272681
|
- |
|
futuresoft
|
tftp_server_2000
|
Directory traversal vulnerability in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allows remote attackers to read arbitrary files via a TFTP GET request containing (1) "../" (dot dot slash) or (…
|
CWE-22
Path Traversal
|
CVE-2005-1813
|
2008-09-5 13:00 |
2005-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
272682
|
- |
|
apache
|
derby
|
Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMetaData.getURL functio…
|
CWE-200
Information Exposure
|
CVE-2005-4849
|
2008-09-5 13:00 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
272683
|
- |
|
macromedia
|
jrun
|
Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information used by the session server.
|
CWE-287
Improper Authentication
|
CVE-2004-2182
|
2008-09-5 13:00 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
272684
|
- |
|
intersystems
|
cache
|
Unspecified vulnerability in the %XML.Utils.SchemaServer class in InterSystems Cache' 5.0 allows attackers to access arbitrary files on a server.
|
NVD-CWE-noinfo
|
CVE-2004-2683
|
2008-09-5 13:00 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
272685
|
- |
|
intersystems
|
cache_database
|
Unspecified vulnerability in the %template package in InterSystems Cache' 5.0 allows attackers to access certain files on a server, including (1) cache.key and (2) cache.dat, related to .csp files un…
|
NVD-CWE-noinfo
|
CVE-2004-2684
|
2008-09-5 13:00 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
272686
|
- |
|
apple samba
|
xcode samba
|
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed …
|
CWE-16
Configuration
|
CVE-2004-2687
|
2008-09-5 13:00 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
272687
|
- |
|
aspdotnetstorefront
|
aspdotnetstorefront
|
Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2004-2700
|
2008-09-5 13:00 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
272688
|
- |
|
phrozensmoke
|
gyach_enhanced
|
Unspecified vulnerability in Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service (crash) via conference packets with error messages.
|
NVD-CWE-noinfo CWE-20
Improper Input Validation
|
CVE-2004-2706
|
2008-09-5 13:00 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
272689
|
- |
|
ibm
|
aix
|
Unspecified vulnerability in crontab in IBM AIX 3.2 allows local users to gain root privileges via unknown attack vectors.
|
NVD-CWE-noinfo
|
CVE-1999-1589
|
2008-09-5 13:00 |
1999-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
272690
|
- |
|
coxco_support
|
a-cart metacart midicart_asp midicart_asp_maxi midicart_asp_plus salescart-pro salescart-std
|
MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly requesting the database.
|
CWE-200
Information Exposure
|
CVE-2002-1432
|
2008-09-5 13:00 |
2003-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|