CVE-2004-1000 to CVE-2004-1999
376 CVEs with public proof-of-concept exploits.
- CVE-2004-10031 PoCTrend ScanMail allows remote attackers to obtain potentially sensitive information or disable the anti-virus capability via the smency.nsf…
- CVE-2004-10161 PoCThe scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to cause a denial of…
- CVE-2004-10182 PoCsMultiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or…
- CVE-2004-10201 PoCThe addslashes function in PHP 4.3.9 does not properly escape a NULL (/0) character, which may allow remote attackers to read arbitrary…
- CVE-2004-10291 PoCThe Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly…
- CVE-2004-10373 PoCsThe search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.
- CVE-2004-10431 PoCInternet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics" command in the…
- CVE-2004-10502 PoCsHeap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME…
- CVE-2004-10542 PoCsUntrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying…
- CVE-2004-10602 PoCsMultiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of…
- CVE-2004-10731 PoCThe open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, allows local users…
- CVE-2004-10741 PoCThe binfmt functionality in the Linux kernel, when "memory overcommit" is enabled, allows local users to cause a denial of service (kernel…
- CVE-2004-10751 PoCCross-site scripting (XSS) vulnerability in standard_error_message.dtml for Zwiki after 0.10.0rc1 to 0.36.2 allows remote attackers to…
- CVE-2004-10803 PoCsThe WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to…
- CVE-2004-10951 PoCMultiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8)…
- CVE-2004-10961 PoCArchive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus…
- CVE-2004-11001 PoCCross-site scripting (XSS) vulnerability in mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled,…
- CVE-2004-11011 PoCmailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash), leak…
- CVE-2004-11021 PoCMailPost 5.1.1sv, and possibly earlier versions, displays a different error message depending on whether the requested file exists or not,…
- CVE-2004-11041 PoCMicrosoft Internet Explorer 6.0 SP2 allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via…
- CVE-2004-11091 PoCThe FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (CPU consumption…
- CVE-2004-11182 PoCsBuffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup…
- CVE-2004-11191 PoCStack-based buffer overflow in IN_CDDA.dll in Winamp 5.05, and possibly other versions including 5.06, allows remote attackers to execute…
- CVE-2004-11202 PoCsMultiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2…
- CVE-2004-11211 PoCApple Safari 1.0 through 1.2.3 allows remote attackers to spoof the URL displayed in the status bar via TABLE tags.
- CVE-2004-11271 PoCBuffer overflow in Open Dc Hub 0.7.14 allows remote attackers, with administrator privileges, to execute arbitrary code via a long…
- CVE-2004-11342 PoCsBuffer overflow in the Microsoft W3Who ISAPI (w3who.dll) allows remote attackers to cause a denial of service and possibly execute…
- CVE-2004-11353 PoCsMultiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long…
- CVE-2004-11371 PoCMultiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers…
- CVE-2004-11471 PoCphpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary…
- CVE-2004-11501 PoCStack-based buffer overflow in the in_cdda.dll plugin for Winamp 5.0 through 5.08c allows attackers to execute arbitrary code via a cda://…
- CVE-2004-11511 PoCMultiple buffer overflows in the (1) sys32_ni_syscall and (2) sys32_vm86_warning functions in sys_ia32.c for Linux 2.6.x may allow local…
- CVE-2004-11611 PoCrssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass…
- CVE-2004-11651 PoCKonqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a")…
- CVE-2004-11661 PoCCRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP…
- CVE-2004-11701 PoCa2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.
- CVE-2004-11723 PoCsStack-based buffer overflow in the Agent Browser in Veritas Backup Exec 8.x before 8.60.3878 Hotfix 68, and 9.x before 9.1.4691 Hotfix 40,…
- CVE-2004-11921 PoCFormat string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute arbitrary code via…
- CVE-2004-11941 PoCBuffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a…
- CVE-2004-11951 PoCStar Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a join request that…
- CVE-2004-11961 PoCCross-site scripting (XSS) vulnerability in inmail.pl in Insite Inmail allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2004-12061 PoCDirectory traversal vulnerability in codebrowserpntm.php in pnTresMailer 6.0.3 allows remote attackers to read arbitrary files via a ..…
- CVE-2004-12071 PoCThe Serious engine, as used in (1) Alpha Black Zero Intrepid Protocol 1.04 and earlier, (2) Nitro family, and (3) Serious Sam Second…
- CVE-2004-12081 PoCBuffer overflow in Orbz 2.10 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute…
- CVE-2004-12101 PoCCross-site scripting (XSS) vulnerability in proxylog.dat in IPCop 1.4.1 and possibly other versions, allows remote attackers to inject…
- CVE-2004-12118 PoCsMultiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service…
- CVE-2004-12121 PoCDirectory traversal vulnerability in btdownload.php in Blog Torrent preview 0.8 allows remote attackers to download arbitrary files via a…
- CVE-2004-12131 PoCCross-site scripting (XSS) vulnerability in index.php in Advanced Guestbook 2.3.1, 2.2, and possibly other versions allows remote…
- CVE-2004-12141 PoCFormat string vulnerability in Kreed 1.05 and earlier allows remote attackers to execute arbitrary code via format specifiers in (1) a…
- CVE-2004-12151 PoCKreed 1.05 and earlier allows remote attackers to cause a denial of service (server disconnect) via a long UDP packet, which causes a…
- CVE-2004-12161 PoCThe scripts that handle players in Kreed 1.05 and earlier allow remote attackers to cause a denial of service (server freeze) via a long…
- CVE-2004-12171 PoCHosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the…
- CVE-2004-12202 PoCsBattlefield 1942 1.6.19 and earlier, and Battlefield Vietnam 1.2 and earlier, allows a remote master server to cause a denial of service…
- CVE-2004-12211 PoCDirectory traversal vulnerability in weblibs.pl in WebLibs 1.0 allows remote attackers to read arbitrary files via .. sequences in the…
- CVE-2004-12231 PoCThe Management Agent in F-Secure Policy Manager 5.11.2810 allows remote attackers to gain sensitive information, such as the absolute path…
- CVE-2004-12251 PoCSQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain…
- CVE-2004-12271 PoCDirectory traversal vulnerability in SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to read arbitrary files and possibly…
- CVE-2004-12354 PoCsRace condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6…
- CVE-2004-12541 PoCWinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long…
- CVE-2004-12561 PoCMultiple buffer overflows in the (1) event_text and (2) event_specific functions in abc2midi 2004.12.04 allow remote attackers to execute…
- CVE-2004-12591 PoCMultiple buffer overflows in the handle_directive function in abcpp.c for abcpp 1.3.0 allow remote attackers to execute arbitrary code via…
- CVE-2004-12602 PoCsMultiple buffer overflows in the (1) write_heading function in subs.cpp or (2) trim_title function in parse.cpp for abctab2ps 1.6.3 allow…
- CVE-2004-12611 PoCMultiple buffer overflows in the preparse function in asp2php 0.76.23 allow remote attackers to execute arbitrary code via crafted ASP…
- CVE-2004-12641 PoCBuffer overflow in the simplify_path function in config.c for ChBg 1.5 allows remote attackers to execute arbitrary code via a crafted…
- CVE-2004-12671 PoCBuffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute…
- CVE-2004-12691 PoClppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which…
- CVE-2004-12821 PoCBuffer overflow in the strexpand function in string.c for LinPopUp 1.2.0 allows remote attackers to execute arbitrary code via a crafted…
- CVE-2004-12841 PoCBuffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a…
- CVE-2004-12862 PoCsBuffer overflow in the auto_filter_extern function in auto.c for NapShare 1.2, with the extern filter enabled, allows remote attackers to…
- CVE-2004-12871 PoCBuffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file,…
- CVE-2004-12881 PoCBuffer overflow in the parse_html function in o3read.c for o3read 0.0.3 allows remote attackers to execute arbitrary code via a crafted…
- CVE-2004-12892 PoCsMultiple buffer overflows in (1) the getline function in pcalutil.c and (2) the get_holiday function in readfile.c for pcal 4.7.1 allow…
- CVE-2004-12911 PoCBuffer overflow in qwik-smtpd allows remote attackers to use the server as an SMTP spam relay via a long HELO command, which overwrites…
- CVE-2004-12921 PoCBuffer overflow in the parse_emelody function in parse_emelody.c for ringtonetools 2.22 allows remote attackers to execute arbitrary code…
- CVE-2004-12931 PoCBuffer overflow in the ReadFontTbl function in reader.c for rtf2latex2e 1.0fc2 allows remote attackers to execute arbitrary code via a…
- CVE-2004-12981 PoCBuffer overflow in the parse function in vb2c.c for vb2c 0.02 allows remote attackers to execute arbitrary code via a crafted FRM file.
- CVE-2004-12991 PoCBuffer overflow in the get_attr function in html.c for vilistextum 2.6.6 allows remote attackers to execute arbitrary code via a crafted…
- CVE-2004-13001 PoCBuffer overflow in the open_aiff_file function in demux_aiff.c for xine-lib (libxine) 1-rc7 allows remote attackers to execute arbitrary…
- CVE-2004-13011 PoCBuffer overflow in the book_format_sql function in format.c for xlreader 0.9.0 allows remote attackers to execute arbitrary code via a…
- CVE-2004-13031 PoCBuffer overflow in the get function in get.c for Yanf 0.4 allows remote malicious web servers to execute arbitrary code via crafted HTTP…
- CVE-2004-13041 PoCStack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted…
- CVE-2004-13051 PoCThe Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow…
- CVE-2004-13061 PoCHeap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote…
- CVE-2004-13156 PoCsviewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight,…
- CVE-2004-13161 PoCHeap-based buffer overflow in MSG_UnEscapeSearchUrl in nsNNTPProtocol.cpp for Mozilla 1.7.3 and earlier allows remote attackers to cause a…
- CVE-2004-13175 PoCsStack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attackers to execute…
- CVE-2004-13241 PoCThe Microsoft Windows Media Player 9.0 ActiveX control may allow remote attackers to execute arbitrary web script in the Local computer…
- CVE-2004-13251 PoCThe getItemInfoByAtom function in the ActiveX control for Microsoft Windows Media Player 9.0 returns a 0 if the file does not exist and…
- CVE-2004-13262 PoCsBuffer overflow in dxterm in Ultrix 4.5 allows local users to execute arbitrary code via a long -setup parameter.
- CVE-2004-13271 PoCBuffer overflow in Crystal FTP Client 2.8 allows remote malicious servers to execute arbitrary code via a response to a LIST command that…
- CVE-2004-13292 PoCsUntrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through…
- CVE-2004-13301 PoCBuffer overflow in paginit in AIX 5.1 through 5.3 allows local users to execute arbitrary code via a long username.
- CVE-2004-13331 PoCInteger overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service…
- CVE-2004-13351 PoCMemory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (memory…
- CVE-2004-13643 PoCsDirectory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the…
- CVE-2004-13734 PoCsFormat string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) and execute…
- CVE-2004-13801 PoCFirefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to…
- CVE-2004-13811 PoCFirefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as…
- CVE-2004-13831 PoCMultiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrary SQL statements…
- CVE-2004-13842 PoCsMultiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web…
- CVE-2004-13851 PoCphpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID…
- CVE-2004-13885 PoCsFormat string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7 allows remote…
- CVE-2004-13892 PoCsUnknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1, and 4.5,…
- CVE-2004-13921 PoCPHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument…
- CVE-2004-13952 PoCsThe Lithtech engine, as used in (1) Contract Jack 1.1 and earlier, (2) No one lives forever 2 1.3 and earlier, (3) Tron 2.0 1.042 and…
- CVE-2004-14001 PoCThe control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unauthorized access via…
- CVE-2004-14011 PoCSQL injection vulnerability in verify.asp in Asp-rider allows remote attackers to execute arbitrary SQL statements and bypass…
- CVE-2004-14021 PoCSQL injection vulnerability in iWebNegar allows remote attackers to execute arbitrary SQL commands via (1) the string parameter for…
- CVE-2004-14051 PoCMediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar,…
- CVE-2004-14061 PoCSQL injection vulnerability in ikonboard.cgi in Ikonboard 3.1.0 through 3.1.3 allows remote attackers to inject arbitrary SQL commands via…
- CVE-2004-14101 PoCCross-site scripting (XSS) vulnerability in Gadu-Gadu build 155 and earlier allows remote attackers to inject arbitrary web script via a…
- CVE-2004-14121 PoCCross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.x allows remote attackers to inject arbitrary web script or…
- CVE-2004-14131 PoCMultiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands via the (1) subcat,…
- CVE-2004-14151 PoCSQL injection vulnerability in (1) disp_album.php and possibly (2) disp_img.php in 2Bgal 2.4 and 2.5.1 allows remote attackers to execute…
- CVE-2004-14171 PoCCross-site scripting (XSS) vulnerability in login.php in PsychoStats 2.2.4 Beta and earlier allows remote attackers to inject arbitrary…
- CVE-2004-14181 PoCCross-site scripting (XSS) vulnerability in WPKontakt 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2004-14201 PoCMultiple cross-site scripting (XSS) vulnerabilities in header.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to inject…
- CVE-2004-14211 PoCMultiple PHP remote file inclusion vulnerabilities (1) step_one.php, (2) step_one_tables.php, (3) step_two_tables.php in WHM AutoPilot…
- CVE-2004-14221 PoCWHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php settings.
- CVE-2004-14232 PoCsMultiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts…
- CVE-2004-14371 PoCMultiple buffer overflows in the digest authentication functionality in Pavuk 0.9.28-r2 and earlier allow remote attackers to execute…
- CVE-2004-14393 PoCsBuffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1) USER, (2) PASS,…
- CVE-2004-14411 PoCCross-site scripting (XSS) vulnerability in icq.cgi in Board Power 2.04PF allows remote attackers to inject arbitrary web script or HTML…
- CVE-2004-14421 PoCCross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary…
- CVE-2004-14441 PoCDirectory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences…
- CVE-2004-14562 PoCsfilediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.
- CVE-2004-14651 PoCMultiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors, including the…
- CVE-2004-14662 PoCsThe set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds after they have…
- CVE-2004-14671 PoCMultiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.0.00.003 and earlier allow remote attackers to inject arbitrary web…
- CVE-2004-14701 PoCCRLF injection vulnerability in SnipSnap 0.5.2a, and other versions before 1.0b1, allows remote attackers to perform HTTP Response…
- CVE-2004-14711 PoCFormat string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT…
- CVE-2004-14751 PoCMultiple stack-based buffer overflows in xine-lib 1-rc2 through 1-rc5 allow attackers to execute arbitrary code via (1) long VideoCD…
- CVE-2004-14841 PoCFormat string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with…
- CVE-2004-14881 PoCwget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote…
- CVE-2004-14911 PoCOpera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a…
- CVE-2004-14931 PoCMaster of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (server crash) via multiple connections with…
- CVE-2004-14991 PoCCross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute…
- CVE-2004-15001 PoCFormat string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of…
- CVE-2004-15041 PoCThe displaycontent function in config.php for Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to gain sensitive information…
- CVE-2004-15051 PoCDirectory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to read arbitrary files…
- CVE-2004-15151 PoCSQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL…
- CVE-2004-15191 PoCSQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands via (1) the bug_id…
- CVE-2004-15204 PoCsStack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE…
- CVE-2004-15211 PoCEudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable encoded…
- CVE-2004-15311 PoCSQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL…
- CVE-2004-15321 PoCAppServ 2.5.x and earlier installs a default username and password, which allows remote attackers to gain access.
- CVE-2004-15331 PoCBuffer overflow in pop3svr.exe for DMS POP3 1.5.3.27 and earlier allows remote attackers to cause a denial of service (service crash) via…
- CVE-2004-15351 PoCPHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary…
- CVE-2004-15361 PoCSQL injection vulnerability in index.php in the ibProArcade module for Invision Power Board (IPB) 1.x and 2.x allows remote attackers to…
- CVE-2004-15371 PoCCross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web…
- CVE-2004-15391 PoCHalo: Combat Evolved 1.05 and earlier allows remote game servers to cause a denial of service (client crash) via a long value in a game…
- CVE-2004-15401 PoCZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a…
- CVE-2004-15421 PoCBuffer overflow in Soldier of Fortune II 1.03 Gold and earlier allows remote attackers to cause a denial of service (server or client…
- CVE-2004-15431 PoCDirectory traversal vulnerability in viewimg.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to list arbitrary directories…
- CVE-2004-15462 PoCsMultiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a long (1) SAML,…
- CVE-2004-15501 PoCMotorola Wireless Router WR850G running firmware 4.03 allows remote attackers to bypass authentication, log on as an administrator, and…
- CVE-2004-15511 PoCCross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute…
- CVE-2004-15522 PoCsSQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on…
- CVE-2004-15532 PoCsSQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the…
- CVE-2004-15541 PoCPHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitrary PHP code by…
- CVE-2004-15552 PoCsMultiple SQL injection vulnerabilities in BroadBoard Instant ASP Message Board allow remote attackers to run arbitrary SQL commands via…
- CVE-2004-15585 PoCsMultiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial of service…
- CVE-2004-15597 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the…
- CVE-2004-15601 PoCMicrosoft SQL Server 7.0 allows remote attackers to cause a denial of service (mssqlserver service halt) via a long request to TCP port…
- CVE-2004-156110 PoCsBuffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a large number of…
- CVE-2004-15621 PoCSQL injection vulnerability in redir_url.php in w-Agora 4.1.6a allows remote attackers to execute arbitrary SQL commands via the key…
- CVE-2004-15633 PoCsMultiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web script or HTML via…
- CVE-2004-15641 PoCCRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks…
- CVE-2004-15671 PoCprofile.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to gain privileges by setting the mail parameter to 1, which is the…
- CVE-2004-15691 PoCBuffer overflow in (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe in dBpowerAMP Audio Player 2.0 and dbPowerAmp Music Converter…
- CVE-2004-15711 PoCAJ-Fork 167 allows remote attackers to gain sensitive information via a direct request to (1) auto-acronyms.php, (2) auto-archive.php, (3)…
- CVE-2004-15731 PoCThe documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute…
- CVE-2004-15741 PoCBuffer overflow in Vypress Messenger 3.5.1 and earlier allows remote attackers to execute arbitrary code via a message with a long first…
- CVE-2004-15802 PoCsSQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id…
- CVE-2004-15842 PoCsCRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify…
- CVE-2004-15851 PoCFlash Messaging 5.2.0g (rev 1.1.2) and earlier allows remote attackers to cause a denial of service (application crash) via certain wide…
- CVE-2004-15871 PoCBuffer overflow in Monolith games including (1) Alien versus Predator 2 1.0.9.6 and earlier, (2) Blood 2 2.1 and earlier, (3) No one lives…
- CVE-2004-15921 PoCPHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code…
- CVE-2004-15953 PoCsBuffer overflow in ShixxNote 6.net build 117 allows remote attackers to execute arbitrary code via a long font field.
- CVE-2004-15961 PoCThe 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as passwords and…
- CVE-2004-16011 PoCDirectory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files and execute local…
- CVE-2004-16022 PoCsProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote…
- CVE-2004-16122 PoCsDirectory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a…
- CVE-2004-16181 PoCVypress Tonecast 1.3 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed mp2 stream.
- CVE-2004-16191 PoCBuffer overflow in Privateer's Bounty: Age of Sail II allows remote attackers to execute arbitrary code via a long nickname.
- CVE-2004-16201 PoCCRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify…
- CVE-2004-16211 PoCNOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and…
- CVE-2004-16221 PoCSQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name…
- CVE-2004-16231 PoCThe WAV file property handler in Windows XP SP1 allows remote attackers to cause a denial of service (infinite loop in Explorer) via a WAV…
- CVE-2004-16241 PoCCarbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local…
- CVE-2004-16264 PoCsBuffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long STOR…
- CVE-2004-16271 PoCBuffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a…
- CVE-2004-16361 PoCHeap-based buffer overflow in the WvTFTPServer::new_connection function in wvtftpserver.cc for WvTftp 0.9 allows remote attackers to…
- CVE-2004-16385 PoCsBuffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long (1) EHLO and possibly (2) HELO command.
- CVE-2004-16401 PoCMultiple cross-site scripting (XSS) vulnerabilities in XOOPS 0.94 and 1.0 allow remote attackers to execute arbitrary web script and HTML…
- CVE-2004-16412 PoCsHeap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) via a long FTP…
- CVE-2004-16421 PoCWFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST commands.
- CVE-2004-16431 PoCWS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that contains an invalid…
- CVE-2004-16452 PoCsCross-site scripting (XSS) vulnerability in Xedus 1.0 allows remote attackers to execute arbitrary web script or HTML via the (1) username…
- CVE-2004-16461 PoCDirectory traversal vulnerability in Xedus 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
- CVE-2004-16471 PoCSQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via…
- CVE-2004-16502 PoCsD-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the IP address of the…
- CVE-2004-16551 PoCCross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML…
- CVE-2004-16561 PoCCRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify…
- CVE-2004-16571 PoCCross-site scripting (XSS) vulnerability in the Activity and Events Viewer for Newtelligence DasBlog allows remote attackers to inject…
- CVE-2004-16591 PoCCross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Administrator, Editor,…
- CVE-2004-16611 PoCMailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains "auth=1" and "uId=1."
- CVE-2004-16621 PoCYaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path…
- CVE-2004-16641 PoCCall of Duty 1.4 and earlier allows remote attackers to cause a denial of service (game end) via a large (1) query or (2) reply packet,…
- CVE-2004-16651 PoCCross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the…
- CVE-2004-16662 PoCsBuffer overflow in the MSN module in Trillian 0.74i allows remote MSN servers to execute arbitrary code via a long string that ends in a…
- CVE-2004-16751 PoCServ-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command…
- CVE-2004-16781 PoCDirectory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly…
- CVE-2004-16814 PoCsMultiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI for QNX RTP 6.1…
- CVE-2004-16871 PoCCRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response Splitting attacks…
- CVE-2004-16881 PoCPigeon Server 3.02.0143 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a long…
- CVE-2004-16891 PoCsudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a…
- CVE-2004-16911 PoCThe Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a large amount of…
- CVE-2004-16921 PoCCross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML…
- CVE-2004-16931 PoCPHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by…
- CVE-2004-16951 PoCEmuLive Server4 Commerce Edition Build 7560 allows remote attackers to bypass authentication for the remote administration feature via a…
- CVE-2004-16961 PoCEmuLive Server4 Commerce Edition Build 7560 allows remote attackers to cause a denial of service (application crash) via a sequence of…
- CVE-2004-16981 PoCThe Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service…
- CVE-2004-16991 PoCSettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid…
- CVE-2004-17014 PoCsHeap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to…
- CVE-2004-17021 PoCThe AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 does not properly check the return value of the…
- CVE-2004-17031 PoCFusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img…
- CVE-2004-17042 PoCsWpQuiz 2.60b1 through 2.60b8 allows remote attackers to gain privileges via a direct request to adminrestore.php in the extras directory.
- CVE-2004-17053 PoCsBuffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.
- CVE-2004-17071 PoCThe (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and…
- CVE-2004-17141 PoCBlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone…
- CVE-2004-17172 PoCsMultiple buffer overflows in the psscan function in ps.c for gv (ghostview) allow remote attackers to execute arbitrary code via a…
- CVE-2004-17194 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbitrary web script or…
- CVE-2004-17201 PoCThe (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information…
- CVE-2004-17221 PoCSQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via…
- CVE-2004-17241 PoCThe ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world…
- CVE-2004-17251 PoCStack-based buffer overflow in xvbmp.c in XV allows remote attackers to execute arbitrary code via a crafted image file.
- CVE-2004-17261 PoCMultiple integer overflows in (1) xviris.c, (2) xvpcx.c, and (3) xvpm.c in XV allow remote attackers to execute arbitrary code via a…
- CVE-2004-17271 PoCBadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same…
- CVE-2004-17281 PoCBuffer overflow in British National Corpus SARA (sarad) allows remote attackers to execute arbitrary code by calling the client with a…
- CVE-2004-17311 PoCsignup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail…
- CVE-2004-17351 PoCCross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject…
- CVE-2004-17371 PoCSQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass…
- CVE-2004-17391 PoCBird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users.
- CVE-2004-17401 PoCMusic daemon (musicd) 0.0.3 and earlier allows remote attackers to read arbitrary files by calling LOAD with a full pathname, then calling…
- CVE-2004-17412 PoCsMusic daemon (musicd) 0.0.3 and earlier allows remote attackers to cause a denial of service (crash) by calling LOAD with a binary file as…
- CVE-2004-17421 PoCDirectory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a .. (dot dot) in the viewcat…
- CVE-2004-17441 PoCEasy File Sharing (EFS) Webserver 1.25 allows remote attackers to cause a denial of service (CPU consumption or crash) via many large HTTP…
- CVE-2004-17451 PoCBuffer overflow in Painkiller 1.3.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute…
- CVE-2004-17461 PoCCross-site scripting (XSS) vulnerability in index.php in PHP Code Snippet Library allows remote attackers to inject arbitrary web script…
- CVE-2004-17481 PoCNtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid pointers to hook…
- CVE-2004-17511 PoCGround Control II: Operation Exodus 1.0.0.7 and earlier allows remote servers to cause a denial of service (client or server crash) via a…
- CVE-2004-17521 PoCStack-based buffer overflow in Gaucho 1.4 Build 145 allows remote attackers to execute arbitrary code via a POP3 email with a long…
- CVE-2004-17541 PoCThe DNS proxy (DNSd) for multiple Symantec Gateway Security products allows remote attackers to poison the DNS cache via a malicious DNS…
- CVE-2004-17693 PoCsThe "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote…
- CVE-2004-17701 PoCThe login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters…
- CVE-2004-17741 PoCBuffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows…
- CVE-2004-17811 PoCInfo Touch Surfnet kiosk allows local users to crash Surfnet and access the underlying operating system via the CMD_CREDITCARD_CHARGE…
- CVE-2004-17821 PoCathenareg.php in Athena Web Registration allows remote attackers to execute arbitrary commands via shell metacharacters in the pass…
- CVE-2004-17831 PoCDirectory traversal vulnerability in Net2Soft Flash FTP Server 1.0 allows remote attackers to read and create arbitrary files via a /..…
- CVE-2004-17841 PoCBuffer overflow in the web server of Webcam Watchdog 3.63 allows remote attackers to execute arbitrary code via a long HTTP GET request.
- CVE-2004-17861 PoCPortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to…
- CVE-2004-17881 PoCASP-Nuke 1.3 and earlier places user credentials under the web document root with insufficient access control, which allows remote…
- CVE-2004-17891 PoCCross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to inject arbitrary web…
- CVE-2004-17901 PoCCross-site scripting (XSS) vulnerability in the web management interface in Edimax AR-6004 ADSL Routers allows remote attackers to inject…
- CVE-2004-17921 PoCswnet.dll in YaSoft Switch Off 2.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a long packet with…
- CVE-2004-17931 PoCStack-based buffer overflow in swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote authenticated users to execute arbitrary code…
- CVE-2004-17963 PoCsPHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1)…
- CVE-2004-17971 PoCCross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to inject arbitrary…
- CVE-2004-18011 PoCDirectory traversal vulnerability in PWebServer 0.3.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
- CVE-2004-18051 PoCFormat string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of service (crash)…
- CVE-2004-18101 PoCThe Javascript engine in Opera 7.23 allows remote attackers to cause a denial of service (crash) by creating a new Array object with a…
- CVE-2004-18131 PoCVocalTec VGW4/8 Gateway 8.0 allows remote attackers to bypass authentication via an HTTP request to home.asp with a trailing slash (/).
- CVE-2004-18171 PoCCross-site scripting (XSS) vulnerability in modules.php in Php-Nuke 7.1.0 allows remote attackers to inject arbitrary web script or HTML…
- CVE-2004-18181 PoCCross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute…
- CVE-2004-18201 PoCPHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to…
- CVE-2004-18211 PoCSQL injection vulnerability in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to gain privileges or perform…
- CVE-2004-18223 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject arbitrary web script…
- CVE-2004-18232 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4 allows remote attackers to inject…
- CVE-2004-18241 PoCCross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.0 allows remote attackers to inject arbitrary web script or HTML…
- CVE-2004-18251 PoCCross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject…
- CVE-2004-18261 PoCSQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary…
- CVE-2004-18271 PoCCross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web…
- CVE-2004-18281 PoCVcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall…
- CVE-2004-18291 PoCMultiple cross-site scripting (XSS) vulnerabilities in error.php in Gijza.net Error Manager 2.1 for PHP-Nuke 6.0 allow remote attackers to…
- CVE-2004-18301 PoCerror.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2)…
- CVE-2004-18352 PoCsMultiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1)…
- CVE-2004-18361 PoCSQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary…
- CVE-2004-18381 PoCDirectory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the URL.
- CVE-2004-18421 PoCCross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges…
- CVE-2004-18432 PoCsSQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1)…
- CVE-2004-18442 PoCsCross-site scripting (XSS) vulnerability in Member Management System 2.1 allows remote attackers to inject arbitrary web script or HTML…
- CVE-2004-18453 PoCsMultiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML…
- CVE-2004-18463 PoCsMultiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via the (1) ID…
- CVE-2004-18471 PoCNews Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN parameter in…
- CVE-2004-18501 PoCThe Rage 1.01 and earlier allows remote attackers to cause a denial of service (infinite loop) via a TCP packet with the port and IP…
- CVE-2004-18531 PoCBuffer overflow in Terminator 3: War of the Machines 1.0 allows remote attackers to cause a denial of service via a long ServerInfo…
- CVE-2004-18542 PoCsBuffer overflow in the logging function in Picophone 1.63 and earlier allows remote attackers to execute arbitrary code via a large packet.
- CVE-2004-18551 PoCDark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers to gain sensitive…
- CVE-2004-18561 PoCdevices_update_printer_fw_upload.hts in HP Web JetAdmin 7.5.2546, when no password is set, allows remote attackers to upload arbitrary…
- CVE-2004-18572 PoCsDirectory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to read arbitrary files…
- CVE-2004-18591 PoCDirectory traversal vulnerability in Trend Micro Interscan Web Viruswall in InterScan VirusWall 3.5x allows remote attackers to read…
- CVE-2004-18611 PoCInvision NetSupport School Pro uses a weak encryption algorithm to encrypt passwords, which allows local users to obtain passwords.
- CVE-2004-18661 PoCnstxd in Nstx 1.1 beta3 and earlier allows remote attackers to cause a denial of service (crash) via a large packet, which triggers a null…
- CVE-2004-18671 PoCCross-site scripting (XSS) vulnerability in guest.cgi in Fresh Guest Book allows remote attackers to inject arbitrary web script or HTML…
- CVE-2004-18683 PoCsStack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE…
- CVE-2004-18702 PoCsMultiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1)…
- CVE-2004-18711 PoCMultiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to inject arbitrary web…
- CVE-2004-18721 PoCCross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote attackers to inject arbitrary web script or HTML…
- CVE-2004-18732 PoCsSQL injection vulnerability in category.asp in A-CART Pro and A-CART 2.0 allows remote attackers to gain privileges via the catcode…
- CVE-2004-18751 PoCMultiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via…
- CVE-2004-18781 PoCLINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to…
- CVE-2004-18811 PoCSQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL…
- CVE-2004-18821 PoCCross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or…
- CVE-2004-18831 PoCMultiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code by causing a…
- CVE-2004-18872 PoCsAda Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a trailing %00 (null).
- CVE-2004-18882 PoCsdisplay.cgi in Aborior Encore WebForum allows remote to execute arbitrary commands via shell metacharacters in the file variable.
- CVE-2004-18921 PoCStack-based buffer overflow in DecodeBase16 function, as used in the (1) IRC module and (2) web server in eMule 0.42d, allows remote…
- CVE-2004-18971 PoCAdministration interface in Monit 1.4 through 4.2 allows remote attackers to cause a denial of service (segmentation fault) by sending a…
- CVE-2004-18981 PoCStack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via…
- CVE-2004-19031 PoCBuffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an object tag.
- CVE-2004-19041 PoCBuffer overflow in ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to execute arbitrary code via the Internacional property…
- CVE-2004-19061 PoCMcafee FreeScan allows remote attackers to cause a denial of service and possibly arbitrary code via a long string in the ScanParam…
- CVE-2004-19071 PoCThe Web Filtering functionality in Kerio Personal Firewall (KPF) 4.0.13 allows remote attackers to cause a denial of service (crash) by…
- CVE-2004-19082 PoCsMcFreeScan.CoMcFreeScan.1 ActiveX object in Mcafee FreeScan allows remote attackers to obtain sensitive information via the…
- CVE-2004-19101 PoCrufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to the…
- CVE-2004-19112 PoCsCross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the…
- CVE-2004-19124 PoCsThe (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used…
- CVE-2004-19131 PoCCross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject…
- CVE-2004-19141 PoCSQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL…
- CVE-2004-19151 PoCBuffer overflow in the parse_all_client_messages function in LCDproc 0.4.x up to 0.4.4 allows remote attackers to execute arbitrary code…
- CVE-2004-19191 PoCThe hash_strcmp function in hasch.c in Crackalaka 1.0.8 allows remote attackers to cause a denial of service (crash) via large malformed…
- CVE-2004-19232 PoCsTiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1)…
- CVE-2004-19248 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to inject…
- CVE-2004-19258 PoCsMultiple SQL injection vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to execute arbitrary SQL…
- CVE-2004-19263 PoCsTiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real…
- CVE-2004-19272 PoCsDirectory traversal vulnerability in the map feature (tiki-map.phtml) in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote…
- CVE-2004-19282 PoCsThe image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute…
- CVE-2004-19291 PoCSQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass…
- CVE-2004-19301 PoCCross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used,…
- CVE-2004-19321 PoCSQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL…
- CVE-2004-19341 PoCPHP remote file inclusion vulnerability in affich.php in Gemitel 3.50 allows remote attackers to execute arbitrary PHP code via the base…
- CVE-2004-19351 PoCCross-site scripting (XSS) vulnerability in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via onload,…
- CVE-2004-19371 PoCMultiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote attackers to read or include arbitrary files via ..…
- CVE-2004-19382 PoCsSQL injection vulnerability in userlogin.php in Phorum 3.4.7 allows remote attackers to execute arbitrary SQL commands via doubly…
- CVE-2004-19391 PoCCross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows remote attackers to inject arbitrary web script or HTML via double…
- CVE-2004-19401 PoCsipclient.cpp in KPhone 4.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a STUN response packet with a…
- CVE-2004-19431 PoCPHP remote file inclusion vulnerability in album_portal.php in phpBB modified by Przemo 1.8 allows remote attackers to execute arbitrary…
- CVE-2004-19441 PoCEudora 6.1 and 6.0.3 for Windows allows remote attackers to cause a denial of service (crash) via a deeply nested multipart MIME message.
- CVE-2004-19453 PoCsBuffer overflow in Kinesphere eXchange POP3 allows remote attackers to execute arbitrary code via a long MAIL FROM field.
- CVE-2004-19472 PoCsThe AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive…
- CVE-2004-19511 PoCxine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via…
- CVE-2004-19523 PoCsSQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via…
- CVE-2004-19531 PoCphProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in…
- CVE-2004-19541 PoCCross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML…
- CVE-2004-19551 PoCSQL injection vulnerability in modules.php in phProfession 2.5 allows remote attackers to execute arbitrary SQL code via the offset…
- CVE-2004-19572 PoCsMultiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2004-19581 PoCDirectory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files via .. (dot dot)…
- CVE-2004-19601 PoCCross-site scripting (XSS) vulnerability in blocker_query.php in Protector System 1.15b1 allows remote attackers to inject arbitrary web…
- CVE-2004-19611 PoCblocker.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection protection and execute limited SQL commands via…
- CVE-2004-19621 PoCSQL injection vulnerability in index.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection filters by using…
- CVE-2004-19656 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject…
- CVE-2004-19664 PoCsMultiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execute arbitrary SQL…
- CVE-2004-19681 PoCThe readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbitrary messages by…
- CVE-2004-19721 PoCSQL injection vulnerability in modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to execute arbitrary SQL…
- CVE-2004-19731 PoCDiGi Web Server allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request that contains a large…
- CVE-2004-19751 PoCCross-site scripting (XSS) vulnerability in the category module in pafiledb.php for paFileDB 3.1 allows remote attackers to inject…
- CVE-2004-19781 PoCCross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script…
- CVE-2004-19832 PoCsThe arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is…
- CVE-2004-19851 PoCCross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary…
- CVE-2004-19861 PoCDirectory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with…
- CVE-2004-19881 PoCPHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary…
- CVE-2004-19891 PoCPHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP…
- CVE-2004-19921 PoCBuffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter,…
- CVE-2004-19951 PoCCross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to…
- CVE-2004-19961 PoCCross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the…