266021
|
- |
|
3com
|
3cradsl72
|
The 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as passwords and router settings via a direct HTTP request to app_sta.stm.
|
NVD-CWE-Other
|
CVE-2004-1596
|
2017-07-11 10:31 |
2004-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266022
|
- |
|
adobe
|
acrobat acrobat_reader
|
Adobe Acrobat and Acrobat Reader 6.0 allow remote attackers to read arbitrary files via a PDF file that contains an embedded Shockwave (swf) file that references files outside of the temporary direct…
|
NVD-CWE-Other
|
CVE-2004-1598
|
2017-07-11 10:31 |
2004-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266023
|
- |
|
coolphp
|
coolphpweb_portal
|
Cross-site scripting (XSS) vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to execute arbitrary web script or HTML via the (1) query or (2) nick parameters.
|
NVD-CWE-Other
|
CVE-2004-1599
|
2017-07-11 10:31 |
2004-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266024
|
- |
|
coolphp
|
coolphp
|
index.php in CoolPHP 1.0-stable allows remote attackers to gain sensitive information via an invalid op parameter, which reveals the path in an error message.
|
NVD-CWE-Other
|
CVE-2004-1600
|
2017-07-11 10:31 |
2004-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266025
|
- |
|
coolphp
|
coolphp_web_portal
|
Directory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files and execute local PHP scripts via a .. (dot dot) in the op parameter.
|
NVD-CWE-Other
|
CVE-2004-1601
|
2017-07-11 10:31 |
2004-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266026
|
- |
|
best_software saleslogix_corporation
|
saleslogix
|
SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator.
|
NVD-CWE-Other
|
CVE-2004-1605
|
2017-07-11 10:31 |
2004-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266027
|
- |
|
best_software saleslogix_corporation
|
saleslogix
|
slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the ErrorLogMsg cookie.
|
NVD-CWE-Other
|
CVE-2004-1606
|
2017-07-11 10:31 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266028
|
- |
|
best_software saleslogix_corporation
|
saleslogix
|
slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error mes…
|
NVD-CWE-Other
|
CVE-2004-1607
|
2017-07-11 10:31 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266029
|
- |
|
best_software saleslogix_corporation
|
saleslogix
|
SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation.
|
NVD-CWE-Other
|
CVE-2004-1608
|
2017-07-11 10:31 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266030
|
- |
|
best_software saleslogix_corporation
|
saleslogix
|
SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.
|
NVD-CWE-Other
|
CVE-2004-1609
|
2017-07-11 10:31 |
2004-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|