|
350151
|
7.5 |
HIGH
|
sandsurfer
|
sandsurfer
|
Unknown vulnerability in SandSurfer before 1.7.0 allows remote attackers to gain access as a logged-in user.
|
NVD-CWE-Other
|
CVE-2004-2087
|
2017-07-11 10:31 |
2004-02-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350152
|
5.0 |
MEDIUM
|
sophos
|
sophos_anti-virus
|
Sophos Anti-Virus 3.78 allows remote attackers to bypass virus scanning by using a qmail generated Delivery Status Notification (DSN) where the original email is not included in the bounce message.
|
NVD-CWE-Other
|
CVE-2004-2088
|
2017-07-11 10:31 |
2004-02-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350153
|
5.0 |
MEDIUM
|
-
|
-
|
Matrix FTP Server allows remote attackers to cause a denial of service (crash) by logging in using four spaces as the username and password and then issuing a LIST command.
|
NVD-CWE-Other
|
CVE-2004-2089
|
2017-07-11 10:31 |
2004-02-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350154
|
4.6 |
MEDIUM
|
-
|
-
|
Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PR…
|
NVD-CWE-Other
|
CVE-2004-2093
|
2017-07-11 10:31 |
2004-02-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350155
|
4.3 |
MEDIUM
|
darkwet
|
webcam_xp
|
Cross-site scripting (XSS) vulnerability in WebcamXP 1.06.945 allows remote attackers to inject arbitrary HTML or web script as other users via a URL that contains the script.
|
NVD-CWE-Other
|
CVE-2004-2094
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350156
|
5.0 |
MEDIUM
|
niels_provos
|
honeyd
|
Honeyd before 0.8 replies to TCP packets with the SYN and RST flags set, which allows remote attackers to identify IP addresses that are being simulated by Honeyd.
|
NVD-CWE-Other
|
CVE-2004-2095
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350157
|
4.3 |
MEDIUM
|
mephistoles_internet_suite
|
mephistoles_httpd
|
Cross-site scripting (XSS) vulnerability in Mephistoles httpd 0.6.0 final allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the URL.
|
NVD-CWE-Other
|
CVE-2004-2096
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350158
|
2.1 |
LOW
|
suse
|
suse_linux
|
Multiple scripts on SuSE Linux 9.0 allow local users to overwrite arbitrary files via a symlink attack on (1) /tmp/fvwm-bug created by fvwm-bug, (2) /tmp/wmmenu created by wm-oldmenu2new, (3) /tmp/ra…
|
NVD-CWE-Other
|
CVE-2004-2097
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350159
|
4.3 |
MEDIUM
|
native_solutions
|
tbe_banner_engine
|
Cross-site scripting (XSS) vulnerability in the banner engine (TBE) 5.0 allows remote attackers to execute arbitrary script as other users via the HTML banner view/preview capability.
|
NVD-CWE-Other
|
CVE-2004-2098
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350160
|
5.1 |
MEDIUM
|
electronic_arts
|
need_for_speed_hot_pursuit_2
|
Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary code via long (1) gamename, (2) gamever, (3) hostnam…
|
NVD-CWE-Other
|
CVE-2004-2099
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350161
|
5.0 |
MEDIUM
|
geovision
|
geohttpserver
|
The sysinfo script in GeoHttpServer allows remote attackers to cause a denial of service (crash) via a long pwd parameter, possibly triggering a buffer overflow.
|
NVD-CWE-Other
|
CVE-2004-2101
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350162
|
4.3 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web script or HTML via the test parameter.
|
NVD-CWE-Other
|
CVE-2004-2102
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350163
|
7.5 |
HIGH
|
finjan_software
|
surfingate
|
Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote attackers to use the finjan-parameter-type header to (1) restart …
|
NVD-CWE-Other
|
CVE-2004-2107
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350164
|
7.5 |
HIGH
|
quadcomm
|
q-shop
|
Multiple SQL injection vulnerabilities in QuadComm Q-Shop allow remote attackers to execute arbitrary SQL commands via certain parameters to (1) search.asp, (2) browse.asp, (3) details.asp, (4) showc…
|
NVD-CWE-Other
|
CVE-2004-2108
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350165
|
6.8 |
MEDIUM
|
quadcomm
|
q-shop
|
Multiple cross-site scripting (XSS) vulnerabilities in (1) imagezoom.asp or (2) recommend.asp in Q-Shop allow remote attackers to execute arbitrary script and steal the user session ID via Javascript…
|
NVD-CWE-Other
|
CVE-2004-2109
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350166
|
5.0 |
MEDIUM
|
herberlin
|
bremsserver
|
Directory traversal vulnerability in BremsServer 1.2.4 allows remote attackers to read arbitrary files via ".." (dot dot) sequences in the URL.
|
NVD-CWE-Other
|
CVE-2004-2112
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350167
|
4.3 |
MEDIUM
|
herberlin
|
bremsserver
|
Cross-site scripting (XSS) vulnerability in BremsServer 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the URL.
|
NVD-CWE-Other
|
CVE-2004-2113
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350168
|
10.0 |
HIGH
|
internetnow
|
proxynow
|
Stack-based and heap-based buffer overflows in ProxyNow! 2.75 and earlier allow remote attackers to execute arbitrary code via a GET request with a long ftp:// URL.
|
NVD-CWE-Other
|
CVE-2004-2114
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350169
|
6.8 |
MEDIUM
|
oracle
|
http_server
|
Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, …
|
NVD-CWE-Other
|
CVE-2004-2115
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350170
|
5.0 |
MEDIUM
|
reptile_web_server
|
reptile_web_server
|
Reptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET requests without the HTTP version.
|
NVD-CWE-Other
|
CVE-2004-2120
|
2017-07-11 10:31 |
2004-01-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350171
|
5.0 |
MEDIUM
|
borland_software
|
web_server_for_corel_paradox
|
Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download arbitrary files via (1) multi-dot "......" sequences, or (2) "%5…
|
NVD-CWE-Other
|
CVE-2004-2121
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350172
|
4.3 |
MEDIUM
|
intra_forum
|
intra_forum
|
Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary web script or HTML via the (1) use_last_read or (2) forum parameters.
|
NVD-CWE-Other
|
CVE-2004-2122
|
2017-07-11 10:31 |
2004-01-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350173
|
4.3 |
MEDIUM
|
nextplace
|
e-commerce_asp_engine
|
Multiple cross-site scripting (XSS) vulnerabilities in Nextplace.com E-Commerce ASP Engine allow remote attackers to inject arbitrary web script or HTML via the (1) level parameter of productdetail.a…
|
NVD-CWE-Other
|
CVE-2004-2123
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350174
|
5.0 |
MEDIUM
|
gallery_project
|
gallery
|
The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_…
|
NVD-CWE-Other
|
CVE-2004-2124
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350175
|
4.6 |
MEDIUM
|
iss
|
blackice_agent_server blackice_pc_protection blackice_server_protection realsecure_desktop
|
Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users to gain system privileges by modifying the .INI fil…
|
NVD-CWE-Other
|
CVE-2004-2125
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350176
|
5.0 |
MEDIUM
|
leif_m._wright
|
web_blog
|
Directory traversal vulnerability in Web Blog 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file variable.
|
NVD-CWE-Other
|
CVE-2004-2127
|
2017-07-11 10:31 |
2004-01-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350177
|
6.8 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as other users via the query string to ISAPISkeleton.dll.
|
NVD-CWE-Other
|
CVE-2004-2128
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350178
|
5.0 |
MEDIUM
|
loom_software
|
surfnow_professional surfnow_standard
|
SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow.
|
NVD-CWE-Other
|
CVE-2004-2129
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350179
|
7.2 |
HIGH
|
ibm
|
informix_dynamic_server informix_extended_parallel_server
|
Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment var…
|
NVD-CWE-Other
|
CVE-2004-2131
|
2017-07-11 10:31 |
2004-01-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350180
|
5.0 |
MEDIUM
|
pj_cgi_neo_review
|
pj_cgi_neo_review
|
Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter.
|
NVD-CWE-Other
|
CVE-2004-2132
|
2017-07-11 10:31 |
2004-01-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350181
|
4.6 |
MEDIUM
|
cvsup
|
cvsup
|
Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of certain executables, which could allow local users to execute arbitrary code by ca…
|
NVD-CWE-Other
|
CVE-2004-2133
|
2017-07-11 10:31 |
2004-01-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350182
|
5.0 |
MEDIUM
|
microsoft
|
outlook_express
|
Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger than" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fiel…
|
NVD-CWE-Other
|
CVE-2004-2137
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350183
|
10.0 |
HIGH
|
jorg_schilling
|
sdd
|
Unknown vulnerability in the remote tape support (remote.c) in the RMT client for Jorg Schilling sdd 1.28 and 1.31 has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2004-2142
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350184
|
7.5 |
HIGH
|
mambo
|
mambo_portal
|
SQL injection vulnerability in the ReMOSitory Server add-on module to Mambo Portal 4.5.1 (1.09) and earlier allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in th…
|
NVD-CWE-Other
|
CVE-2004-2143
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350185
|
7.5 |
HIGH
|
pd9_software
|
megabbs
|
SQL injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows remote attackers to execute arbitrary SQL commands via the (1) sortdir or (2) criteria parameter to ladder-log.asp or the (3) memb…
|
NVD-CWE-Other
|
CVE-2004-2145
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350186
|
5.0 |
MEDIUM
|
pd9_software
|
megabbs
|
CRLF injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows attackers to conduct HTTP response splitting attacks via the fid parameter in a writenew action to thread-post.asp.
|
NVD-CWE-Other
|
CVE-2004-2146
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350187
|
7.2 |
HIGH
|
slava_astashonok
|
fprobe
|
Unknown local vulnerability in the "change user" feature of Slava Astashonok Fprobe 1.0.5 and earlier has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2004-2148
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350188
|
5.0 |
MEDIUM
|
virtual_projects
|
chatman
|
Chatman 1.1.1 RC1 and earlier allows remote attackers to cause a denial of service (memory consumption or application crash) via a very large data size.
|
NVD-CWE-Other
|
CVE-2004-2151
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350189
|
4.3 |
MEDIUM
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in 'raw' page output mode for MediaWiki 1.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML.
|
NVD-CWE-Other
|
CVE-2004-2152
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350190
|
10.0 |
HIGH
|
real_estate_management_software
|
real_estate_management_software
|
Multiple unknown vulnerabilities in Real Estate Management Software 1.0 have unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2004-2153
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350191
|
7.5 |
HIGH
|
-
|
-
|
Online-bookmarks before 0.4.6 allows remote attackers to bypass its authentication mechanism via a direct request to (1) config/*, (2) bookmarks.php, (3) footer.php, (4) main.php, (5) tree.php, or (6…
|
NVD-CWE-Other
|
CVE-2004-2155
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350192
|
10.0 |
HIGH
|
recruitment_agency_software
|
online_recruitment_agency
|
Multiple unknown vulnerabilities in Online Recruitment Agency 1.0 have unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2004-2156
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350193
|
4.3 |
MEDIUM
|
s9y
|
serendipity
|
Cross-site scripting (XSS) vulnerability in Comment.php in Serendipity 0.7 beta1, and possibly other versions before 0.7-beta3, allows remote attackers to inject arbitrary HTML and PHP code via the (…
|
NVD-CWE-Other
|
CVE-2004-2157
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350194
|
7.5 |
HIGH
|
s9y
|
serendipity
|
SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter to (1) exit.php or (2) comment.php.
|
NVD-CWE-Other
|
CVE-2004-2158
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350195
|
10.0 |
HIGH
|
xmlstarlet
|
command_line_xml_toolkit
|
Multiple buffer overflows in XMLStarlet Command Line XML Toolkit 0.9.3 have unknown impact and attack vectors via (1) xml_elem.c and (2) xml_select.c.
|
NVD-CWE-Other
|
CVE-2004-2159
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350196
|
7.5 |
HIGH
|
tutos
|
tutos
|
SQL injection vulnerability in file_overview.php in TUTOS 1.1 allows remote attackers to execute arbitrary SQL commands via the link_id parameter.
|
NVD-CWE-Other
|
CVE-2004-2161
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350197
|
4.3 |
MEDIUM
|
tutos
|
tutos
|
Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the search field of the Address Module or (2) the t parameter to…
|
NVD-CWE-Other
|
CVE-2004-2162
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350198
|
7.5 |
HIGH
|
openbsd
|
openbsd
|
login_radius on OpenBSD 3.2, 3.5, and possibly other versions does not verify the shared secret in a response packet from a RADIUS server, which allows remote attackers to bypass authentication by sp…
|
NVD-CWE-Other
|
CVE-2004-2163
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350199
|
5.0 |
MEDIUM
|
virtual_programming
|
vp-asp
|
shoprestoreorder.asp in VP-ASP 5.0 does not close the database connection when a user restores a previous order, which allows remote attackers to cause a denial of service (connection consumption).
|
NVD-CWE-Other
|
CVE-2004-2164
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350200
|
5.0 |
MEDIUM
|
impressions_games
|
lords_of_the_realm_iii
|
Lords of the Realm III 1.01 and earlier, when in the lobby stage, allows remote attackers to cause a denial of service (crash from unallocated memory write) via a long user nickname.
|
NVD-CWE-Other
|
CVE-2004-2165
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|