266481
|
- |
|
francisco_burzi
|
php-nuke
|
Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in …
|
NVD-CWE-Other
|
CVE-2004-0265
|
2017-07-11 10:30 |
2004-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266482
|
- |
|
evolutionx
|
evolutionx
|
Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP server, or (2) a long dir command to the telnet s…
|
NVD-CWE-Other
|
CVE-2004-0268
|
2017-07-11 10:30 |
2004-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266483
|
- |
|
francisco_burzi
|
php-nuke
|
SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Sea…
|
NVD-CWE-Other
|
CVE-2004-0269
|
2017-07-11 10:30 |
2004-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266484
|
- |
|
maxwebportal
|
maxwebportal
|
Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the Sen…
|
NVD-CWE-Other
|
CVE-2004-0271
|
2017-07-11 10:30 |
2004-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266485
|
- |
|
maxwebportal
|
maxwebportal
|
This vulnerability is addressed in the following product release:
MaxWebPortal, MaxWebPortal, 1.32
|
NVD-CWE-Other
|
CVE-2004-0271
|
2017-07-11 10:30 |
2004-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266486
|
- |
|
maxwebportal
|
maxwebportal
|
SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.
|
NVD-CWE-Other
|
CVE-2004-0272
|
2017-07-11 10:30 |
2004-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266487
|
- |
|
bosdev
|
bosdates
|
SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.
|
NVD-CWE-Other
|
CVE-2004-0275
|
2017-07-11 10:30 |
2004-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266488
|
- |
|
bolintech
|
dream_ftp_server
|
Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username.
|
NVD-CWE-Other
|
CVE-2004-0277
|
2017-07-11 10:30 |
2004-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266489
|
- |
|
ratbag
|
dirt_track_racing dirt_track_racing_australia dirt_track_racing_sprint_cars leadfoot world_of_outlaws_sprint_cars
|
Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet …
|
NVD-CWE-Other
|
CVE-2004-0278
|
2017-07-11 10:30 |
2004-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266490
|
- |
|
aim_sniff
|
aim_sniff
|
AIM Sniff (aimSniff.pl) 0.9b allows local users to overwrite arbitrary files via a symlink attack on /tmp/AS.log.
|
NVD-CWE-Other
|
CVE-2004-0279
|
2017-07-11 10:30 |
2004-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|