|
313401
|
5.0 |
MEDIUM
|
soft3304
|
04webserver
|
Soft3304 04WebServer before 1.41 does not properly check file names, which allows remote attackers to obtain sensitive information (CGI source code).
|
NVD-CWE-Other
|
CVE-2004-2661
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313402
|
5.0 |
MEDIUM
|
soft3304
|
04webserver
|
Soft3304 04WebServer before 1.41 allows remote attackers to cause a denial of service (resource consumption or crash) via certain data related to OpenSSL, which causes a thread to terminate but conti…
|
NVD-CWE-Other
|
CVE-2004-2662
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313403
|
5.0 |
MEDIUM
|
john_lim
|
adodb
|
John Lim ADOdb Library for PHP before 4.23 allows remote attackers to obtain sensitive information via direct requests to certain scripts that result in an undefined value of ADODB_DIR, which reveals…
|
NVD-CWE-Other
|
CVE-2004-2664
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313404
|
5.0 |
MEDIUM
|
john_lim
|
adodb
|
This vulnerability is addressed in the following product release:
John Lim, ADOdb, 4.23
|
NVD-CWE-Other
|
CVE-2004-2664
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313405
|
5.0 |
MEDIUM
|
mantis
|
mantis
|
Mantis before 20041016 provides a complete Issue History (Bug History) in the web interface regardless of view_history_threshold, which allows remote attackers to obtain sensitive information (privat…
|
NVD-CWE-Other
|
CVE-2004-2666
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313406
|
6.8 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in Lotus Domino 6.0.x before 6.0.4 and 6.5.x before 6.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2004-2667
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313407
|
7.5 |
HIGH
|
-
|
-
|
SQL injection vulnerability in Interchange before 4.8.9 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
|
NVD-CWE-Other
|
CVE-2004-2668
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313408
|
7.5 |
HIGH
|
argosoft
|
ftp_server
|
Unspecified vulnerability in ArGoSoft FTP server before 1.4.2.2 allows attackers to upload .lnk files via unknown vectors.
|
NVD-CWE-Other
|
CVE-2004-2672
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313409
|
7.5 |
HIGH
|
argosoft
|
ftp_server
|
This vulnerability is addressed in the following product release:
ArGoSoft, FTP server, 1.4.2.2
|
NVD-CWE-Other
|
CVE-2004-2672
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313410
|
5.8 |
MEDIUM
|
peersec_networks
|
matrixssl
|
PeerSec MatrixSSL before 1.1 does not implement RSA blinding, which allows context-dependent attackers to obtain the server's private key by determining factors using timing differences on (1) the nu…
|
NVD-CWE-Other
|
CVE-2004-2682
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313411
|
5.0 |
MEDIUM
|
phrozensmoke
|
gyach_enhanced
|
Gyach Enhanced (Gyach-E) before 1.0.0 stores passwords in plaintext, which allows attackers to obtain user passwords by reading the configuration file.
|
CWE-255
証明書・パスワード管理
|
CVE-2004-2708
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313412
|
7.5 |
HIGH
|
phrozensmoke
|
gyach_enhanced
|
Buffer overflow in the strip_html_tags method for Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown vectors in…
|
CWE-119
バッファエラー
|
CVE-2004-2709
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313413
|
7.5 |
HIGH
|
phrozensmoke
|
gyach_enhanced
|
Multiple buffer overflows in Gyach Enhanced (Gyach-E) before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) sending c…
|
CWE-119
バッファエラー
|
CVE-2004-2710
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313414
|
7.5 |
HIGH
|
phrozensmoke
|
gyach_enhanced
|
Multiple buffer overflows in Gyach Enhanced (Gyach-E) before 1.0.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to "avatar retri…
|
CWE-119
バッファエラー
|
CVE-2004-2711
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313415
|
5.0 |
MEDIUM
|
phrozensmoke
|
gyach_enhanced
|
Buffer overflow in Gyach Enhanced (Gyach-E) before 1.0.0-SneakPeek-3 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to "URL data."
|
CWE-119
バッファエラー
|
CVE-2004-2712
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313416
|
4.3 |
MEDIUM
|
php_heaven
|
phpmychat
|
PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database passwords via a direct request.
|
CWE-264
認可・権限・アクセス制御
|
CVE-2004-2718
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313417
|
5.0 |
MEDIUM
|
mailenable
|
mailenable
|
HTTPMail service in MailEnable Professional 1.18 does not properly handle arguments to the Authorization header, which allows remote attackers to cause a denial of service (null dereference and appli…
|
NVD-CWE-Other
|
CVE-2004-2726
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313418
|
4.4 |
MEDIUM
|
linux
|
linux_kernel
|
Multiple integer overflows in Sbus PROM driver (drivers/sbus/char/openprom.c) for the Linux kernel 2.4.x up to 2.4.27, 2.6.x up to 2.6.7, and possibly later versions, allow local users to execute arb…
|
CWE-189
数値処理の問題
|
CVE-2004-2731
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313419
|
7.5 |
HIGH
|
zen_cart
|
zen_cart
|
SQL injection vulnerability in application_top.php for Zen Cart 1.1.3 before patch 2 may allow remote attackers to execute arbitrary SQL commands via the products_id parameter.
|
NVD-CWE-Other
|
CVE-2004-2025
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313420
|
7.2 |
HIGH
|
-
|
-
|
The Altiris Client Service for Windows 5.6 SP1 Hotfix E (5.6.181) allows local users to execute arbitrary commands by opening the AClient tray icon and using the View Log File option, a different vul…
|
NVD-CWE-Other
|
CVE-2004-2070
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313421
|
5.0 |
MEDIUM
|
microsoft
|
baseline_security_analyzer
|
Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administr…
|
NVD-CWE-Other
|
CVE-2004-2091
|
2008-09-6 05:43 |
2004-02-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313422
|
5.0 |
MEDIUM
|
symantec
|
norton_antivirus
|
Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) without a carriage ret…
|
NVD-CWE-Other
|
CVE-2004-2147
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313423
|
6.4 |
MEDIUM
|
xmlstarlet
|
command_line_xml_toolkit
|
Format string vulnerability in xml_elem.c for XMLStarlet Command Line XML Toolkit 0.9.3 may allow attackers to cause a denial of service or execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2004-2160
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313424
|
4.6 |
MEDIUM
|
microsoft
|
windows_xp
|
The Internet Connection Firewall (ICF) in Microsoft Windows XP SP2 is configured by default to trust sessmgr.exe, which allows local users to use sessmgr.exe to create a local listening port that byp…
|
NVD-CWE-Other
|
CVE-2004-2176
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313425
|
4.3 |
MEDIUM
|
devoybb
|
devoybb_web_forum
|
Cross-site scripting (XSS) vulnerability in DevoyBB Web Forum 1.0.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2004-2177
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313426
|
7.5 |
HIGH
|
devoybb
|
devoybb_web_forum
|
SQL injection vulnerability in DevoyBB Web Forum 1.0.0 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
|
NVD-CWE-Other
|
CVE-2004-2178
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313427
|
5.0 |
MEDIUM
|
microsoft
|
frontpage ie
|
asycpict.dll, as used in Microsoft products such as Front Page 97 and 98, allows remote attackers to cause a denial of service (hang) via a JPEG image with maximum height and width values.
|
NVD-CWE-Other
|
CVE-2004-2179
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313428
|
4.3 |
MEDIUM
|
wowbb
|
wowbb_web_forum
|
Multiple cross-site scripting (XSS) vulnerabilities in WowBB Forum 1.61 allow remote attackers to inject arbitrary web script or HTML via the (1) country parameter to view_user.php, (2) show paramete…
|
NVD-CWE-Other
|
CVE-2004-2180
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313429
|
7.5 |
HIGH
|
wehelpbus
|
wehelpbus
|
Unknown vulnerability in WeHelpBUS 0.1 allows remote attackers to execute arbitrary shell commands via the query string.
|
NVD-CWE-Other
|
CVE-2004-2183
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313430
|
6.8 |
MEDIUM
|
mediawiki
|
mediawiki
|
Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki 1.3.5 allow remote attackers to execute arbitrary scripts and/or SQL queries via (1) the UnicodeConverter extension, (2) raw page view…
|
NVD-CWE-Other
|
CVE-2004-2185
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313431
|
7.5 |
HIGH
|
mediawiki
|
mediawiki
|
SQL injection vulnerability in MediaWiki 1.3.5 allows remote attackers to execute arbitrary SQL commands via SpecialMaintenance.
|
NVD-CWE-Other
|
CVE-2004-2186
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313432
|
5.0 |
MEDIUM
|
mediawiki
|
mediawiki
|
Unknown vulnerability in ImagePage for MediaWiki 1.3.5, related to "filename validation," has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2004-2187
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313433
|
7.5 |
HIGH
|
dmxready
|
dmxready_site_chassis_manager
|
SQL injection vulnerability in DMXReady Site Chassis Manager allows remote attackers to execute arbitrary SQL commands via unknown vectors.
|
NVD-CWE-Other
|
CVE-2004-2189
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313434
|
5.0 |
MEDIUM
|
unzoo
|
unzoo
|
Directory traversal vulnerability in Unzoo 4.4-2 has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2004-2190
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313435
|
5.0 |
MEDIUM
|
mailenable
|
mailenable_enterprise mailenable_professional
|
MailEnable Professional Edition before 1.53 and Enterprise Edition before 1.02 allows remote attackers to cause a denial of service (crash) via malformed (1) SMTP or (2) IMAP commands.
|
NVD-CWE-Other
|
CVE-2004-2194
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313436
|
4.3 |
MEDIUM
|
ideal_science
|
idealbb
|
Cross-site scripting (XSS) vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2004-2207
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313437
|
5.0 |
MEDIUM
|
ideal_science
|
idealbb
|
CRLF injection vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to conduct HTTP response splitting attacks via unknown vectors.
|
NVD-CWE-Other
|
CVE-2004-2208
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313438
|
7.5 |
HIGH
|
ideal_science
|
idealbb
|
SQL injection vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
|
NVD-CWE-Other
|
CVE-2004-2209
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313439
|
4.3 |
MEDIUM
|
express-web
|
express-web_content_management_system
|
Multiple cross-site scripting (XSS) vulnerabilities in Express-Web Content Management System (CMS) allow remote attackers to steal cookie-based authentication information and possibly perform other e…
|
NVD-CWE-Other
|
CVE-2004-2210
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313440
|
5.0 |
MEDIUM
|
mozilla
|
firefox
|
Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download directory via a crafted data: URI that is not properly handled when the user clicks the Save button.
|
NVD-CWE-Other
|
CVE-2004-2225
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313441
|
7.5 |
HIGH
|
-
|
-
|
Unknown vulnerability in Moodle before 1.2 allows teachers to log in as administrators.
|
NVD-CWE-Other
|
CVE-2004-2234
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313442
|
10.0 |
HIGH
|
moodle
|
moodle
|
Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.
|
NVD-CWE-Other
|
CVE-2004-2235
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313443
|
4.3 |
MEDIUM
|
goollery
|
goollery
|
Cross-site scripting (XSS) vulnerability in Goollery before 0.04b allows remote attackers to inject arbitrary HTML or web script via the conversation_id parameter to viewpic.php.
|
NVD-CWE-Other
|
CVE-2004-2246
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313444
|
10.0 |
HIGH
|
goosequill
|
audienceconnect
|
Unknown vulnerability in the "admin of paypal email addresses" in AudienceConnect before 1.0.beta.21 has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2004-2247
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313445
|
5.0 |
MEDIUM
|
evan_sims
|
effingerd
|
efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a packet with a single byte, which triggers a "Wrong protocol or connection state" error.
|
NVD-CWE-Other
|
CVE-2004-2273
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313446
|
5.0 |
MEDIUM
|
ibm
|
lotus_notes
|
Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial of service (crash) via unknown vectors related to Java applets, as identified by…
|
NVD-CWE-Other
|
CVE-2004-2280
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313447
|
10.0 |
HIGH
|
ibm
|
lotus_notes
|
Multiple unknown vulnerabilities in IBM Lotus Notes 6.5.x before 6.5.4 and 6.0.x before 6.0.5 have unknown impact and attack vectors, related to Java applets, as identified by (1) KSPR5YS6GR and (2) …
|
NVD-CWE-Other
|
CVE-2004-2281
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313448
|
5.0 |
MEDIUM
|
daniel_barron
|
dansguardian
|
DansGuardian before 2.7.7-2 allows remote attackers to bypass URL filters via a ".." in the request.
|
NVD-CWE-Other
|
CVE-2004-2282
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313449
|
5.0 |
MEDIUM
|
daniel_barron
|
dansguardian
|
Unknown vulnerability in DansGuardian before 2.6.1-13 allows remote attackers to bypass URL filters via a crafted request that causes a page to be added to the clean page cache.
|
NVD-CWE-Other
|
CVE-2004-2283
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313450
|
5.0 |
MEDIUM
|
dsm
|
light_web_file_browser
|
Directory traversal vulnerability in explorer.php in DSM Light Web File Browser 2.0 allows remote attackers to read arbitrary files via .. (dot dot) in the wdir parameter.
|
NVD-CWE-Other
|
CVE-2004-2287
|
2008-09-6 05:43 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|