269261
|
- |
|
phpbb_group
|
phpbb
|
phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.
|
NVD-CWE-Other
|
CVE-2004-1950
|
2017-07-11 10:31 |
2004-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269262
|
- |
|
xine
|
xine xine-lib xine-ui
|
xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename option…
|
NVD-CWE-Other
|
CVE-2004-1951
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269263
|
- |
|
advanced_guestbook
|
advanced_guestbook
|
SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password.
|
NVD-CWE-Other
|
CVE-2004-1952
|
2017-07-11 10:31 |
2004-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269264
|
- |
|
phprofession
|
phprofession
|
phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error message.
|
NVD-CWE-Other
|
CVE-2004-1953
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269265
|
- |
|
phprofession
|
phprofession
|
Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML via the jcode parameter.
|
NVD-CWE-Other
|
CVE-2004-1954
|
2017-07-11 10:31 |
2004-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269266
|
- |
|
phprofession
|
phprofession
|
SQL injection vulnerability in modules.php in phProfession 2.5 allows remote attackers to execute arbitrary SQL code via the offset parameter.
|
NVD-CWE-Other
|
CVE-2004-1955
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269267
|
- |
|
postnuke_software_foundation
|
postnuke
|
PostNuke 0.7.2.6 allows remote attackers to gain information via a direct HTTP request to files in the (1) includes/blocks directory, (2) pnadodb directory, (3) NS-NewUser module, (4) NS-Your_Account…
|
NVD-CWE-Other
|
CVE-2004-1956
|
2017-07-11 10:31 |
2004-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269268
|
- |
|
-
|
-
|
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web script or HTML via the (1) lid and query parameters to the Downloads module, (2) …
|
NVD-CWE-Other
|
CVE-2004-1957
|
2017-07-11 10:31 |
2004-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269269
|
- |
|
epic_games
|
unreal_engine unreal_tournament unreal_tournament_2003
|
Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in a UMOD (Unreal MOD) file.
|
NVD-CWE-Other
|
CVE-2004-1958
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269270
|
- |
|
protector_system
|
protector_system
|
blocker_query.php in Protector System 1.15b1 for PHP-Nuke allows remote attackers to gain sensitive information via a string in the portNum parameter, which reveals the full path in an error message.
|
NVD-CWE-Other
|
CVE-2004-1959
|
2017-07-11 10:31 |
2004-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|