CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2004-1995

    Last Modified: 16 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2010

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in phpShop 0.7.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the base_dir parameter to reference a URL on a remote web server that contains phpshop.cfg.

    Published: 31 Dec 2004
    2.6
    Low

    CVE-2004-2011

    Last Modified: 16 Apr 2026

    msxml3.dll in Internet Explorer 6.0.2600.0 allows remote attackers to cause a denial of service (crash) via a single & (ampersand) in a <Ref href> link, which triggers a parsing error, possibly due to missing portions of the URI.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2015

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in WebCT Campus Edition allows remote attackers to inject arbitrary HTML or web script via (1) iframe, (2) img, or (3) object tags.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2016

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the HTTP server in NetChat 7.3 and earlier allows remote attackers to execute arbitrary code via a long GET request.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2018

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Php-Nuke 6.x through 7.3 allows remote attackers to execute arbitrary PHP code by modifying the modpath parameter to reference a URL on a remote web server that contains the code.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2019

    Last Modified: 16 Apr 2026

    The WebLinks module in Php-Nuke 6.x through 7.3 allows remote attackers to obtain sensitive information via an invalid show parameter, which displays the full path in a PHP error message.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2023

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in login.php in Zen Cart 1.1.2d, 1.1.4 before patch 1, and possibly other versions allows remote attackers to execute arbitrary SQL via the (1) admin_name or (2) admin_pass parameters.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2024

    Last Modified: 16 Apr 2026

    The distribution of Zen Cart 1.1.4 before patch 2 includes certain debugging code in the Admin password retrieval functionality, which allows attackers to gain administrative privileges via password_forgotten.php.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2025

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in application_top.php for Zen Cart 1.1.3 before patch 2 may allow remote attackers to execute arbitrary SQL commands via the products_id parameter.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2026

    Last Modified: 16 Apr 2026

    Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format string specifiers in syslog messages.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-2049

    Last Modified: 16 Apr 2026

    eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain access.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2052

    Last Modified: 16 Apr 2026

    eSeSIX Thintune thin clients running firmware 2.4.38 and earlier accept any password that begins with the actual password, which makes it easier for users to conduct brute force password guessing.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2057

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2058

    Last Modified: 16 Apr 2026

    ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2059

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SearchFor parameter in [TABLE-NAME]_search.asp, (2) SQL parameter in [TABLE-NAME]_edit.asp, (3) SearchFor parameter in [TABLE]_list.asp, or (4) SQL parameter in export.asp.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2060

    Last Modified: 16 Apr 2026

    ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2062

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2) parent_id, or (3) mode parameters.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2063

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inject arbitrary HTML or web script via the feedback parameter.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2056

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in action.php in Nucleus CMS 3.01 allows remote attackers to execute arbitrary SQL statements via the itemid parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2068

    Last Modified: 16 Apr 2026

    fetchnews in leafnode 1.9.47 and earlier allows remote attackers to cause a denial of service (process hang) via an empty NNTP news article with missing mandatory headers.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2070

    Last Modified: 16 Apr 2026

    The Altiris Client Service for Windows 5.6 SP1 Hotfix E (5.6.181) allows local users to execute arbitrary commands by opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2005-1590.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2071

    Last Modified: 16 Apr 2026

    Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authentication in the web interface via an HTTP GET request with two slashes ("//") after the server name.

    Published: 31 Dec 2004
    6.8
    Medium

    CVE-2004-2072

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2075

    Last Modified: 16 Apr 2026

    Sophos Anti-Virus 3.78 allows remote attackers to cause a denial of service (infinite loop) via a MIME header that is not properly terminated.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2076

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php for Jelsoft vBulletin 3.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2081

    Last Modified: 16 Apr 2026

    The samiftp.dll library in Sami FTP Server 1.1.3 allows local users to cause a denial of service (pmsystem.exe crash) by issuing (1) a CD command with a tilde (~) character or dot dot (/../) or (2) a GET command for an unavailable file.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2074

    Last Modified: 16 Apr 2026

    Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2116

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Tiny Server 1.1 allows remote attackers to read or download arbitrary files via a .. (dot dot) in the URL.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2094

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in WebcamXP 1.06.945 allows remote attackers to inject arbitrary HTML or web script as other users via a URL that contains the script.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2095

    Last Modified: 16 Apr 2026

    Honeyd before 0.8 replies to TCP packets with the SYN and RST flags set, which allows remote attackers to identify IP addresses that are being simulated by Honeyd.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2096

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Mephistoles httpd 0.6.0 final allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the URL.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2097

    Last Modified: 16 Apr 2026

    Multiple scripts on SuSE Linux 9.0 allow local users to overwrite arbitrary files via a symlink attack on (1) /tmp/fvwm-bug created by fvwm-bug, (2) /tmp/wmmenu created by wm-oldmenu2new, (3) /tmp/rates created by x11perfcomp, (4) /tmp/xf86debug.1.log created by xf86debug, (5) /tmp/.winpopup-new created by winpopup-send.sh, or (6) /tmp/initrd created by lvmcreate_initrd.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2101

    Last Modified: 16 Apr 2026

    The sysinfo script in GeoHttpServer allows remote attackers to cause a denial of service (crash) via a long pwd parameter, possibly triggering a buffer overflow.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2102

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web script or HTML via the test parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2104

    Last Modified: 16 Apr 2026

    Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2105

    Last Modified: 16 Apr 2026

    The webacc servlet in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to read arbitrary .htt files via a full pathname in the error parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2106

    Last Modified: 16 Apr 2026

    Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to list directories via a direct request to (1) /com/, (2) /com/novell/, (3) /com/novell/webaccess, or (4) /ns-icons/.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2100

    Last Modified: 16 Apr 2026

    GeoHttpServer, when configured to authenticate users, allows remote attackers to bypass authentication and access unauthorized files via a URL that contains %0a%0a (encoded newlines).

    Published: 31 Dec 2004
    6.8
    Medium

    CVE-2004-2109

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in (1) imagezoom.asp or (2) recommend.asp in Q-Shop allow remote attackers to execute arbitrary script and steal the user session ID via Javascript in a URL.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2110

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in register.php in Phorum before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the hide_email parameter.

    Published: 31 Dec 2004
    8.5
    High

    CVE-2004-2111

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2112

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in BremsServer 1.2.4 allows remote attackers to read arbitrary files via ".." (dot dot) sequences in the URL.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2113

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in BremsServer 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the URL.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2114

    Last Modified: 16 Apr 2026

    Stack-based and heap-based buffer overflows in ProxyNow! 2.75 and earlier allow remote attackers to execute arbitrary code via a GET request with a long ftp:// URL.

    Published: 31 Dec 2004
    6.8
    Medium

    CVE-2004-2115

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request.

    Published: 31 Dec 2004
    5.1
    Medium

    CVE-2004-1455

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Xine-lib-rc5 in xine-lib 1_rc5-r2 and earlier allows remote attackers to execute arbitrary code via crafted playlists that result in a long vcd:// URL.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1456

    Last Modified: 16 Apr 2026

    filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1457

    Last Modified: 16 Apr 2026

    The Virtual Private Network (VPN) capability in Novell Bordermanager 3.8 allows remote attackers to cause a denial of service (ABEND in IKE.NLM) via a malformed IKE packet, as sent by the Striker ISAKMP Protocol Test Suite.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1458

    Last Modified: 16 Apr 2026

    The CSAdmin web administration interface for Cisco Secure Access Control Server (ACS) 3.2(2) build 15 allows remote attackers to cause a denial of service (hang) via a flood of TCP connections to port 2002.

    Published: 31 Dec 2004