268101
|
- |
|
postnuke_software_foundation
|
postnuke
|
SQL injection vulnerability in PostNuke 7.2.6 and earlier allows remote attackers to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset paramete…
|
NVD-CWE-Other
|
CVE-2004-1949
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268102
|
- |
|
phpbb_group
|
phpbb
|
phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.
|
NVD-CWE-Other
|
CVE-2004-1950
|
2017-07-11 10:31 |
2004-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268103
|
- |
|
xine
|
xine xine-lib xine-ui
|
xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename option…
|
NVD-CWE-Other
|
CVE-2004-1951
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268104
|
- |
|
advanced_guestbook
|
advanced_guestbook
|
SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password.
|
NVD-CWE-Other
|
CVE-2004-1952
|
2017-07-11 10:31 |
2004-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268105
|
- |
|
phprofession
|
phprofession
|
phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error message.
|
NVD-CWE-Other
|
CVE-2004-1953
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268106
|
- |
|
phprofession
|
phprofession
|
Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML via the jcode parameter.
|
NVD-CWE-Other
|
CVE-2004-1954
|
2017-07-11 10:31 |
2004-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268107
|
- |
|
phprofession
|
phprofession
|
SQL injection vulnerability in modules.php in phProfession 2.5 allows remote attackers to execute arbitrary SQL code via the offset parameter.
|
NVD-CWE-Other
|
CVE-2004-1955
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268108
|
- |
|
postnuke_software_foundation
|
postnuke
|
PostNuke 0.7.2.6 allows remote attackers to gain information via a direct HTTP request to files in the (1) includes/blocks directory, (2) pnadodb directory, (3) NS-NewUser module, (4) NS-Your_Account…
|
NVD-CWE-Other
|
CVE-2004-1956
|
2017-07-11 10:31 |
2004-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268109
|
- |
|
-
|
-
|
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web script or HTML via the (1) lid and query parameters to the Downloads module, (2) …
|
NVD-CWE-Other
|
CVE-2004-1957
|
2017-07-11 10:31 |
2004-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268110
|
- |
|
epic_games
|
unreal_engine unreal_tournament unreal_tournament_2003
|
Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in a UMOD (Unreal MOD) file.
|
NVD-CWE-Other
|
CVE-2004-1958
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|