|
350101
|
5.0 |
MEDIUM
|
trevor_hogan
|
bnbt
|
The Util_DecodeHTTPAuth function in BNBT BitTorrent Tracker Beta 7.5 Release 2 and earlier allows remote attackers to cause a denial of service (crash) via a Basic Authorization HTTP request with a "…
|
NVD-CWE-Other
|
CVE-2004-2029
|
2017-07-11 10:31 |
2004-05-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350102
|
4.3 |
MEDIUM
|
liferay
|
liferay_enterprise_portal
|
Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the me…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2004-2030
|
2017-07-11 10:31 |
2004-05-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350103
|
4.3 |
MEDIUM
|
e107
|
e107
|
Cross-site scripting (XSS) vulnerability in user.php in e107 allows remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) MSN, or (3) AIM fields.
|
NVD-CWE-Other
|
CVE-2004-2031
|
2017-07-11 10:31 |
2004-05-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350104
|
7.5 |
HIGH
|
netgear
|
rp114
|
Netgear RP114 allows remote attackers to bypass the keyword based URL filtering by requesting a long URL, as demonstrated using a large number of %20 (hex-encoded space) sequences.
|
NVD-CWE-Other
|
CVE-2004-2032
|
2017-07-11 10:31 |
2004-05-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350105
|
5.0 |
MEDIUM
|
orenosv
|
orenosv_http_ftp_server
|
Orenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.
|
NVD-CWE-Other
|
CVE-2004-2033
|
2017-07-11 10:31 |
2004-05-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350106
|
7.5 |
HIGH
|
wildtangent
|
webdriver
|
Buffer overflow in the (1) WTHoster and (2) WebDriver modules in WildTangent Web Driver 4.0 allows remote attackers to execute arbitrary code via a long filename.
|
NVD-CWE-Other
|
CVE-2004-2034
|
2017-07-11 10:31 |
2004-01-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350107
|
5.0 |
MEDIUM
|
minishare
|
minimal_http_server
|
MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of trailing CRLF sequences.
|
NVD-CWE-Other
|
CVE-2004-2035
|
2017-07-11 10:31 |
2004-05-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350108
|
7.5 |
HIGH
|
jportal
|
jportal_web_portal
|
SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2004-2036
|
2017-07-11 10:31 |
2004-05-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350109
|
7.5 |
HIGH
|
mollensoft_software
|
lightweight_ftp_server
|
Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long CWD command, as demonstr…
|
NVD-CWE-Other
|
CVE-2004-2037
|
2017-07-11 10:31 |
2004-03-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350110
|
4.3 |
MEDIUM
|
neocrome
|
land_down_under
|
Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a BBcode img tag in (1) functions.php, (2) header.p…
|
NVD-CWE-Other
|
CVE-2004-2038
|
2017-07-11 10:31 |
2004-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350111
|
5.0 |
MEDIUM
|
e107
|
e107
|
e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php, (4) counter_menu.php, (5) login_menu.php, and ot…
|
NVD-CWE-Other
|
CVE-2004-2039
|
2017-07-11 10:31 |
2004-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350112
|
4.3 |
MEDIUM
|
e107
|
e107
|
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 parameter to clock_menu.php, (2) "email article to …
|
NVD-CWE-Other
|
CVE-2004-2040
|
2017-07-11 10:31 |
2004-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350113
|
7.5 |
HIGH
|
-
|
-
|
PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modifying the p parameter to reference a URL on a remote web se…
|
NVD-CWE-Other
|
CVE-2004-2041
|
2017-07-11 10:31 |
2004-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350114
|
7.5 |
HIGH
|
e107
|
e107
|
Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via (1) content parameter to content.php, (2) content_id parame…
|
NVD-CWE-Other
|
CVE-2004-2042
|
2017-07-11 10:31 |
2004-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350115
|
5.0 |
MEDIUM
|
borland_software firebirdsql
|
interbase interbase_superserver firebird
|
Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows remote attackers to cause a denial of service …
|
NVD-CWE-Other
|
CVE-2004-2043
|
2017-07-11 10:31 |
2004-05-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350116
|
7.5 |
HIGH
|
francisco_burzi oscommerce paul_laudanski trustix
|
php-nuke osc2nuke betanc_php-nuke secure_linux
|
PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERV…
|
NVD-CWE-Other
|
CVE-2004-2044
|
2017-07-11 10:31 |
2004-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350117
|
5.0 |
MEDIUM
|
conceptronic
|
cadslr1_adsl_router
|
The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of service (device reboot) via an HTTP request with a long usern…
|
NVD-CWE-Other
|
CVE-2004-2045
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350118
|
5.0 |
MEDIUM
|
apc
|
powerchute
|
Unknown vulnerability in APC PowerChute Business Edition 6.0 through 7.0.1 allows remote attackers to cause a denial of service via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2004-2046
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350119
|
5.0 |
MEDIUM
|
easyweb
|
easyweb_filemanager
|
Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the pathext parameter.
|
NVD-CWE-Other
|
CVE-2004-2047
|
2017-07-11 10:31 |
2004-07-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350120
|
10.0 |
HIGH
|
esesix
|
thintune_extreme thintune_l thintune_m thintune_mobile thintune_s thintune_xm thintune_xs
|
radmin in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier starts a process port 25072 that can be accessed with a default "jstwo" password, which allows remote attackers to gain acce…
|
NVD-CWE-Other
|
CVE-2004-2048
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350121
|
4.6 |
MEDIUM
|
esesix
|
thintune_extreme thintune_l thintune_m thintune_mobile thintune_s thintune_xm thintune_xs
|
eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain acc…
|
NVD-CWE-Other
|
CVE-2004-2049
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350122
|
4.6 |
MEDIUM
|
esesix
|
thintune_extreme thintune_l thintune_m thintune_mobile thintune_s thintune_xm thintune_xs
|
eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allow local users to gain privileges by pressing CTRL-SHIFT-ALT-DEL and entering the "maertsJ" password, which is hard-coded into lshe…
|
NVD-CWE-Other
|
CVE-2004-2050
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350123
|
5.0 |
MEDIUM
|
esesix
|
thintune_extreme thintune_l thintune_m thintune_mobile thintune_s thintune_xm thintune_xs
|
The Phoenix browser in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allows local users to read arbitrary files via a file:/// URL.
|
NVD-CWE-Other
|
CVE-2004-2051
|
2017-07-11 10:31 |
2004-07-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350124
|
7.5 |
HIGH
|
easyins
|
easyins
|
PHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitrary PHP code via the site parameter.
|
NVD-CWE-Other
|
CVE-2004-2053
|
2017-07-11 10:31 |
2004-07-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350125
|
5.0 |
MEDIUM
|
phpbb_group
|
phpbb
|
CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via (1) the mode parameter to …
|
NVD-CWE-Other
|
CVE-2004-2054
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350126
|
4.3 |
MEDIUM
|
phpbb_group
|
phpbb
|
Cross-site scripting (XSS) vulnerability in search.php for PhpBB 2.0.4 and 2.0.9 allows remote attackers to inject arbitrary HTMl or web script via the search_author parameter.
|
NVD-CWE-Other
|
CVE-2004-2055
|
2017-07-11 10:31 |
2004-07-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350127
|
7.5 |
HIGH
|
xlinesoft
|
asprunner
|
SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements.
|
NVD-CWE-Other
|
CVE-2004-2057
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350128
|
5.0 |
MEDIUM
|
xlinesoft
|
asprunner
|
ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages.
|
NVD-CWE-Other
|
CVE-2004-2058
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350129
|
5.0 |
MEDIUM
|
xlinesoft
|
asprunner
|
ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable b…
|
NVD-CWE-Other
|
CVE-2004-2060
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350130
|
7.5 |
HIGH
|
antiboard
|
antiboard
|
SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2) parent_id, or (3) mode parameters.
|
NVD-CWE-Other
|
CVE-2004-2062
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350131
|
4.3 |
MEDIUM
|
antiboard
|
antiboard
|
Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inject arbitrary HTML or web script via the feedback parameter.
|
NVD-CWE-Other
|
CVE-2004-2063
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350132
|
4.3 |
MEDIUM
|
verylost
|
lostbook
|
Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web script via the (1) Email or (2) Website fields.
|
NVD-CWE-Other
|
CVE-2004-2064
|
2017-07-11 10:31 |
2004-07-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350133
|
7.5 |
HIGH
|
daniel_barron
|
dansguardian
|
DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension or . in the filename.
|
NVD-CWE-Other
|
CVE-2004-2065
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350134
|
7.5 |
HIGH
|
linpha
|
linpha
|
SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and bypass authentication via the (1) linpha_userid or (2) linpha_password cookies.
|
NVD-CWE-Other
|
CVE-2004-2066
|
2017-07-11 10:31 |
2004-07-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350135
|
7.5 |
HIGH
|
jaws
|
jaws
|
SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) pa…
|
NVD-CWE-Other
|
CVE-2004-2067
|
2017-07-11 10:31 |
2004-07-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350136
|
7.5 |
HIGH
|
macallan
|
mail_solution
|
Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authentication in the web interface via an HTTP GET request with two slashes ("//") after …
|
NVD-CWE-Other
|
CVE-2004-2071
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350137
|
6.8 |
MEDIUM
|
mambo
|
mambo_open_source
|
Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter.
|
NVD-CWE-Other
|
CVE-2004-2072
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350138
|
7.2 |
HIGH
|
-
|
-
|
Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server via a modified chroot-again exploit using the chmod command.
|
NVD-CWE-Other
|
CVE-2004-2073
|
2017-07-11 10:31 |
2004-02-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350139
|
5.0 |
MEDIUM
|
bolintech
|
dream_ftp_server
|
Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands.
|
NVD-CWE-Other
|
CVE-2004-2074
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350140
|
5.0 |
MEDIUM
|
-
|
-
|
Sophos Anti-Virus 3.78 allows remote attackers to cause a denial of service (infinite loop) via a MIME header that is not properly terminated.
|
NVD-CWE-Other
|
CVE-2004-2075
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350141
|
4.3 |
MEDIUM
|
jelsoft
|
vbulletin
|
Cross-site scripting (XSS) vulnerability in search.php for Jelsoft vBulletin 3.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.
|
NVD-CWE-Other
|
CVE-2004-2076
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350142
|
5.0 |
MEDIUM
|
nadeo
|
game_engine trackmania virtual_skipper
|
Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values…
|
NVD-CWE-Other
|
CVE-2004-2077
|
2017-07-11 10:31 |
2004-02-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350143
|
5.0 |
MEDIUM
|
red-m
|
red-alert
|
Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss of logged events) via a long request to TCP port 80, possibly triggering a buffe…
|
NVD-CWE-Other
|
CVE-2004-2078
|
2017-07-11 10:31 |
2004-02-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350144
|
7.5 |
HIGH
|
red-m
|
red-alert
|
Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authe…
|
NVD-CWE-Other
|
CVE-2004-2079
|
2017-07-11 10:31 |
2004-02-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350145
|
5.0 |
MEDIUM
|
red-m
|
red-alert
|
Red-M Red-Alert 2.7.5 with software 3.1 build 24 converts multiple spaces in a Service Set Identifier (SSID) to a single space, which prevents Red-Alert from correctly identifying the SSID.
|
NVD-CWE-Other
|
CVE-2004-2080
|
2017-07-11 10:31 |
2004-02-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350146
|
5.0 |
MEDIUM
|
karjasoft
|
sami_ftp_server
|
The samiftp.dll library in Sami FTP Server 1.1.3 allows local users to cause a denial of service (pmsystem.exe crash) by issuing (1) a CD command with a tilde (~) character or dot dot (/../) or (2) a…
|
NVD-CWE-Other
|
CVE-2004-2081
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350147
|
5.0 |
MEDIUM
|
karjasoft
|
sami_ftp_server
|
The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsystem.exe crash) via a GET request wit a large number of leading "/" (slash) charac…
|
NVD-CWE-Other
|
CVE-2004-2082
|
2017-07-11 10:31 |
2004-02-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350148
|
4.3 |
MEDIUM
|
jshop_e-commerce
|
jshop_professional jshop_server
|
Cross-site scripting (XSS) vulnerability in search.php in JShop E-Commerce Server allows remote attackers to inject arbitrary web script or HTML via the xSearch parameter.
|
NVD-CWE-Other
|
CVE-2004-2084
|
2017-07-11 10:31 |
2004-02-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350149
|
4.3 |
MEDIUM
|
brad_fears
|
phpcodecabinet
|
Multiple cross-site scripting (XSS) vulnerabilities in Brad Fears phpCodeCabinet 0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) t…
|
NVD-CWE-Other
|
CVE-2004-2085
|
2017-07-11 10:31 |
2004-02-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350150
|
5.0 |
MEDIUM
|
sambar
|
sambar_server
|
Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an …
|
NVD-CWE-Other
|
CVE-2004-2086
|
2017-07-11 10:31 |
2004-02-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|