CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2004-0353

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in auth_ident() function in auth.c for GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to gain privileges via a long string.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0236

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in login.asp in thePHOTOtool allows remote attackers to gain unauthorized access via the password field.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0240

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in X-Cart 3.4.3 allows remote attackers to view arbitrary files via a .. (dot dot) in the shop_closed_file argument to auth.php.

    Published: 18 Mar 2004
    4.7
    Medium

    CVE-2004-0244

    Last Modified: 16 Apr 2026

    Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allow local users to cause a denial of service (hang or reset) by sending a layer 2 frame packet that encapsulates a layer 3 packet, but has inconsistent length values with that packet.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0246

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in (1) fonctions.lib.php, (2) derniers_commentaires.php, and (3) admin.php in Les Commentaires 2.0 allow remote attackers to execute arbitrary PHP code via the rep parameter.

    Published: 18 Mar 2004
    7.6
    High

    CVE-2004-0258

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in RealOne Player, RealOne Player 2.0, RealOne Enterprise Desktop, and RealPlayer Enterprise allow remote attackers to execute arbitrary code via malformed (1) .RP, (2) .RT, (3) .RAM, (4) .RPM or (5) .SMIL files.

    Published: 18 Mar 2004
    9.3
    Critical

    CVE-2004-0259

    Last Modified: 16 Apr 2026

    The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.

    Published: 18 Mar 2004
    2.1
    Low

    CVE-2004-0267

    Last Modified: 16 Apr 2026

    The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to overwrite arbitrary files via a symlink attack on files in /tmp.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0268

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP server, or (2) a long dir command to the telnet server.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0275

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0278

    Last Modified: 16 Apr 2026

    Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet that contains less data than specified, which causes Ratbag to repeatedly check the socket for more data.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0281

    Last Modified: 16 Apr 2026

    Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP request for "WEB-INF..", which is equivalent to "WEB-INF" in Windows.

    Published: 18 Mar 2004
    9.8
    Critical

    CVE-2004-0285

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0287

    Last Modified: 16 Apr 2026

    Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0296

    Last Modified: 16 Apr 2026

    TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a TsFtpSrv.exe to exit with an exception by opening and immediately closing a connection.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0300

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0308

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connection to the VxWorks shell.

    Published: 18 Mar 2004
    6.4
    Medium

    CVE-2004-0312

    Last Modified: 16 Apr 2026

    Linksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/write communtiy strings via a query for OID 1.3.6.1.4.1.3955.2.1.13.1.2.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0316

    Last Modified: 16 Apr 2026

    Buffer overflow in Avirt Soho 4.3 allows remote attackers to cause a denial of service (crash) via (1) a large GET request to port 1080 or (2) a large GET request of % characters to port 8080.

    Published: 18 Mar 2004
    6.8
    Medium

    CVE-2004-0319

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the font tag in ezBoard 7.3u allows remote attackers to execute arbitrary script as other users, as demonstrated using the background:url in a (1) font color or (2) font face argument.

    Published: 18 Mar 2004
    2.1
    Low

    CVE-2004-0325

    Last Modified: 16 Apr 2026

    TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (CPU consumption) via "//../" arguments to (1) mkd, (2) xmkd, (3) dele, (4) size, (5) retr, (6) stor, (7) appe, (8) rnfr, (9) rnto, (10) rmd, or (11) xrmd, as demonstrated using "//../qwerty".

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0327

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequences in the clang parameter.

    Published: 18 Mar 2004
    7.2
    High

    CVE-2004-0328

    Last Modified: 16 Apr 2026

    Gigabyte Gn-B46B 2.4Ghz wireless broadband router firmware 1.003.00 allows local users on the same local network as the router to bypass authentication by using a copy of the router's html menu on a separate system.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0330

    Last Modified: 16 Apr 2026

    Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0333

    Last Modified: 16 Apr 2026

    Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0334

    Last Modified: 16 Apr 2026

    InnoMedia VideoPhone allows remote attackers to bypass Basic Authorization via an HTTP request to (1) videophone_admindetail.asp, (2) videophone_syscfg.asp, (3) videophone_upgrade.asp, or (4) videophone_sysctrl.asp that contains a trailing / (slash). NOTE: the original report mentioned AXIS 2100 Network Camera, but this was likely a cut-and-paste error.

    Published: 18 Mar 2004
    5.5
    Medium

    CVE-2004-0342

    Last Modified: 16 Apr 2026

    WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0343

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0354

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code via format string specifiers in strings passed to (1) the info function in log.c, (2) the anubis_error function in errs.c, or (3) the ssl_error function in ssl.c.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0357

    Last Modified: 16 Apr 2026

    Stack-based buffer overflows in SL Mail Pro 2.0.9 allow remote attackers to execute arbitrary code via (1) user.dll, (2) loadpageadmin.dll or (3) loadpageuser.dll.

    Published: 18 Mar 2004
    6.8
    Medium

    CVE-2004-0358

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed parameter during the newslogo_upload action in admin.php.

    Published: 18 Mar 2004
    4.3
    Medium

    CVE-2004-1829

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in error.php in Gijza.net Error Manager 2.1 for PHP-Nuke 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pagetitle or (2) error parameters, or (3) certain parameters in the error log.

    Published: 18 Mar 2004
    6.8
    Medium

    CVE-2004-0301

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-1830

    Last Modified: 16 Apr 2026

    error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a PHP error message.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0241

    Last Modified: 16 Apr 2026

    X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0242

    Last Modified: 16 Apr 2026

    X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0243

    Last Modified: 16 Apr 2026

    AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0245

    Last Modified: 16 Apr 2026

    Web Crossing 4.x and 5.x allows remote attackers to cause a denial of service (crash) by sending a HTTP POST request with a large or negative Content-Length, which causes an integer divide-by-zero.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0250

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat parameter in showcat.php.

    Published: 18 Mar 2004
    6.8
    Medium

    CVE-2004-0251

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in rxgoogle.cgi allows remote attackers to execute arbitrary script as other users via the query parameter.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0252

    Last Modified: 16 Apr 2026

    TYPSoft FTP Server 1.10 allows remote attackers to cause a denial of service (CPU consumption) via an empty USER name.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0253

    Last Modified: 16 Apr 2026

    IBM Cloudscape 5.1 running jdk 1.4.2_03 allows remote attackers to execute arbitrary programs or cause a denial of service via certain SQL code, possibly due to a SQL injection vulnerability.

    Published: 18 Mar 2004
    6.8
    Medium

    CVE-2004-0254

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Discuz! Board 2.x and 3.x allows remote attackers to execute arbitrary script as other users via an img tag.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0255

    Last Modified: 16 Apr 2026

    Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0249

    Last Modified: 16 Apr 2026

    PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another userID.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0260

    Last Modified: 16 Apr 2026

    The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains a backdoor that allows remote attackers to delete arbitrary files via an email address that starts with |||.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0264

    Last Modified: 16 Apr 2026

    palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue.

    Published: 18 Mar 2004
    6.8
    Medium

    CVE-2004-0271

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4) the image name of an Avatar in the register form.

    Published: 18 Mar 2004
    7.5
    High

    CVE-2004-0272

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0277

    Last Modified: 16 Apr 2026

    Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username.

    Published: 18 Mar 2004