0 |
MEDIUM
|
open_group
|
scalable_ogo
|
Scalable OGo (SOGo) 1.0 allows remote authenticated users to bypass intended permissions and view private appointments of other users.
|
NVD-CWE-Other
|
CVE-2004-1771
|
2017-07-11 10:31 |
2004-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|