|
344001
|
7.5 |
HIGH
|
-
|
-
|
SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1) resend.asp or (2) news_view.asp.
|
NVD-CWE-Other
|
CVE-2004-1843
|
2017-07-11 10:31 |
2004-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344002
|
4.3 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in Member Management System 2.1 allows remote attackers to inject arbitrary web script or HTML via (1) the err parameter to error.asp or (2) register.asp.
|
NVD-CWE-Other
|
CVE-2004-1844
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344003
|
4.3 |
MEDIUM
|
expinion.net
|
news_manager_lite
|
Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search p…
|
NVD-CWE-Other
|
CVE-2004-1845
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344004
|
7.5 |
HIGH
|
expinion.net
|
news_manager_lite
|
Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via the (1) ID parameter to more.asp, (2) ID parameter to category_news.asp, or (3…
|
NVD-CWE-Other
|
CVE-2004-1846
|
2017-07-11 10:31 |
2004-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344005
|
7.5 |
HIGH
|
-
|
-
|
News Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN parameter in the NEWS_LOGIN cookie.
|
NVD-CWE-Other
|
CVE-2004-1847
|
2017-07-11 10:31 |
2004-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344006
|
4.3 |
MEDIUM
|
cpanel
|
cpanel
|
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to dodelautores.html or (2) handle parame…
|
NVD-CWE-Other
|
CVE-2004-1849
|
2017-07-11 10:31 |
2004-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344007
|
5.0 |
MEDIUM
|
fluidgames
|
the_rage
|
The Rage 1.01 and earlier allows remote attackers to cause a denial of service (infinite loop) via a TCP packet with the port and IP address set to zero.
|
NVD-CWE-Other
|
CVE-2004-1850
|
2017-07-11 10:31 |
2004-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344008
|
7.5 |
HIGH
|
dameware_development
|
mini_remote_control_server
|
Dameware Mini Remote Control 4.1.0.0 uses insufficiently random data to create the encryption key, which makes it easier for remote attackers to obtain sensitive information via brute force guessing.
|
NVD-CWE-Other
|
CVE-2004-1851
|
2017-07-11 10:31 |
2004-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344009
|
5.0 |
MEDIUM
|
atari
|
terminator_3_war_of_the_machines
|
Buffer overflow in Terminator 3: War of the Machines 1.0 allows remote attackers to cause a denial of service via a long ServerInfo variable.
|
NVD-CWE-Other
|
CVE-2004-1853
|
2017-07-11 10:31 |
2004-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344010
|
7.5 |
HIGH
|
picophone
|
internet_telephone
|
Buffer overflow in the logging function in Picophone 1.63 and earlier allows remote attackers to execute arbitrary code via a large packet.
|
NVD-CWE-Other
|
CVE-2004-1854
|
2017-07-11 10:31 |
2004-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344011
|
5.0 |
MEDIUM
|
mythic_entertainment
|
dark_age_of_camelot
|
Dark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers to gain sensitive information via a man-in-the-middle attack.
|
NVD-CWE-Other
|
CVE-2004-1855
|
2017-07-11 10:31 |
2004-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344012
|
5.0 |
MEDIUM
|
hp
|
web_jetadmin
|
devices_update_printer_fw_upload.hts in HP Web JetAdmin 7.5.2546, when no password is set, allows remote attackers to upload arbitrary files to the printer directory.
|
NVD-CWE-Other
|
CVE-2004-1856
|
2017-07-11 10:31 |
2004-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344013
|
2.1 |
LOW
|
hp
|
web_jetadmin
|
Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to read arbitrary files via a .. (dot dot) in the setinclude parameter.
|
NVD-CWE-Other
|
CVE-2004-1857
|
2017-07-11 10:31 |
2004-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344014
|
5.0 |
MEDIUM
|
trend_micro
|
interscan_viruswall_for_windows_nt
|
Directory traversal vulnerability in Trend Micro Interscan Web Viruswall in InterScan VirusWall 3.5x allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
|
NVD-CWE-Other
|
CVE-2004-1859
|
2017-07-11 10:31 |
2004-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344015
|
5.0 |
MEDIUM
|
xmb_forum
|
xmb
|
Buffer overflow in Check Point SmartDashboard in Check Point NG AI R54 and R55 allows remote authenticated users to cause a denial of service (server disconnect) and possibly execute arbitrary code v…
|
NVD-CWE-Other
|
CVE-2004-1860
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344016
|
4.6 |
MEDIUM
|
netsupport
|
netsupport_school
|
Invision NetSupport School Pro uses a weak encryption algorithm to encrypt passwords, which allows local users to obtain passwords.
|
NVD-CWE-Other
|
CVE-2004-1861
|
2017-07-11 10:31 |
2004-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344017
|
5.0 |
MEDIUM
|
nstx
|
ip_over_dns_utility
|
nstxd in Nstx 1.1 beta3 and earlier allows remote attackers to cause a denial of service (crash) via a large packet, which triggers a null dereference.
|
NVD-CWE-Other
|
CVE-2004-1866
|
2017-07-11 10:31 |
2004-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344018
|
4.3 |
MEDIUM
|
web_fresh
|
fresh_guest_book
|
Cross-site scripting (XSS) vulnerability in guest.cgi in Fresh Guest Book allows remote attackers to inject arbitrary web script or HTML via the Name field.
|
NVD-CWE-Other
|
CVE-2004-1867
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344019
|
7.5 |
HIGH
|
esignal
|
esignal
|
Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE tag.
|
NVD-CWE-Other
|
CVE-2004-1868
|
2017-07-11 10:31 |
2004-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344020
|
5.0 |
MEDIUM
|
nival_interactive
|
etherlords etherlords_ii
|
Etherlords I 1.07 and earlier and Etherlords II 1.03 and earlier allows remote attackers to cause a denial of service (crash) by sending a packet that specifies the size for the next packet, then sen…
|
NVD-CWE-Other
|
CVE-2004-1869
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344021
|
7.5 |
HIGH
|
photopost
|
photopost_php_pro
|
Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comment…
|
NVD-CWE-Other
|
CVE-2004-1870
|
2017-07-11 10:31 |
2004-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344022
|
4.3 |
MEDIUM
|
photopost
|
photopost_php_pro
|
Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ppuser, (2) password, (3) stype, (…
|
NVD-CWE-Other
|
CVE-2004-1871
|
2017-07-11 10:31 |
2004-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344023
|
4.3 |
MEDIUM
|
webct
|
webct
|
Cross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote attackers to inject arbitrary web script or HTML via the @import URL function in a CSS style tag.
|
NVD-CWE-Other
|
CVE-2004-1872
|
2017-07-11 10:31 |
2004-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344024
|
4.3 |
MEDIUM
|
alan_ward
|
a-cart
|
Multiple cross-site scripting (XSS) vulnerabilities in (1) deliver.asp and (2) billing.asp in A-CART Pro and A-CART 2.0 allow remote attackers to inject arbitrary web script or HTML via the user info…
|
NVD-CWE-Other
|
CVE-2004-1874
|
2017-07-11 10:31 |
2004-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344025
|
9.3 |
HIGH
|
cpanel
|
cpanel
|
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to testfile.html, (2) file parameter …
|
CWE-79
Cross-site Scripting
|
CVE-2004-1875
|
2017-07-11 10:31 |
2004-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344026
|
4.6 |
MEDIUM
|
clam_anti-virus
|
clamav
|
The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.
|
NVD-CWE-Other
|
CVE-2004-1876
|
2017-07-11 10:31 |
2004-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344027
|
2.6 |
LOW
|
oracle
|
application_server http_server
|
The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the lo…
|
NVD-CWE-Other
|
CVE-2004-1877
|
2017-07-11 10:31 |
2004-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344028
|
5.0 |
MEDIUM
|
linbit_technologies
|
linbox_officeserver
|
LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl preceded by // (double leading slash).
|
NVD-CWE-Other
|
CVE-2004-1878
|
2017-07-11 10:31 |
2004-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344029
|
4.3 |
MEDIUM
|
phpkit
|
phpkit
|
Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HTML via forum messages.
|
NVD-CWE-Other
|
CVE-2004-1879
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344030
|
7.5 |
HIGH
|
cactusoft
|
cactushop
|
SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via the strItems parameter.
|
NVD-CWE-Other
|
CVE-2004-1881
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344031
|
4.3 |
MEDIUM
|
cactusoft
|
cactushop
|
Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or HTML via the strImageTag parameter.
|
NVD-CWE-Other
|
CVE-2004-1882
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344032
|
5.0 |
MEDIUM
|
ada
|
imgsvr
|
Ada Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a trailing %00 (null).
|
NVD-CWE-Other
|
CVE-2004-1887
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344033
|
5.0 |
MEDIUM
|
sgi
|
irix
|
Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via a link failure with Microsoft Windows.
|
NVD-CWE-Other
|
CVE-2004-1889
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344034
|
5.0 |
MEDIUM
|
-
|
-
|
Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via the PORT mode.
|
NVD-CWE-Other
|
CVE-2004-1890
|
2017-07-11 10:31 |
2004-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344035
|
7.5 |
HIGH
|
emule
|
emule
|
Stack-based buffer overflow in DecodeBase16 function, as used in the (1) IRC module and (2) web server in eMule 0.42d, allows remote attackers to execute arbitrary code via a long string.
|
NVD-CWE-Other
|
CVE-2004-1892
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344036
|
5.0 |
MEDIUM
|
-
|
-
|
Dreamweaver MX, when "Using Driver On Testing Server" or "Using DSN on Testing Server" is selected, uploads the mmhttpdb.asp script to the web site but does not require authentication, which allows r…
|
NVD-CWE-Other
|
CVE-2004-1893
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344037
|
2.1 |
LOW
|
-
|
-
|
TEXutil in ConTEXt, when executed with the --silent option, allows local users to overwrite arbitrary files via a symlink attack on texutil.log.
|
NVD-CWE-Other
|
CVE-2004-1894
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344038
|
2.1 |
LOW
|
suse
|
suse_linux
|
YaST Online Update (YOU) in SuSE 8.2 and 9.0 allows local users to overwrite arbitrary files via a symlink attack on you-$USER/cookies.
|
NVD-CWE-Other
|
CVE-2004-1895
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344039
|
7.6 |
HIGH
|
nullsoft
|
winamp
|
Heap-based buffer overflow in in_mod.dll in Nullsoft Winamp 2.91 through 5.02 allows remote attackers to execute arbitrary code via a Fasttracker 2 (.xm) mod media file.
|
NVD-CWE-Other
|
CVE-2004-1896
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344040
|
5.0 |
MEDIUM
|
-
|
-
|
Administration interface in Monit 1.4 through 4.2 allows remote attackers to cause a denial of service (segmentation fault) by sending a Basic Authentication request without a password, which causes …
|
NVD-CWE-Other
|
CVE-2004-1897
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344041
|
10.0 |
HIGH
|
tildeslash
|
monit
|
Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username.
|
NVD-CWE-Other
|
CVE-2004-1898
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344042
|
5.0 |
MEDIUM
|
tildeslash
|
monit
|
The administration interface in Monit 1.4 through 4.2 allows remote attackers to cause an off-by-one overflow via a POST that contains 1024 bytes.
|
NVD-CWE-Other
|
CVE-2004-1899
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344043
|
7.5 |
HIGH
|
pan_vision
|
i.g.i-2_covert_strike
|
Format string vulnerability in the logging function in IGI 2 Covert Strike server 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in RCON commands.
|
NVD-CWE-Other
|
CVE-2004-1900
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344044
|
2.1 |
LOW
|
citrix
|
metaframe_password_manager
|
The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows …
|
NVD-CWE-Other
|
CVE-2004-1902
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344045
|
10.0 |
HIGH
|
blaxxun
|
contact_3d
|
Buffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an object tag.
|
NVD-CWE-Other
|
CVE-2004-1903
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344046
|
7.5 |
HIGH
|
panda
|
activescan
|
Buffer overflow in ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to execute arbitrary code via the Internacional property followed by a long string.
|
NVD-CWE-Other
|
CVE-2004-1904
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344047
|
5.0 |
MEDIUM
|
panda
|
activescan
|
ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to cause a denial of service (crash) by calling the SetSitesFile function.
|
NVD-CWE-Other
|
CVE-2004-1905
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344048
|
5.0 |
MEDIUM
|
-
|
-
|
Mcafee FreeScan allows remote attackers to cause a denial of service and possibly arbitrary code via a long string in the ScanParam property of a COM object, which may trigger a buffer overflow.
|
NVD-CWE-Other
|
CVE-2004-1906
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344049
|
2.6 |
LOW
|
-
|
-
|
The Web Filtering functionality in Kerio Personal Firewall (KPF) 4.0.13 allows remote attackers to cause a denial of service (crash) by sending hex-encoded URLs containing "%13%12%13".
|
NVD-CWE-Other
|
CVE-2004-1907
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344050
|
5.0 |
MEDIUM
|
mcafee
|
freescan
|
McFreeScan.CoMcFreeScan.1 ActiveX object in Mcafee FreeScan allows remote attackers to obtain sensitive information via the GetSpecialFolderLocation function with certain parameters.
|
NVD-CWE-Other
|
CVE-2004-1908
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|