268191
|
- |
|
softwin
|
bitdefender
|
The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or (2) use the RequestF…
|
NVD-CWE-Other
|
CVE-2004-1947
|
2017-07-11 10:31 |
2004-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268192
|
- |
|
ncftp_software
|
ncftp
|
NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which di…
|
NVD-CWE-Other
|
CVE-2004-1948
|
2017-07-11 10:31 |
2004-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268193
|
- |
|
postnuke_software_foundation
|
postnuke
|
SQL injection vulnerability in PostNuke 7.2.6 and earlier allows remote attackers to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset paramete…
|
NVD-CWE-Other
|
CVE-2004-1949
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268194
|
- |
|
phpbb_group
|
phpbb
|
phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.
|
NVD-CWE-Other
|
CVE-2004-1950
|
2017-07-11 10:31 |
2004-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268195
|
- |
|
xine
|
xine xine-lib xine-ui
|
xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename option…
|
NVD-CWE-Other
|
CVE-2004-1951
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268196
|
- |
|
advanced_guestbook
|
advanced_guestbook
|
SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password.
|
NVD-CWE-Other
|
CVE-2004-1952
|
2017-07-11 10:31 |
2004-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268197
|
- |
|
phprofession
|
phprofession
|
phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error message.
|
NVD-CWE-Other
|
CVE-2004-1953
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268198
|
- |
|
phprofession
|
phprofession
|
Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML via the jcode parameter.
|
NVD-CWE-Other
|
CVE-2004-1954
|
2017-07-11 10:31 |
2004-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268199
|
- |
|
phprofession
|
phprofession
|
SQL injection vulnerability in modules.php in phProfession 2.5 allows remote attackers to execute arbitrary SQL code via the offset parameter.
|
NVD-CWE-Other
|
CVE-2004-1955
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268200
|
- |
|
postnuke_software_foundation
|
postnuke
|
PostNuke 0.7.2.6 allows remote attackers to gain information via a direct HTTP request to files in the (1) includes/blocks directory, (2) pnadodb directory, (3) NS-NewUser module, (4) NS-Your_Account…
|
NVD-CWE-Other
|
CVE-2004-1956
|
2017-07-11 10:31 |
2004-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|