267011
|
- |
|
ubertec
|
help_center_live
|
PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) allows remote attackers to read local files and possibly execute PHP code via a URL in the SKIN_inner parameter to inc/skin.p…
|
NVD-CWE-Other
|
CVE-2004-2601
|
2017-07-11 10:32 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267012
|
- |
|
ubertec
|
help_center_live
|
PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) before 1.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the HCL_path parameter to pipe.php.
|
NVD-CWE-Other
|
CVE-2004-2602
|
2017-07-11 10:32 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267013
|
- |
|
intel hp
|
cli_auto-configuration_utility client_system_setup_utility server_configuration_wizard server_control system_setup_utility carrier_grade_server_tigpr2u carrier_grade_server_tsrlt2
|
The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter…
|
NVD-CWE-Other
|
CVE-2004-2600
|
2017-07-11 10:32 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267014
|
- |
|
ubertec
|
help_center_live
|
Successful exploitation requires that "register_globals" is enabled.
|
NVD-CWE-Other
|
CVE-2004-2602
|
2017-07-11 10:32 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267015
|
- |
|
ubertec
|
help_center_live
|
Cross-site scripting (XSS) vulnerability in the Search module in UberTec Help Center Live (HCL) allows remote attackers to inject arbitrary web script or HTML via the find parameter to index.php.
|
NVD-CWE-Other
|
CVE-2004-2603
|
2017-07-11 10:32 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267016
|
- |
|
phproxy
|
phproxy
|
Cross-site scripting (XSS) vulnerability in index.php in PHProxy allows remote attackers to inject arbitrary web script or HTML via the error parameter.
|
NVD-CWE-Other
|
CVE-2004-2604
|
2017-07-11 10:32 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267017
|
- |
|
astats
|
astats
|
aStats 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on (1) the aStats-Graphic-Signature-Generation file and (2) certain PNG image files.
|
NVD-CWE-Other
|
CVE-2004-2605
|
2017-07-11 10:32 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267018
|
- |
|
linksys
|
befsr41_v3 wrt54g
|
The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to attempt to login to an administration web page, even when the configuration sp…
|
NVD-CWE-Other
|
CVE-2004-2606
|
2017-07-11 10:32 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267019
|
- |
|
opentools
|
attachment_mod
|
Directory traversal vulnerability in the Attachment module 2.3.10 and earlier for phpBB allows remote attackers to read arbitrary files via a .. (dot dot) in the filename.
|
NVD-CWE-Other
|
CVE-2004-1399
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267020
|
- |
|
active_server_corner
|
asp_calendar
|
The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unauthorized access via a direct request to main.asp.
|
NVD-CWE-Other
|
CVE-2004-1400
|
2017-07-11 10:31 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|