CVE-2004-2000 to CVE-2004-2999
250 CVEs with public proof-of-concept exploits.
- CVE-2004-20001 PoCSQL injection vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL via the…
- CVE-2004-20031 PoCBuffer overflow in the ssl_prcert function in the SSLway filter (sslway.c) for DeleGate 8.9.2 and earlier allows remote attackers to…
- CVE-2004-20051 PoCBuffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-mail with (1) a…
- CVE-2004-20071 PoCCross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to inject arbitrary HTML or…
- CVE-2004-20081 PoCSQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid…
- CVE-2004-20121 PoCThe systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not…
- CVE-2004-20141 PoCWget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.
- CVE-2004-20171 PoCMultiple cross-site scripting (XSS) vulnerabilities in Turbo Traffic Trader C (TTT-C) 1.0 allow remote attackers to inject arbitrary HTML…
- CVE-2004-20181 PoCPHP remote file inclusion vulnerability in index.php in Php-Nuke 6.x through 7.3 allows remote attackers to execute arbitrary PHP code by…
- CVE-2004-20211 PoCDirectory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot)…
- CVE-2004-20221 PoCActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial…
- CVE-2004-20262 PoCsFormat string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code…
- CVE-2004-20281 PoCCross-site scripting (XSS) vulnerability in stats.php in e107 allows remote attackers to inject arbitrary web script or HTML via the…
- CVE-2004-20291 PoCThe Util_DecodeHTTPAuth function in BNBT BitTorrent Tracker Beta 7.5 Release 2 and earlier allows remote attackers to cause a denial of…
- CVE-2004-20301 PoCMultiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to…
- CVE-2004-20321 PoCNetgear RP114 allows remote attackers to bypass the keyword based URL filtering by requesting a long URL, as demonstrated using a large…
- CVE-2004-20333 PoCsOrenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.
- CVE-2004-20351 PoCMiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper…
- CVE-2004-20361 PoCSQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers…
- CVE-2004-20371 PoCBuffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and…
- CVE-2004-20381 PoCCross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or…
- CVE-2004-20402 PoCsMultiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the…
- CVE-2004-20432 PoCsBuffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase…
- CVE-2004-20441 PoCPHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and…
- CVE-2004-20451 PoCThe HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of…
- CVE-2004-20471 PoCDirectory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a…
- CVE-2004-20531 PoCPHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitrary PHP code via…
- CVE-2004-20594 PoCsMultiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1)…
- CVE-2004-20601 PoCASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a…
- CVE-2004-20612 PoCsRiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files,…
- CVE-2004-20621 PoCSQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1)…
- CVE-2004-20631 PoCCross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inject arbitrary HTML…
- CVE-2004-20641 PoCCross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web script via the (1)…
- CVE-2004-20671 PoCSQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute…
- CVE-2004-20711 PoCMacallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authentication in the web…
- CVE-2004-20721 PoCCross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to…
- CVE-2004-20732 PoCsLinux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server…
- CVE-2004-20743 PoCsFormat string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the…
- CVE-2004-20761 PoCCross-site scripting (XSS) vulnerability in search.php for Jelsoft vBulletin 3.0.0 RC4 allows remote attackers to inject arbitrary web…
- CVE-2004-20772 PoCsNadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via…
- CVE-2004-20781 PoCRed-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss of logged events)…
- CVE-2004-20811 PoCThe samiftp.dll library in Sami FTP Server 1.1.3 allows local users to cause a denial of service (pmsystem.exe crash) by issuing (1) a CD…
- CVE-2004-20821 PoCThe samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsystem.exe crash) via a…
- CVE-2004-20863 PoCsStack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial…
- CVE-2004-20901 PoCMicrosoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript…
- CVE-2004-20931 PoCBuffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service…
- CVE-2004-20941 PoCCross-site scripting (XSS) vulnerability in WebcamXP 1.06.945 allows remote attackers to inject arbitrary HTML or web script as other…
- CVE-2004-20961 PoCCross-site scripting (XSS) vulnerability in Mephistoles httpd 0.6.0 final allows remote attackers to execute arbitrary script as other…
- CVE-2004-20991 PoCBuffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute…
- CVE-2004-21021 PoCCross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web…
- CVE-2004-21043 PoCsNovell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP…
- CVE-2004-21071 PoCFinjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote…
- CVE-2004-21117 PoCsStack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code…
- CVE-2004-21121 PoCDirectory traversal vulnerability in BremsServer 1.2.4 allows remote attackers to read arbitrary files via ".." (dot dot) sequences in the…
- CVE-2004-21131 PoCCross-site scripting (XSS) vulnerability in BremsServer 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the URL.
- CVE-2004-21141 PoCStack-based and heap-based buffer overflows in ProxyNow! 2.75 and earlier allow remote attackers to execute arbitrary code via a GET…
- CVE-2004-21151 PoCMultiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute…
- CVE-2004-21161 PoCDirectory traversal vulnerability in Tiny Server 1.1 allows remote attackers to read or download arbitrary files via a .. (dot dot) in the…
- CVE-2004-21171 PoCTiny Server 1.1 allows remote attackers to cause a denial of service (crash) via malformed HTTP requests such as (1) a GET request without…
- CVE-2004-21191 PoCCross-site scripting (XSS) vulnerability in Tiny Server 1.1 allows remote attackers to inject arbitrary web script or HTML via the URL.
- CVE-2004-21201 PoCReptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET requests without the…
- CVE-2004-21211 PoCMultiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download…
- CVE-2004-21242 PoCsThe register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable…
- CVE-2004-21271 PoCDirectory traversal vulnerability in Web Blog 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file variable.
- CVE-2004-21281 PoCCross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as other users via the…
- CVE-2004-21291 PoCSurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a…
- CVE-2004-21301 PoCMultiple cross-site scripting (XSS) vulnerabilities in privmsg.php in phpBB 2.0.6 allow remote attackers to execute arbitrary script or…
- CVE-2004-21312 PoCsStack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges,…
- CVE-2004-21321 PoCDirectory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary files via a .. (dot…
- CVE-2004-21341 PoCOracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the passwords.
- CVE-2004-21351 PoCcryptoloop on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation"…
- CVE-2004-21431 PoCSQL injection vulnerability in the ReMOSitory Server add-on module to Mambo Portal 4.5.1 (1.09) and earlier allows remote attackers to…
- CVE-2004-21511 PoCChatman 1.1.1 RC1 and earlier allows remote attackers to cause a denial of service (memory consumption or application crash) via a very…
- CVE-2004-21571 PoCCross-site scripting (XSS) vulnerability in Comment.php in Serendipity 0.7 beta1, and possibly other versions before 0.7-beta3, allows…
- CVE-2004-21582 PoCsSQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter…
- CVE-2004-21611 PoCSQL injection vulnerability in file_overview.php in TUTOS 1.1 allows remote attackers to execute arbitrary SQL commands via the link_id…
- CVE-2004-21621 PoCMultiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the…
- CVE-2004-21652 PoCsLords of the Realm III 1.01 and earlier, when in the lobby stage, allows remote attackers to cause a denial of service (crash from…
- CVE-2004-21672 PoCsMultiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary code via (1) the…
- CVE-2004-21701 PoCDirectory traversal vulnerability in sample_showcode.html in Caravan 2.00/03d and earlier allows remote attackers to read arbitrary files…
- CVE-2004-21711 PoCCross-site scripting (XSS) vulnerability in Cherokee before 0.4.8 allows remote attackers to inject arbitrary web script or HTML via the…
- CVE-2004-21721 PoCEarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via a…
- CVE-2004-21752 PoCsMultiple SQL injection vulnerabilities in ReviewPost PHP Pro allow remote attackers to execute arbitrary SQL commands via the (1) product…
- CVE-2004-21761 PoCThe Internet Connection Firewall (ICF) in Microsoft Windows XP SP2 is configured by default to trust sessmgr.exe, which allows local users…
- CVE-2004-21811 PoCMultiple SQL injection vulnerabilities in WowBB Forum 1.61 allow remote attackers to execute arbitrary SQL commands via the (1) sort_by or…
- CVE-2004-21841 PoCDirectory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write arbitrary files via…
- CVE-2004-21931 PoCCross-site scripting (XSS) vulnerability in trade.php for CJOverkill 4.0.3 allows remote attackers to inject arbitrary web script or HTML…
- CVE-2004-21981 PoCaccount.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the…
- CVE-2004-22013 PoCsSQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID…
- CVE-2004-22021 PoCMultiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute…
- CVE-2004-22181 PoCSQL injection vulnerability in pmwh.php in PHPMyWebHosting 0.3.4 and earlier allows remote attackers to modify SQL statements via the…
- CVE-2004-22213 PoCsBuffer overflow in SoftCart.exe in Mercantec SoftCart 4.00b allows remote attackers to execute arbitrary code via a long parameter in an…
- CVE-2004-22421 PoCCross-site scripting (XSS) vulnerability in search.php in Phorum, possibly 5.0.7 beta and earlier, allows remote attackers to inject…
- CVE-2004-22451 PoCCross-site scripting (XSS) vulnerability in Goollery 0.03 allows remote attackers to inject arbitrary HTML or web script via the (1) page…
- CVE-2004-22461 PoCCross-site scripting (XSS) vulnerability in Goollery before 0.04b allows remote attackers to inject arbitrary HTML or web script via the…
- CVE-2004-22531 PoCDirectory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in…
- CVE-2004-22541 PoCSurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the…
- CVE-2004-22621 PoCImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary…
- CVE-2004-22631 PoCSQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL…
- CVE-2004-227110 PoCsBuffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
- CVE-2004-22751 PoCi-mall.cgi in I-Mall Commerce allows remote attackers to execute arbitrary commands via shell metacharacters via the p parameter.
- CVE-2004-22771 PoCBuffer overflow in aGSM Half-Life client allows remote Half-Life servers to cause a denial of service (crash) and possibly execute…
- CVE-2004-22801 PoCBuffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial of service (crash)…
- CVE-2004-22861 PoCInteger overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash) and possibly…
- CVE-2004-22871 PoCDirectory traversal vulnerability in explorer.php in DSM Light Web File Browser 2.0 allows remote attackers to read arbitrary files via ..…
- CVE-2004-22882 PoCsCross-site scripting (XSS) vulnerability in index.php in Jelsoft vBulletin allows remote attackers to spoof parts of a website via the loc…
- CVE-2004-22891 PoCMicrosoft Windows XP Explorer allows local users to execute arbitrary code via a system folder with a Desktop.ini file containing a…
- CVE-2004-22911 PoCMicrosoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script that uses Shell…
- CVE-2004-22931 PoCMultiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.0 to 7.3 allow remote attackers to inject arbitrary web script or HTML…
- CVE-2004-22941 PoCCanonicalize-before-filter error in the send_review function in the Reviews module for PHP-Nuke 6.0 to 7.3 allows remote attackers to…
- CVE-2004-22951 PoCSQL injection vulnerability in the Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2004-22971 PoCThe Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large,…
- CVE-2004-22991 PoCBuffer overflow in Omnicron OmniHTTPd 3.0a and earlier allows remote attackers to execute arbitrary code via an HTTP GET request with a…
- CVE-2004-23001 PoCBuffer overflow in snmpd in ucd-snmp 4.2.6 and earlier, when installed setuid root, allows local users to execute arbitrary code via a…
- CVE-2004-23031 PoCMTools Mformat before 3.9.9, when installed setuid root, creates files with world-readable and world-writable permissions, which allows…
- CVE-2004-23081 PoCCross-site scripting (XSS) vulnerability in cPanel 9.1.0 and possibly earlier allows remote attackers to inject arbitrary web script or…
- CVE-2004-23091 PoCDirectory traversal vulnerability in Crob FTP Server 3.5.1 allows local users to browse outside the FTP root via multiple ../ (dot dot…
- CVE-2004-23101 PoCCross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbitrary web script…
- CVE-2004-23111 PoCDirectory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or determine the existence…
- CVE-2004-23121 PoCBuffer overflow in GNU make for IBM AIX 4.3.3, when installed setgid, allows local users to gain privileges via a long CC argument.
- CVE-2004-23261 PoCSQL injection vulnerability in IP3 Networks NetAccess Appliance before firmware 3.1.18b13 allows remote attackers to bypass authentication…
- CVE-2004-23341 PoCMultiple cross-site scripting (XSS) vulnerabilities in EMU Webmail 5.2.7 allow remote attackers to inject arbitrary web script or HTML via…
- CVE-2004-23441 PoCUnknown vulnerability in the ASN.1/H.323/H.225 stack of VocalTec VGW120 and VGW480 allows remote attackers to cause a denial of service.
- CVE-2004-23471 PoCblog.cgi in Leif M. Wright Web Blog 1.1 and 1.1.5 allows remote attackers to execute arbitrary commands via shell metacharacters such as…
- CVE-2004-23501 PoCSQL injection vulnerability in search.php for phpBB 1.0 through 2.0.6 allows remote attackers to execute arbitrary SQL and gain privileges…
- CVE-2004-23551 PoCCross-site scripting (XSS) vulnerability in Crafty Syntax Live Help (CSLH) before 2.7.4 allows remote attackers to inject arbitrary web…
- CVE-2004-23591 PoCDell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started from the systray…
- CVE-2004-23602 PoCsTargem Battle Mages 1.0 allows remote attackers to cause a denial of service (infinite loop) via a UDP packet with incomplete data, which…
- CVE-2004-23611 PoCDigital Reality game engine, as used in Haegemonia 1.0 through 1.0.7 and Desert Rats vs. Afrika Korps 1.0, allows remote attackers to…
- CVE-2004-23631 PoCValidate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allows remote attackers…
- CVE-2004-23646 PoCsCross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs…
- CVE-2004-23661 PoCBuffer overflow in GlobalSCAPE Secure FTP Server 2.0 B03.11.2004.2 allows remote attackers to cause a denial of service (crash) via a SITE…
- CVE-2004-23671 PoCThe Control Panel applet in WFTPD and WFTPD Pro 3.21 R1 and R2 allows remote authenticated users to cause a denial of service (crash) via…
- CVE-2004-23681 PoCPHP remote file inclusion vulnerability in header.php in Opt-X 0.7.2 allows remote attackers to execute arbitrary PHP code via the…
- CVE-2004-23711 PoCMultiple Red Storm web-based games, including Ghost Recon 1.4 and earlier, Desert Siege, and The Sum of all Fears 1.1.1.0 and earlier, do…
- CVE-2004-23731 PoCThe Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allow remote attackers…
- CVE-2004-23741 PoCBadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php, which includes…
- CVE-2004-23751 PoCBuffer overflow in the POP3 server in 1st Class Mail Server 4.0 allows remote attackers to cause a denial of service (crash) and possibly…
- CVE-2004-23831 PoCMicrosoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard…
- CVE-2004-23851 PoCEMU Webmail 5.2.7 allows remote attackers to obtain sensitive path information (home directory) via an HTTP request for init.emu.
- CVE-2004-24111 PoCThe CleanseMessage function in shop$db.asp for VP-ASP Shopping Cart 4.0 through 5.0 does not sufficiently cleanse inputs, which allows…
- CVE-2004-24131 PoCSQL injection vulnerability in VP-ASP Shopping Cart 4.0 through 5.0 allows remote attackers to execute arbitrary SQL commands via the (1)…
- CVE-2004-24162 PoCsBuffer overflow in the logging component of CCProxy allows remote attackers to execute arbitrary code via a long HTTP GET request.
- CVE-2004-24182 PoCsBuffer overflow in SlimFTPd 3.15 and earlier allows local users to execute arbitrary code via a long command, such as (1) CWD, (2) STOR,…
- CVE-2004-24252 PoCsAxis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent…
- CVE-2004-24261 PoCDirectory traversal vulnerability in Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to…
- CVE-2004-24271 PoCAxis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via…
- CVE-2004-24321 PoCWinAgents TFTP Server 3.0 allows remote attackers to cause a denial of service (crash) via a request for a file with a long file name,…
- CVE-2004-24341 PoCMicrosoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon…
- CVE-2004-24421 PoCMultiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and…
- CVE-2004-24431 PoCJaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash…
- CVE-2004-24441 PoCCross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script or HTML via the…
- CVE-2004-24451 PoCDirectory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a .. (dot dot) in the…
- CVE-2004-24476 PoCsCross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2004-24491 PoCRoger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial of service…
- CVE-2004-24511 PoCRoger Wilco 1.4.1.6 and earlier, or Roger Wilco Base Station 0.30a or earlier, allows remote attackers to send audio to arbitrary…
- CVE-2004-24561 PoCSQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL commands via the user…
- CVE-2004-24641 PoCDirectory traversal vulnerability in ADA Image Server (ImgSvr) 0.4 allows remote attackers to read arbitrary files or list directories via…
- CVE-2004-24666 PoCschat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter,…
- CVE-2004-24751 PoCCross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html…
- CVE-2004-24801 PoCSquid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via "@@" sequences in…
- CVE-2004-24871 PoCDirectory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files…
- CVE-2004-24911 PoCA race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which…
- CVE-2004-24941 PoCCross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or…
- CVE-2004-24961 PoCThe HTTP daemon in OpenText FirstClass 7.1 and 8.0 allows remote attackers to cause a denial of service (service availability loss) via a…
- CVE-2004-25012 PoCsBuffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute…
- CVE-2004-25022 PoCsim-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the imswitcher[PID]…
- CVE-2004-25051 PoCMacromedia ColdFusion MX before 6.1 does not restrict the size of error messages, which allows remote attackers to cause a denial of…
- CVE-2004-25071 PoCAbsolute path traversal vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to read…
- CVE-2004-25081 PoCCross-site scripting (XSS) vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to inject…
- CVE-2004-25093 PoCsCross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads 6.2.3 and 6.5…
- CVE-2004-25101 PoCCross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to inject arbitrary web…
- CVE-2004-25113 PoCsMultiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arbitrary web script…
- CVE-2004-25121 PoCCRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP response splitting…
- CVE-2004-25135 PoCsBuffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via a long SELECT…
- CVE-2004-25141 PoCCross-site scripting (XSS) vulnerability in modules/private_messages/index.php in PowerPortal 1.x allows remote attackers to inject…
- CVE-2004-25161 PoCDirectory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET command with a…
- CVE-2004-25171 PoCmyServer 0.7.1 allows remote attackers to cause a denial of service (crash) via a long HTTP POST request in a View=Logon operation to…
- CVE-2004-25182 PoCsGattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00") to a URL or (2)…
- CVE-2004-25191 PoCGattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specifiers in the…
- CVE-2004-25201 PoCPOP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (application crash) via a…
- CVE-2004-25221 PoCCross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject arbitrary web…
- CVE-2004-25233 PoCsFormat string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated…
- CVE-2004-25261 PoCDirectory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary…
- CVE-2004-25281 PoCCross-site scripting (XSS) vulnerability in sresult.exe in Webcam Watchdog 4.0.1a allows remote attackers to inject arbitrary web script…
- CVE-2004-25301 PoCVisual truncation vulnerability in Gadu-Gadu allows remote attackers to spoof the file extension on transmitted files via a filename with…
- CVE-2004-25321 PoCServ-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute…
- CVE-2004-25341 PoCFastream NETFile Server 7.1.2 does not properly handle keep-alive connection timeouts and does not close the connection after a HEAD…
- CVE-2004-25472 PoCsNetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify…
- CVE-2004-25481 PoCMultiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject…
- CVE-2004-25493 PoCsNortel Wireless LAN (WLAN) Access Point (AP) 2220, 2221, and 2225 allow remote attackers to cause a denial of service (service crash) via…
- CVE-2004-25511 PoCMultiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the…
- CVE-2004-25551 PoCRiverdeep FoolProof Security 3.9.x on Windows 98 and Windows ME uses weak cryptography (arithmetic and XOR operations) to relate the…
- CVE-2004-25611 PoCMultiple SQL injection vulnerabilities in Internet Software Sciences Web+Center 4.0.1 allow remote attackers to execute arbitrary SQL…
- CVE-2004-25621 PoCSQL injection vulnerability in jobedit.asp in Leigh Business Enterprises (LBE) Web Helpdesk before 4.0.0.81 allows remote attackers to…
- CVE-2004-25631 PoCSerena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and database information, and…
- CVE-2004-25642 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, allow…
- CVE-2004-25651 PoCMultiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, when the…
- CVE-2004-25661 PoCMultiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat,…
- CVE-2004-25731 PoCPHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute…
- CVE-2004-25741 PoCCross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary…
- CVE-2004-25921 PoCQuake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a…
- CVE-2004-26142 PoCsBuffer overflow in MyWeb 3.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long…
- CVE-2004-26161 PoCThe file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information by uploading a…
- CVE-2004-26171 PoCDirectory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the web root via a ..…
- CVE-2004-26181 PoCCross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary web script or HTML…
- CVE-2004-26251 PoCCross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTML via Javascript…
- CVE-2004-26261 PoCGUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SMS messages by…
- CVE-2004-26281 PoCMultiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary…
- CVE-2004-26311 PoCEval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute…
- CVE-2004-26361 PoCTinyWeb 1.9 allows remote attackers to read source code of scripts via "/./" in the URL.
- CVE-2004-26401 PoCDirectory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot…
- CVE-2004-26461 PoCThe addUser function in UserManager.java in Free Web Chat 2.0 allows remote attackers to cause a denial of service (uncaught…
- CVE-2004-26471 PoCFree Web Chat 2.0 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections from the same user.
- CVE-2004-26492 PoCsEudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of characters (e.g.…
- CVE-2004-26522 PoCsThe DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows…
- CVE-2004-26702 PoCsMultiple cross-site scripting (XSS) vulnerabilities in mod.php in eNdonesia 8.3 allow remote attackers to inject arbitrary web script or…
- CVE-2004-26711 PoCmod.php in eNdonesia 8.3 allows remote attackers to obtain sensitive information via certain direct requests, and certain requests with…
- CVE-2004-26751 PoCArGoSoft FTP Server before 1.4.1.6 allows remote authenticated users to cause a denial of service (crash) via a SITE PASS command with a…
- CVE-2004-26771 PoCFormat string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary…
- CVE-2004-26852 PoCsBuffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long address in a ping (p)…
- CVE-2004-26863 PoCsDirectory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel…
- CVE-2004-268723 PoCsdistcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute…
- CVE-2004-26911 PoCUnspecified vulnerability in 3Com SuperStack 3 4400 switches with firmware version before 3.31 allows remote attackers to cause a denial…
- CVE-2004-26921 PoCThe exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass restrictions and…
- CVE-2004-26971 PoCThe Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack…
- CVE-2004-26981 PoCRace condition in IMWheel 1.0.0pre11 and earlier, when running with the -k option, allows local users to cause a denial of service…
- CVE-2004-26991 PoCdeleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter.
- CVE-2004-27011 PoCCross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script…
- CVE-2004-27021 PoCCross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web…
- CVE-2004-27151 PoCedituser.php3 in PHPMyChat 0.14.5 allow remote attackers to bypass authentication and gain administrative privileges by setting the…
- CVE-2004-27161 PoCMultiple SQL injection vulnerabilities in usersL.php3 in PHPMyChat 0.14.5 allow remote attackers to execute arbitrary SQL commands via the…
- CVE-2004-27171 PoCMultiple directory traversal vulnerabilities in admin.php3 in PHPMyChat 0.14.5 allow remote attackers with administrative privileges to…
- CVE-2004-27181 PoCPHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information…
- CVE-2004-27191 PoCBuffer overflow in the UrlToLocal function in PunyLib.dll of Foxmail 5.0.300 allows remote attackers to execute arbitrary code via a mail…
- CVE-2004-27201 PoCCross-site scripting (XSS) vulnerability in register.asp in Snitz Forums 2000 3.4.04 and earlier allows remote attackers to inject…
- CVE-2004-27251 PoCMultiple cross-site scripting (XSS) vulnerabilities in Aztek Forum 4.0 allow remote attackers to inject arbitrary web script or HTML via…
- CVE-2004-27271 PoCBuffer overflow in MEHTTPS (HTTPMail) of MailEnable Professional 1.5 through 1.7 allows remote attackers to cause a denial of service…
- CVE-2004-27321 PoCnbmember.cgi in Netbilling 2.0 allows remote attackers to obtain sensitive information via the cmd=test option, which can be leveraged to…
- CVE-2004-27361 PoCPolar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cookie.
- CVE-2004-27371 PoCSQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary SQL commands via…
- CVE-2004-27451 PoCDirectory traversal vulnerability in Anteco Visual Technologies OwnServer 1.0 and earlier allows remote attackers to read arbitrary files…
- CVE-2004-27461 PoCSQL injection vulnerability in adminlogin.asp in XTREME ASP Photo Gallery 2.0 allows remote attackers to execute arbitrary SQL commands…
- CVE-2004-27481 PoCviewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via…
- CVE-2004-27491 PoCDirectory traversal vulnerability in wra/public/wralogin in 2Wire Gateway, possibly as used in HomePortal and other product lines, allows…
- CVE-2004-27501 PoCDirectory traversal vulnerability in browser.php in JBrowser 1.0 through 2.1 allows remote attackers to read arbitrary files via the…
- CVE-2004-27541 PoCSQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to…
- CVE-2004-27561 PoCCross-site scripting (XSS) vulnerability in viewtopic.php in Xoops 2.x, possibly 2 through 2.0.5, allows remote attackers to inject…
- CVE-2004-27611 PoCThe MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing…
- CVE-2004-27761 PoCgo.cgi in GoScript 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) query string or (2)…