CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2004-1538

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1539

    Last Modified: 16 Apr 2026

    Halo: Combat Evolved 1.05 and earlier allows remote game servers to cause a denial of service (client crash) via a long value in a game server reply, which triggers a NULL dereference.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1540

    Last Modified: 16 Apr 2026

    ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to access rpFWUpload.html, which allows remote attackers to reset the router configuration file.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1541

    Last Modified: 16 Apr 2026

    SecureCRT 4.0, 4.1, and possibly other versions, allows remote attackers to execute arbitrary commands via a telnet:// URL that uses the /F option to specify a configuration file on a samba share.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1542

    Last Modified: 16 Apr 2026

    Buffer overflow in Soldier of Fortune II 1.03 Gold and earlier allows remote attackers to cause a denial of service (server or client crash) via a long (1) query or (2) reply.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1543

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in viewimg.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1536

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in the ibProArcade module for Invision Power Board (IPB) 1.x and 2.x allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1547

    Last Modified: 16 Apr 2026

    The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to cause a denial of service (application crash) via a long filename, possibly triggering a buffer overflow.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1548

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the file server in ActivePost Standard 3.1 allows remote authenticated users to upload arbitrary files via a .. (dot dot) in the filename.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1549

    Last Modified: 16 Apr 2026

    The conference menu in ActivePost Standard 3.1 sends passwords of password-protected rooms in cleartext, which could allow remote attackers to gain sensitive information by sniffing the network connection.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1550

    Last Modified: 16 Apr 2026

    Motorola Wireless Router WR850G running firmware 4.03 allows remote attackers to bypass authentication, log on as an administrator, and obtain sensitive information by repeatedly making an HTTP request for ver.asp until an administrator logs on.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1554

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitrary PHP code by modifying the chem_absolu parameter to reference a URL on a remote web server that contains the code.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1555

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in BroadBoard Instant ASP Message Board allow remote attackers to run arbitrary SQL commands via the (1) keywords parameter to search.asp, (2) handle parameter to profile.asp, (3) txtUserHandle parameter to reg2.asp or (4) txtUserEmail parameter to forgot.asp.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1546

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a long (1) SAML, SOML, SEND, or MAIL command to the SMTP server or (2) LIST command to the IMAP server.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1561

    Last Modified: 16 Apr 2026

    Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a large number of headers.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1562

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in redir_url.php in w-Agora 4.1.6a allows remote attackers to execute arbitrary SQL commands via the key parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1564

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the thread parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1565

    Last Modified: 16 Apr 2026

    list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1568

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in ParaChat Server 5.5 allows remote attackers to read arbitrary files via a ..%5C (hex-encoded dot dot) in the URL.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1570

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in bBlog 0.7.2 and 0.7.3 allows remote attackers to execute arbitrary SQL commands via the p parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1577

    Last Modified: 16 Apr 2026

    index.php in PHP Links allows remote attackers to gain sensitive information via an invalid show parameter, which reveals the full path in an error message.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1578

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1579

    Last Modified: 16 Apr 2026

    index.php in CubeCart 2.0.1 allows remote attackers to gain sensitive information via an HTTP request with an invalid cat_id parameter, which reveals the full path in a PHP error message.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1580

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1581

    Last Modified: 16 Apr 2026

    BlackBoard 1.5.1 allows remote attackers to gain sensitive information via a direct request to (1) checkdb.inc.php, (2) admin.inc.php or (3) cp.inc.php, which reveals the path in a PHP error message.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-1586

    Last Modified: 16 Apr 2026

    Flash Messaging clients can ignore disconnecting commands such as "shutdown" from the Flash Messaging Server 5.2.0g (rev 1.1.2), which could allow remote attackers to stay connected.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1588

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in GoSmart Message Board allows remote attackers to execute arbitrary SQL code via the (1) QuestionNumber and Category parameters to Forum.asp or (2) Username and Password parameter to Login_Exec.asp.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1589

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in GoSmart Message Board allows remote attackers to execute inject web script or HTML via the (1) Category parameter to Forum.asp or (2) MainMessageID parameter to ReplyToQuestion.asp.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1590

    Last Modified: 16 Apr 2026

    Clientexec allows remote attackers to gain sensitive information via an HTTP request to phpinfo.php, which calls the phpinfo function.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1593

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in render.UserLayoutRootNode.uP in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via the utf parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1723

    Last Modified: 16 Apr 2026

    The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a direct HTTP request, which reveals the installation path in an error message.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1730

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Mantis bugtracker allows remote attackers to inject arbitrary web script or HTML via (1) the return parameter to login_page.php, (2) e-mail field in signup.php, (3) action parameter to login_select_proj_page.php, or (4) hide_status parameter to view_all_set.php.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1736

    Last Modified: 16 Apr 2026

    Cacti 0.8.5a allows remote attackers to gain sensitive information via an HTTP request to (1) auth.php, (2) auth_login.php, (3) auth_changepassword.php, and possibly other php files, which reveal the installation path in a PHP error message.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1738

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in page.php in JShop allows remote attackers to inject arbitrary web script or HTML via the xPage parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1746

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in PHP Code Snippet Library allows remote attackers to inject arbitrary web script or HTML via the (1) cat_select or (2) show parameters.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1747

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in NetworkEverywhere NR041 running firmware 1.2 Release 03 allows remote attackers to inject arbitrary web script or HTML via the DHCP HOSTNAME option.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-1748

    Last Modified: 16 Apr 2026

    NtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid pointers to hook functions such as ZwSetQueryValue.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1750

    Last Modified: 16 Apr 2026

    RealVNC 4.0 and earlier allows remote attackers to cause a denial of service (crash) via a large number of connections to port 5900.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1755

    Last Modified: 16 Apr 2026

    The Web Services fat client for BEA WebLogic Server and Express 7.0 SP4 and earlier, when using 2-way SSL and multiple certificates to connect to the same URL, may use the incorrect identity after the first connection, which could allow users to gain privileges.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-1757

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and Express 8.1, SP1 and earlier, stores the administrator password in cleartext in config.xml, which allows local users to gain privileges.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1762

    Last Modified: 16 Apr 2026

    Unknown vulnerability in F-Secure Anti-Virus (FSAV) 4.52 for Linux before Hotfix 3 allows the Sober.D worm to bypass FASV.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-1763

    Last Modified: 16 Apr 2026

    Buffer overflow in hsrun.exe for HAHTsite Scenario Server 5.1 Patch 06 (build 91) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long project name.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1765

    Last Modified: 16 Apr 2026

    Off-by-one buffer overflow in ModSecurity (mod_security) 1.7.4 for Apache 2.x, when SecFilterScanPost is enabled, allows remote attackers to execute arbitrary code via crafted POST requests.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-1767

    Last Modified: 16 Apr 2026

    The kernel in Solaris 2.6, 7, 8, and 9 allows local users to gain privileges by loading arbitrary loadable kernel modules (LKM), possibly involving the modload function.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1779

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in board.php for ThWboard before beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the lastvisited parameter.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-1780

    Last Modified: 16 Apr 2026

    Info Touch Surfnet kiosk allows local users to deposit extra time into Internet kiosk accounts via repeated authentication attempts.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-1781

    Last Modified: 16 Apr 2026

    Info Touch Surfnet kiosk allows local users to crash Surfnet and access the underlying operating system via the CMD_CREDITCARD_CHARGE command.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1782

    Last Modified: 16 Apr 2026

    athenareg.php in Athena Web Registration allows remote attackers to execute arbitrary commands via shell metacharacters in the pass parameter.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1783

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Net2Soft Flash FTP Server 1.0 allows remote attackers to read and create arbitrary files via a /.. (slash dot dot).

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1403

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in GNUBoard 3.39 and earlier allows remote attackers to execute arbitrary PHP code by modifying the doc parameter to reference a URL on a remote web server that contains the code.

    Published: 31 Dec 2004