|
350201
|
7.5 |
HIGH
|
canon
|
imagerunner_5000i imagerunner_c3200
|
The print-from-email feature in the Canon ImageRUNNER (iR) 5000i and C3200 digital printer, when not using IP address range filtering, allows remote attackers to print arbitrary text without authenti…
|
NVD-CWE-Other
|
CVE-2004-2166
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350202
|
7.5 |
HIGH
|
latex2rtf
|
latex2rtf
|
Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary code via (1) the expandmacro function, and possibly (2) Environments and (3) Tr…
|
NVD-CWE-Other
|
CVE-2004-2167
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350203
|
5.0 |
MEDIUM
|
baardsen_software
|
basomail_server
|
BaSoMail 1.24 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections to TCP port (1) 25 (SMTP) or (2) 110 (POP3).
|
NVD-CWE-Other
|
CVE-2004-2168
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350204
|
2.1 |
LOW
|
a-a-s_application_access_server
|
a-a-s_application_access_server
|
Application Access Server (A-A-S) 1.0.37 and earlier allows remote authenticated users to cause a denial of service (application crash) via a long file request.
|
NVD-CWE-Other
|
CVE-2004-2169
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350205
|
5.0 |
MEDIUM
|
niti_telecom
|
caravan_business_server
|
Directory traversal vulnerability in sample_showcode.html in Caravan 2.00/03d and earlier allows remote attackers to read arbitrary files via the fname parameter.
|
NVD-CWE-Other
|
CVE-2004-2170
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350206
|
4.3 |
MEDIUM
|
cherokee
|
cherokee_httpd
|
Cross-site scripting (XSS) vulnerability in Cherokee before 0.4.8 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting error page.
|
NVD-CWE-Other
|
CVE-2004-2171
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350207
|
7.5 |
HIGH
|
early_impact
|
productcart
|
SQL injection vulnerability in advSearch_h.asp in EarlyImpact ProductCart allows remote attackers to execute arbitrary SQL commands via the priceUntil parameter.
|
NVD-CWE-Other
|
CVE-2004-2173
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350208
|
4.3 |
MEDIUM
|
early_impact
|
productcart
|
Cross-site scripting (XSS) vulnerability in Custva.asp in EarlyImpact ProductCart allows remote attackers to inject arbitrary Javascript via the redirectUrl parameter.
|
NVD-CWE-Other
|
CVE-2004-2174
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350209
|
7.5 |
HIGH
|
all_enthusiast_inc
|
reviewpost_php_pro
|
Multiple SQL injection vulnerabilities in ReviewPost PHP Pro allow remote attackers to execute arbitrary SQL commands via the (1) product parameter to showproduct.php or (2) cat parameter to showcat.…
|
NVD-CWE-Other
|
CVE-2004-2175
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350210
|
6.4 |
MEDIUM
|
digicraft_software
|
yak
|
Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write arbitrary files via "../" or "..\" sequences in commands such as (1) dir or (2) p…
|
NVD-CWE-Other
|
CVE-2004-2184
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350211
|
4.3 |
MEDIUM
|
turbotraffictrader
|
turbotraffictrader_php
|
Cross-site scripting (XSS) vulnerability in ttt-webmaster.php in Turbo Traffic Trader PHP 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) msg[0] or (2) siteurl paramete…
|
NVD-CWE-Other
|
CVE-2004-2191
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350212
|
7.5 |
HIGH
|
turbotraffictrader
|
turbotraffictrader_php
|
SQL injection vulnerability in tttadmin/settings.php in Turbo Traffic Trader PHP 1.0 allows remote attackers to execute arbitrary SQL commands via the ttt_admin parameter.
|
NVD-CWE-Other
|
CVE-2004-2192
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350213
|
4.3 |
MEDIUM
|
cjoverkill
|
cjoverkill
|
Cross-site scripting (XSS) vulnerability in trade.php for CJOverkill 4.0.3 allows remote attackers to inject arbitrary web script or HTML via the (1) tms[0] or (2) url parameters.
|
NVD-CWE-Other
|
CVE-2004-2193
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350214
|
5.0 |
MEDIUM
|
zanfi_solutions
|
zanfi_cms_lite
|
PHP remote file inclusion vulnerability in index.php in Zanfi CMS lite 1.1 allows remote attackers to execute arbitrary PHP code via the inc parameter.
|
NVD-CWE-Other
|
CVE-2004-2195
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350215
|
5.0 |
MEDIUM
|
zanfi_solutions
|
zanfi_cms_lite
|
Zanfi CMS lite 1.1 allows remote attackers to obtain the full path of the web server via direct requests without required arguments to (1) adm_pages.php, (2) corr_pages.php, (3) del_block.php, (4) de…
|
NVD-CWE-Other
|
CVE-2004-2196
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350216
|
7.2 |
HIGH
|
kdocker
|
kdocker
|
kdocker.cpp in kdocker 0.1 through 0.8 does not properly check the ownership of files, which could allow local users to execute arbitrary programs.
|
NVD-CWE-Other
|
CVE-2004-2197
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350217
|
6.4 |
MEDIUM
|
duware
|
duclassmate
|
account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId parameter on the "My Account" page.
|
NVD-CWE-Other
|
CVE-2004-2198
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350218
|
4.3 |
MEDIUM
|
duware
|
duclassified
|
Cross-site scripting (XSS) vulnerability in DUware DUclassified 4.0 allows remote attackers to inject arbitrary web script or HTML via the message text.
|
NVD-CWE-Other
|
CVE-2004-2199
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350219
|
4.3 |
MEDIUM
|
duware
|
duforum
|
Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to inject arbitrary web script or HTML via via the message text.
|
NVD-CWE-Other
|
CVE-2004-2200
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350220
|
7.5 |
HIGH
|
duware
|
duforum
|
SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDetail…
|
NVD-CWE-Other
|
CVE-2004-2201
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350221
|
7.5 |
HIGH
|
duware
|
duclassified
|
Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server's underlying database via the (…
|
NVD-CWE-Other
|
CVE-2004-2202
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350222
|
7.5 |
HIGH
|
ansel
|
ansel
|
Ansel 1.2 through 2.0 uses insecure default permissions, which allows remote attackers to gain access to web readable directories.
|
NVD-CWE-Other
|
CVE-2004-2203
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350223
|
7.2 |
HIGH
|
macromedia
|
coldfusion
|
Macromedia ColdFusion MX 6.0 and 6.1 application server, when running with the CreateObject function or CFOBJECT tag enabled, allows local users to conduct unauthorized activities and obtain administ…
|
NVD-CWE-Other
|
CVE-2004-2204
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350224
|
7.2 |
HIGH
|
symantec_veritas
|
cluster_server
|
Unknown vulnerability in Veritas Cluster Server 1.0.1 through 4.0 allows local users to gain root access via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2004-2205
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350225
|
7.5 |
HIGH
|
natterchat
|
natterchat
|
SQL injection vulnerability in NatterChat 1.12 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
|
NVD-CWE-Other
|
CVE-2004-2206
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350226
|
4.3 |
MEDIUM
|
alivesites
|
alivesites_forum
|
Cross-site scripting (XSS) vulnerability in AliveSites Forums 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) forum_id, (2) method, or (3) forum_title parameters to pos…
|
NVD-CWE-Other
|
CVE-2004-2211
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350227
|
7.5 |
HIGH
|
alivesites
|
alivesites_forum
|
SQL injection vulnerability in forum.asp in AliveSites Forums 2.0 allows remote attackers to execute arbitrary SQL commands via the forum_id parameter.
|
NVD-CWE-Other
|
CVE-2004-2212
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350228
|
5.0 |
MEDIUM
|
mbedthis_software
|
mbedthis_appweb_http_server
|
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to obtain the source code for scripts via a (1) trailing dot (".") or (2) trailing space in an HTTP request.
|
NVD-CWE-Other
|
CVE-2004-2213
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350229
|
4.6 |
MEDIUM
|
marc_lehmann
|
rxvt-unicode
|
RXVT-Unicode 3.4 and 3.5 does not properly close file descriptors, which allows local users to access the terminals of other users and possibly gain privileges.
|
NVD-CWE-Other
|
CVE-2004-2215
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350230
|
5.0 |
MEDIUM
|
sun
|
java_system_application_server java_system_web_server
|
Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier and 6.1 SP1 and earlier, and Application Server 7 Update 4 and earlier, allows remote attackers to cause a denial of service (c…
|
NVD-CWE-Other
|
CVE-2004-2216
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350231
|
5.0 |
MEDIUM
|
ychat
|
ychat
|
Multiple unknown vulnerabilities in yhttpd in yChat before 0.7 allow remote attackers to cause a denial of service (segmentation fault) via unknown vectors.
|
NVD-CWE-Other
|
CVE-2004-2217
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350232
|
7.5 |
HIGH
|
phpmywebhosting
|
phpmywebhosting
|
SQL injection vulnerability in pmwh.php in PHPMyWebHosting 0.3.4 and earlier allows remote attackers to modify SQL statements via the password parameter.
|
NVD-CWE-Other
|
CVE-2004-2218
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350233
|
5.0 |
MEDIUM
|
f-secure
|
f-secure_anti-virus
|
F-Secure Anti-Virus for Microsoft Exchange 6.30 and 6.31 does not properly detect certain password-protected files in a ZIP file, which allows remote attackers to bypass anti-virus protection.
|
NVD-CWE-Other
|
CVE-2004-2220
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350234
|
7.5 |
HIGH
|
mercantec
|
softcart
|
Buffer overflow in SoftCart.exe in Mercantec SoftCart 4.00b allows remote attackers to execute arbitrary code via a long parameter in an HTTP GET request.
|
NVD-CWE-Other
|
CVE-2004-2221
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350235
|
5.0 |
MEDIUM
|
fsphpgallery
|
fsphpgallery
|
FsPHPGallery before 1.2 allows remote attackers to cause a denial of service via an image with a large size attribute, which causes a crash when the server attempts to resize the image.
|
NVD-CWE-Other
|
CVE-2004-2223
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350236
|
5.0 |
MEDIUM
|
appfoundry
|
message_foundry
|
Appfoundry Message Foundry 2.75 .0003 allows remote attackers to cause a denial of service (crash) via an HTTP GET request that contains MS-DOS device names such as com1.
|
NVD-CWE-Other
|
CVE-2004-2224
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350237
|
5.0 |
MEDIUM
|
mozilla
|
thunderbird
|
Mozilla Mail 1.7.1 and 1.7.3, and Thunderbird before 0.9, when HTML-Mails is enabled, allows remote attackers to determine valid e-mail addresses via an HTML e-mail that references a Cascading Style …
|
NVD-CWE-Other
|
CVE-2004-2226
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350238
|
5.0 |
MEDIUM
|
mozilla
|
firefox
|
Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into downloading files with dangerous extensions.
|
NVD-CWE-Other
|
CVE-2004-2227
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350239
|
7.2 |
HIGH
|
-
|
-
|
Mozilla Firefox before 1.0 is installed with world-writable permissions on Mac OS X, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2004-2228
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350240
|
4.6 |
MEDIUM
|
oracle
|
database_server_lite
|
Multiple unknown vulnerabilities in Oracle 9i Lite Mobile Server 5.0.0.0.0 through 5.0.2.9.0 allow remote authenticated users to gain privileges.
|
NVD-CWE-Other
|
CVE-2004-2229
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350241
|
2.1 |
LOW
|
openbsd
|
openbsd
|
Heap-based buffer overflow in isakmpd on OpenBSD 3.4 through 3.6 allows local users to cause a denial of service (panic) and corrupt memory via IPSEC credentials on a socket.
|
NVD-CWE-Other
|
CVE-2004-2230
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350242
|
1.2 |
LOW
|
-
|
-
|
Zero G Software InstallAnywhere 5.0.6, 5.0.7, and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) persistent_state or (2) env.properties.X temporary files.
|
NVD-CWE-Other
|
CVE-2004-2231
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350243
|
7.5 |
HIGH
|
-
|
-
|
Buffer overflow in vsybase.c in vpopmail 5.4.2 and earlier might allow attackers to cause a denial of service or execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2004-2239
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350244
|
7.5 |
HIGH
|
phorum
|
phorum
|
Multiple SQL injection vulnerabilities in Phorum 5.0.11 and earlier allow remote attackers to modify SQL statements via (1) the query string in read.php or (2) unknown vectors in file.php.
|
NVD-CWE-Other
|
CVE-2004-2240
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350245
|
4.3 |
MEDIUM
|
phorum
|
phorum
|
Cross-site scripting (XSS) vulnerability in Phorum 5.0.11 and earlier allows remote attackers to inject arbitrary HTML or web script via search.php. NOTE: some sources have reported that the affected…
|
NVD-CWE-Other
|
CVE-2004-2241
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350246
|
4.3 |
MEDIUM
|
phorum
|
phorum
|
Cross-site scripting (XSS) vulnerability in search.php in Phorum, possibly 5.0.7 beta and earlier, allows remote attackers to inject arbitrary HTML or web script via the subject parameter.
|
NVD-CWE-Other
|
CVE-2004-2242
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350247
|
7.5 |
HIGH
|
phorum
|
phorum
|
Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter, as demonstrated using profile.php. NOTE: the affected ver…
|
NVD-CWE-Other
|
CVE-2004-2243
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350248
|
5.0 |
MEDIUM
|
oracle
|
application_server oracle9i
|
The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote …
|
NVD-CWE-Other
|
CVE-2004-2244
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350249
|
4.3 |
MEDIUM
|
goollery
|
goollery
|
Cross-site scripting (XSS) vulnerability in Goollery 0.03 allows remote attackers to inject arbitrary HTML or web script via the (1) page parameter to viewalbum.php or (2) btopage parameter to viewpi…
|
NVD-CWE-Other
|
CVE-2004-2245
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350250
|
10.0 |
HIGH
|
goosequill
|
remoteeditor
|
Unknown vulnerability in RemoteEditor before 0.1.1 has unknown impact and attack vectors, related to "oversize submissions."
|
NVD-CWE-Other
|
CVE-2004-2248
|
2017-07-11 10:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|