|
343951
|
7.2 |
HIGH
|
oracle
|
application_server oracle10g
|
Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users to execute arbitrary code via a long LAYER paramet…
|
NVD-CWE-Other
|
CVE-2004-1774
|
2017-07-11 10:31 |
2004-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343952
|
5.0 |
MEDIUM
|
cisco
|
ios catos
|
Cisco VACM (View-based Access Control MIB) for Catalyst Operating Software (CatOS) 5.5 and 6.1 and IOS 12.0 and 12.1 allows remote attackers to read and modify device configuration via the read-write…
|
NVD-CWE-Other
|
CVE-2004-1775
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343953
|
7.5 |
HIGH
|
cisco
|
ios
|
Cisco IOS 12.1(3) and 12.1(3)T allows remote attackers to read and modify device configuration data via the cable-docsis read-write community string used by the Data Over Cable Service Interface Spec…
|
NVD-CWE-Other
|
CVE-2004-1776
|
2017-07-11 10:31 |
2001-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343954
|
4.3 |
MEDIUM
|
thwboard
|
thwboard_beta
|
Cross-site scripting (XSS) vulnerability in board.php for ThWboard before beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the lastvisited parameter.
|
NVD-CWE-Other
|
CVE-2004-1779
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343955
|
7.5 |
HIGH
|
webcam_corp
|
webcam_watchdog
|
Buffer overflow in the web server of Webcam Watchdog 3.63 allows remote attackers to execute arbitrary code via a long HTTP GET request.
|
NVD-CWE-Other
|
CVE-2004-1784
|
2017-07-11 10:31 |
2004-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343956
|
5.0 |
MEDIUM
|
iatek
|
portalapp
|
PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb.
|
NVD-CWE-Other
|
CVE-2004-1786
|
2017-07-11 10:31 |
2004-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343957
|
7.5 |
HIGH
|
postnuke_software_foundation
|
postcalendar
|
SQL injection vulnerability in PostCalendar 4.0.0 allows remote attackers to execute arbitrary SQL commands via search queries.
|
NVD-CWE-Other
|
CVE-2004-1787
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343958
|
4.3 |
MEDIUM
|
zyxel
|
zywall10
|
Cross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to inject arbitrary web script or HTML via the rpAuth_1 page.
|
NVD-CWE-Other
|
CVE-2004-1789
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343959
|
4.3 |
MEDIUM
|
edimax
|
full_rate_adsl_router
|
Cross-site scripting (XSS) vulnerability in the web management interface in Edimax AR-6004 ADSL Routers allows remote attackers to inject arbitrary web script or HTML via the URL.
|
NVD-CWE-Other
|
CVE-2004-1790
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343960
|
5.0 |
MEDIUM
|
yatsoft
|
switch_off
|
swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a long packet with two CRLF sequences to the service management port (TCP 8000).
|
NVD-CWE-Other
|
CVE-2004-1792
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343961
|
7.5 |
HIGH
|
yatsoft
|
switch_off
|
Stack-based buffer overflow in swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote authenticated users to execute arbitrary code via a long message parameter in a SendMsg action to action.ht…
|
NVD-CWE-Other
|
CVE-2004-1793
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343962
|
4.3 |
MEDIUM
|
vcard4j
|
vcard4j
|
Cross-site scripting (XSS) vulnerability in the VCard4J Toolkit allows remote attackers to inject arbitrary web script or HTML via the NICKNAME tag in a vCard.
|
NVD-CWE-Other
|
CVE-2004-1794
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343963
|
7.5 |
HIGH
|
hotnews
|
hotnews
|
PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header] parameter to hotnews-engine.inc.php3 or (2) confi…
|
NVD-CWE-Other
|
CVE-2004-1796
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343964
|
4.3 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.
|
NVD-CWE-Other
|
CVE-2004-1797
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343965
|
7.5 |
HIGH
|
-
|
-
|
Unknown vulnerability in Sysbotz SimpleData 4.0.1 and possibly earlier versions allows remote attackers to gain access via a crafted URL and a certain cookie.
|
NVD-CWE-Other
|
CVE-2004-1800
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343966
|
5.0 |
MEDIUM
|
pwebserver
|
pwebserver_web_server
|
Directory traversal vulnerability in PWebServer 0.3.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
|
NVD-CWE-Other
|
CVE-2004-1801
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343967
|
5.0 |
MEDIUM
|
-
|
-
|
Chat Anywhere 2.72 and earlier allows remote attackers to hide their IP address by using %00 before the nickname, which causes the IP address to be displayed as $IP$ on the administration web page.
|
NVD-CWE-Other
|
CVE-2004-1802
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343968
|
5.0 |
MEDIUM
|
invicta
|
wmcam_server
|
wMCam server 2.1.348 allows remote attackers to cause a denial of service (no new connections) via multiple malformed HTTP requests without the GET command.
|
NVD-CWE-Other
|
CVE-2004-1804
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343969
|
5.0 |
MEDIUM
|
epic_games
|
unreal_engine
|
Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifie…
|
NVD-CWE-Other
|
CVE-2004-1805
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343970
|
7.5 |
HIGH
|
dogpatch_software
|
cfwebstore
|
SQL injection vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to execute SQL commands via the (1) category_id, (2) product_id, or (3) feature_id parameters.
|
NVD-CWE-Other
|
CVE-2004-1806
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343971
|
4.3 |
MEDIUM
|
dogpatch_software
|
cfwebstore
|
Cross-site scripting (XSS) vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to inject arbitrary web script or HTML via the URL.
|
NVD-CWE-Other
|
CVE-2004-1807
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343972
|
2.1 |
LOW
|
metamail_corporation
|
metamail
|
Extcompose in metamail does not verify the output file before writing to it, which allows local users to overwrite arbitrary files via a symlink attack.
|
NVD-CWE-Other
|
CVE-2004-1808
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343973
|
4.3 |
MEDIUM
|
phpbb_group
|
phpbb
|
Cross-site scripting (XSS) vulnerability in phpBB 2.0.6d and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) postdays parameter to viewtopic.php or (2) topicdays pa…
|
NVD-CWE-Other
|
CVE-2004-1809
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343974
|
7.5 |
HIGH
|
hp
|
ssl_http_server
|
The SSL HTTP Server in HP Web-enabled Management Software 5.0 through 5.92, with anonymous access enabled, allows remote attackers to compromise the trusted certificates by uploading their own certif…
|
NVD-CWE-Other
|
CVE-2004-1811
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343975
|
7.5 |
HIGH
|
vocaltec
|
vgw4_8_telephony_gateway
|
VocalTec VGW4/8 Gateway 8.0 allows remote attackers to bypass authentication via an HTTP request to home.asp with a trailing slash (/).
|
NVD-CWE-Other
|
CVE-2004-1813
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343976
|
5.0 |
MEDIUM
|
vocaltec
|
vgw4_8_telephony_gateway
|
Directory traversal vulnerability in VocalTec VGW4/8 Gateway 8.0 allows remote attackers to read protected files via .. (dot dot) sequences in an HTTP request, as demonstrated using home.asp.
|
NVD-CWE-Other
|
CVE-2004-1814
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343977
|
5.0 |
MEDIUM
|
macromedia sun
|
coldfusion jrun one_application_server
|
Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory cons…
|
NVD-CWE-Other
|
CVE-2004-1815
|
2017-07-11 10:31 |
2004-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343978
|
5.0 |
MEDIUM
|
-
|
-
|
Unknown vulnerability in Sun Java System Application Server 7.0 Update 2 and earlier, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of …
|
NVD-CWE-Other
|
CVE-2004-1816
|
2017-07-11 10:31 |
2004-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343979
|
4.3 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
Cross-site scripting (XSS) vulnerability in modules.php in Php-Nuke 7.1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) Your Name field, (2) e-mail field, (3) nicname fie…
|
NVD-CWE-Other
|
CVE-2004-1817
|
2017-07-11 10:31 |
2004-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343980
|
6.8 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary script as other users by injecting arbitrary script i…
|
NVD-CWE-Other
|
CVE-2004-1818
|
2017-07-11 10:31 |
2004-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343981
|
5.0 |
MEDIUM
|
warpspeed
|
4nalbum_module
|
4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to obtain sensitive information via a direct request to displaycategory.php, which reveals the path in an error message.
|
NVD-CWE-Other
|
CVE-2004-1819
|
2017-07-11 10:31 |
2004-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343982
|
7.5 |
HIGH
|
warpspeed
|
4nalbum_module
|
PHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary PHP code by modifying the basepath parameter t…
|
NVD-CWE-Other
|
CVE-2004-1820
|
2017-07-11 10:31 |
2004-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343983
|
7.5 |
HIGH
|
warpspeed
|
4nalbum_module
|
SQL injection vulnerability in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to gain privileges or perform unauthorized database operations via the gid parameter.
|
NVD-CWE-Other
|
CVE-2004-1821
|
2017-07-11 10:31 |
2004-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343984
|
4.3 |
MEDIUM
|
phorum
|
phorum
|
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_REFERER parameter to login.php, (2)…
|
NVD-CWE-Other
|
CVE-2004-1822
|
2017-07-11 10:31 |
2004-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343985
|
4.3 |
MEDIUM
|
jelsoft
|
vbulletin
|
Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4 allows remote attackers to inject arbitrary web script or HTML via the (1) page parameter to showt…
|
NVD-CWE-Other
|
CVE-2004-1823
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343986
|
4.3 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.0 allows remote attackers to inject arbitrary web script or HTML via the what parameter to memberlist.php.
|
NVD-CWE-Other
|
CVE-2004-1824
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343987
|
4.3 |
MEDIUM
|
mambo
|
mambo_open_source
|
Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_ch…
|
NVD-CWE-Other
|
CVE-2004-1825
|
2017-07-11 10:31 |
2004-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343988
|
7.5 |
HIGH
|
mambo
|
mambo_open_source_4.5
|
SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2004-1826
|
2017-07-11 10:31 |
2004-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343989
|
5.0 |
MEDIUM
|
belchior_foundry
|
vcard
|
Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and delete database tables via a direct request to uni…
|
NVD-CWE-Other
|
CVE-2004-1828
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343990
|
4.3 |
MEDIUM
|
error_manager
|
php-nuke_module
|
Multiple cross-site scripting (XSS) vulnerabilities in error.php in Gijza.net Error Manager 2.1 for PHP-Nuke 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pagetitle or…
|
NVD-CWE-Other
|
CVE-2004-1829
|
2017-07-11 10:31 |
2004-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343991
|
5.0 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a …
|
NVD-CWE-Other
|
CVE-2004-1830
|
2017-07-11 10:31 |
2004-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343992
|
5.0 |
MEDIUM
|
techland
|
chrome
|
Buffer overflow in Chrome 1.2.0.0 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large length value, which leads to a null dereference or out-of-bounds r…
|
NVD-CWE-Other
|
CVE-2004-1831
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343993
|
5.0 |
MEDIUM
|
apple
|
mac_os_x_server
|
Buffer overflow in the GUI admin service in Mac OS X Server 10.3 allows remote attackers to cause a denial of service (crash and restart) via a large amount of data to TCP port 660.
|
NVD-CWE-Other
|
CVE-2004-1832
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343994
|
7.5 |
HIGH
|
borland_software
|
interbase
|
The admin.ib file in Borland Interbase 7.1 for Linux has default world writable permissions, which allows local users to gain database administrative privileges.
|
NVD-CWE-Other
|
CVE-2004-1833
|
2017-07-11 10:31 |
2004-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343995
|
7.5 |
HIGH
|
invision_power_services
|
invision_gallery
|
Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) a…
|
NVD-CWE-Other
|
CVE-2004-1835
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343996
|
7.5 |
HIGH
|
invision_power_services
|
invision_power_top_site_list
|
SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments action.
|
NVD-CWE-Other
|
CVE-2004-1836
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343997
|
4.3 |
MEDIUM
|
joel_palmius
|
mod_survey
|
Cross-site scripting (XSS) vulnerability in Mod_survey 3.0.x before 3.0.16-pre2 and 3.2.x before 3.2.0-pre4 allows remote attackers to inject arbitrary web script or HTML via the certain survey field…
|
NVD-CWE-Other
|
CVE-2004-1837
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343998
|
5.0 |
MEDIUM
|
xweb
|
xweb
|
Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the URL.
|
NVD-CWE-Other
|
CVE-2004-1838
|
2017-07-11 10:31 |
2004-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343999
|
4.3 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
Multiple cross-site scripting (XSS) vulnerabilities in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) screen parameter to modules.php, …
|
NVD-CWE-Other
|
CVE-2004-1840
|
2017-07-11 10:31 |
2004-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344000
|
7.5 |
HIGH
|
ms_analysis
|
website_traffic_analyzer
|
SQL injection vulnerability in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL via the referer field in an HTTP request.
|
NVD-CWE-Other
|
CVE-2004-1841
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|