268801
|
- |
|
w-agora
|
w-agora
|
list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.
|
NVD-CWE-Other
|
CVE-2004-1565
|
2016-10-18 11:56 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268802
|
- |
|
minihttpserver.net
|
web_forums_server
|
Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot sl…
|
NVD-CWE-Other
|
CVE-2004-1496
|
2016-10-18 11:55 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268803
|
- |
|
-
|
-
|
Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2004-1497
|
2016-10-18 11:55 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268804
|
- |
|
webhost_automation
|
helm_control_panel
|
SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.
|
NVD-CWE-Other
|
CVE-2004-1498
|
2016-10-18 11:55 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268805
|
- |
|
jelsoft
|
vbulletin
|
SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.
|
NVD-CWE-Other
|
CVE-2004-1515
|
2016-10-18 11:55 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268806
|
- |
|
new_media_generation
|
hired_team_trial
|
Hired Team: Trial 2.0 and earlier and 2.200 does not limit how game players can kick other players off the server, including the administrator.
|
NVD-CWE-Other
|
CVE-2004-1526
|
2016-10-18 11:55 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268807
|
- |
|
mediawiki
|
mediawiki
|
MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary c…
|
NVD-CWE-Other
|
CVE-2004-1405
|
2016-10-18 11:54 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268808
|
- |
|
singapore
|
image_gallery_web_application
|
Multiple cross-site scripting vulnerabilities in Image Gallery Web Application 0.9.10 allow remote attackers to inject arbitrary web script or HTML.
|
NVD-CWE-Other
|
CVE-2004-1409
|
2016-10-18 11:54 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268809
|
- |
|
gadu-gadu
|
gadu-gadu_instant_messenger
|
Cross-site scripting (XSS) vulnerability in Gadu-Gadu build 155 and earlier allows remote attackers to inject arbitrary web script via a URL, which is echoed in a popup window that displays a parsing…
|
NVD-CWE-Other
|
CVE-2004-1410
|
2016-10-18 11:54 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268810
|
- |
|
gadu-gadu
|
gadu-gadu_instant_messenger
|
Gadu-Gadu 6.1 build 156 allows remote attackers to cause a denial of service (application hang) via a message that contains many special strings that are converted to images.
|
NVD-CWE-Other
|
CVE-2004-1414
|
2016-10-18 11:54 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|