265131
|
- |
|
lionmax_software
|
chat_anywhere
|
LionMax Software Chat Anywhere 2.72a allows remote attackers to cause a denial of service (server crash and client CPU consumption) via a username beginning with percent (%) followed by a null charac…
|
CWE-287
Improper Authentication
|
CVE-2004-2724
|
2017-07-29 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265132
|
- |
|
aztek_forum
|
aztek_forum
|
Multiple cross-site scripting (XSS) vulnerabilities in Aztek Forum 4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter in (a) search.php, (2) the email para…
|
CWE-79
Cross-site Scripting
|
CVE-2004-2725
|
2017-07-29 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265133
|
- |
|
mailenable
|
mailenable
|
Buffer overflow in MEHTTPS (HTTPMail) of MailEnable Professional 1.5 through 1.7 allows remote attackers to cause a denial of service (application crash) via a long HTTP GET request.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2004-2727
|
2017-07-29 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265134
|
- |
|
hummingbird
|
connectivity
|
Buffer overflow in the FTP server of Hummingbird Connectivity 7.1 and 9.0 allows remote, authenticated users to cause a denial of service (application crash) via a long argument to the XCWD command.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2004-2728
|
2017-07-29 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265135
|
- |
|
hummingbird
|
connectivity
|
Inetd32 Administration Tool of Hummingbird Connectivity 7.1 and 9.0 allows local users to execute arbitrary code by changing the program for handling incoming connections.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2004-2729
|
2017-07-29 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265136
|
- |
|
microsoft
|
psexec psgetsid psinfo pskill pslist psloglist pspasswd psservice psshutdown pssuspend sysinternals_pstools
|
Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) Ps…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2004-2730
|
2017-07-29 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265137
|
- |
|
netbilling
|
netbilling
|
nbmember.cgi in Netbilling 2.0 allows remote attackers to obtain sensitive information via the cmd=test option, which can be leveraged to determine the access key.
|
CWE-78
OS Command
|
CVE-2004-2732
|
2017-07-29 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265138
|
- |
|
webwiz
|
web_wiz_forums
|
Web Wiz Forums 7.7a uses invalid logic to determine user privileges, which allows remote attackers to (1) block arbitrary IP addresses via pop_up_ip_blocking.asp or (2) modify topics via pop_up_topic…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2004-2733
|
2017-07-29 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265139
|
- |
|
novell
|
netware
|
webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access …
|
CWE-287
Improper Authentication
|
CVE-2004-2734
|
2017-07-29 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265140
|
- |
|
fredric_fredricson
|
p4db
|
Cross-site scripting (XSS) vulnerability in P4DB 2.01 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) SET_PREFERENCES parameter in SetPreferences.cgi; (2) BRANCH pa…
|
CWE-79
Cross-site Scripting
|
CVE-2004-2735
|
2017-07-29 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|