266601
|
- |
|
intel hp
|
cli_auto-configuration_utility client_system_setup_utility server_configuration_wizard server_control system_setup_utility carrier_grade_server_tigpr2u carrier_grade_server_tsrlt2
|
The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter…
|
NVD-CWE-Other
|
CVE-2004-2600
|
2017-07-11 10:32 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266602
|
- |
|
ubertec
|
help_center_live
|
Successful exploitation requires that "register_globals" is enabled.
|
NVD-CWE-Other
|
CVE-2004-2602
|
2017-07-11 10:32 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266603
|
- |
|
ubertec
|
help_center_live
|
Cross-site scripting (XSS) vulnerability in the Search module in UberTec Help Center Live (HCL) allows remote attackers to inject arbitrary web script or HTML via the find parameter to index.php.
|
NVD-CWE-Other
|
CVE-2004-2603
|
2017-07-11 10:32 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266604
|
- |
|
phproxy
|
phproxy
|
Cross-site scripting (XSS) vulnerability in index.php in PHProxy allows remote attackers to inject arbitrary web script or HTML via the error parameter.
|
NVD-CWE-Other
|
CVE-2004-2604
|
2017-07-11 10:32 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266605
|
- |
|
astats
|
astats
|
aStats 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on (1) the aStats-Graphic-Signature-Generation file and (2) certain PNG image files.
|
NVD-CWE-Other
|
CVE-2004-2605
|
2017-07-11 10:32 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266606
|
- |
|
linksys
|
befsr41_v3 wrt54g
|
The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to attempt to login to an administration web page, even when the configuration sp…
|
NVD-CWE-Other
|
CVE-2004-2606
|
2017-07-11 10:32 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266607
|
- |
|
opentools
|
attachment_mod
|
Directory traversal vulnerability in the Attachment module 2.3.10 and earlier for phpBB allows remote attackers to read arbitrary files via a .. (dot dot) in the filename.
|
NVD-CWE-Other
|
CVE-2004-1399
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266608
|
- |
|
active_server_corner
|
asp_calendar
|
The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unauthorized access via a direct request to main.asp.
|
NVD-CWE-Other
|
CVE-2004-1400
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266609
|
- |
|
asp-rider
|
asp-rider
|
SQL injection vulnerability in verify.asp in Asp-rider allows remote attackers to execute arbitrary SQL statements and bypass authentication via the username parameter.
|
NVD-CWE-Other
|
CVE-2004-1401
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266610
|
- |
|
iwebnegar
|
iwebnegar
|
SQL injection vulnerability in iWebNegar allows remote attackers to execute arbitrary SQL commands via (1) the string parameter for index.php, (2) comments.php, or (3) the administrator login page.
|
NVD-CWE-Other
|
CVE-2004-1402
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|