Unknown

    CVE-2004-6768

    https://github.com/yougboiz/Metasploit-CVE-2004-6768

    9.8
    Critical

    CVE-2004-2761

    Last Modified: 24 Apr 2013

    The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509 certificate.

    Source:Dan Kaminsky
    Published:30 Dec 2008
    4.3
    Medium

    CVE-2004-2756

    Last Modified: 23 Dec 2012

    Cross-site scripting (XSS) vulnerability in viewtopic.php in Xoops 2.x, possibly 2 through 2.0.5, allows remote attackers to inject arbitrary web script or HTML via the (1) forum and (2) topic_id parameters.

    Source:Ben Drysdale
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2754

    Last Modified: 20 Dec 2012

    SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the ID_MEMBER parameter to the (1) recentTopics and (2) welcome functions.

    Source:BaCkSpAcE
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2750

    Last Modified: 24 Dec 2012

    Directory traversal vulnerability in browser.php in JBrowser 1.0 through 2.1 allows remote attackers to read arbitrary files via the directory parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Himeur Nourredine
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2749

    Last Modified: 20 Dec 2012

    Directory traversal vulnerability in wra/public/wralogin in 2Wire Gateway, possibly as used in HomePortal and other product lines, allows remote attackers to read arbitrary files via a .. (dot dot) in the return parameter. NOTE: this issue was reported as XSS, but this might be a terminology error.

    Source:Rafel Ivgi The-Insider
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2748

    Last Modified: 20 Dec 2012

    viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid profileid parameter, which leaks the pathname in an error message.

    Source:Oliver Karow
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2746

    Last Modified: 20 Dec 2012

    SQL injection vulnerability in adminlogin.asp in XTREME ASP Photo Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Source:posidron
    Published:31 Dec 2004
    7.8
    High

    CVE-2004-2745

    Last Modified: 20 Dec 2012

    Directory traversal vulnerability in Anteco Visual Technologies OwnServer 1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.

    Source:Rafel Ivgi The-Insider
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2737

    Last Modified: 22 Jan 2013

    SQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary SQL commands via the where parameter.

    Source:Noam Rathaus
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2736

    Last Modified: 22 Jan 2013

    Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cookie.

    Source:Noam Rathaus
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2732

    Last Modified: 10 Mar 2013

    nbmember.cgi in Netbilling 2.0 allows remote attackers to obtain sensitive information via the cmd=test option, which can be leveraged to determine the access key.

    Source:ls
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2727

    Last Modified: 14 Jan 2013

    Buffer overflow in MEHTTPS (HTTPMail) of MailEnable Professional 1.5 through 1.7 allows remote attackers to cause a denial of service (application crash) via a long HTTP GET request.

    Source:Behrang Fouladi
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2725

    Last Modified: 12 Mar 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Aztek Forum 4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter in (a) search.php, (2) the email parameter in (b) subscribe.php, and (3) the return and (4) title parameters in (c) forum_2.php.

    Source:benji lemien
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2720

    Last Modified: 10 Feb 2016

    Cross-site scripting (XSS) vulnerability in register.asp in Snitz Forums 2000 3.4.04 and earlier allows remote attackers to inject arbitrary web script or HTML via javascript events in the Email parameter.

    Source:anonymous
    Published:31 Dec 2004
    6.8
    Medium

    CVE-2004-2719

    Last Modified: 16 Mar 2016

    Buffer overflow in the UrlToLocal function in PunyLib.dll of Foxmail 5.0.300 allows remote attackers to execute arbitrary code via a mail message with a long From field, a different issue than CVE-2005-0339.

    Source:xfocus
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2718

    Last Modified: 19 Apr 2016

    PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database passwords via a direct request.

    Source:sysbug
    Published:31 Dec 2004
    2.6
    Low

    CVE-2004-2717

    Last Modified: 19 Jan 2013

    Multiple directory traversal vulnerabilities in admin.php3 in PHPMyChat 0.14.5 allow remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the (1) sheet and (2) What parameters.

    Source:HEX
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2716

    Last Modified: 19 Jan 2013

    Multiple SQL injection vulnerabilities in usersL.php3 in PHPMyChat 0.14.5 allow remote attackers to execute arbitrary SQL commands via the (1) sortBy, (2) sortOrder, (3) startReg, (4) U, (5) LastCheck , and (6) R parameters.

    Source:HEX
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2715

    Last Modified: 19 Jan 2013

    edituser.php3 in PHPMyChat 0.14.5 allow remote attackers to bypass authentication and gain administrative privileges by setting the do_not_login parameter to false.

    Source:HEX
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2702

    Last Modified: 27 Jan 2013

    Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter. NOTE: this might be the same vector as CVE-2006-6451.

    Source:sourvivor
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2701

    Last Modified: 17 Jan 2013

    Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter.

    Source:Thomas Ryan
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2699

    Last Modified: 17 Jan 2013

    deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter.

    Source:Thomas Ryan
    Published:31 Dec 2004
    6.9
    Medium

    CVE-2004-2698

    Last Modified: 27 Jan 2013

    Race condition in IMWheel 1.0.0pre11 and earlier, when running with the -k option, allows local users to cause a denial of service (IMWheel crash) and possibly modify arbitrary files via a symlink attack on the imwheel.pid file.

    Source:I)ruid
    Published:31 Dec 2004
    6.9
    Medium

    CVE-2004-2697

    Last Modified: 4 Jan 2013

    The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a command line argument (log file). NOTE: this might be related to CVE-2006-5002.

    Source:watercloud
    Published:31 Dec 2004
    9.3
    Critical

    CVE-2004-2692

    Last Modified: 2 Dec 2016

    The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass restrictions and execute arbitrary commands via a backtick operator, which is not handled using the php_escape_shell_cmd function.

    Source:VeNoMouS
    Published:31 Dec 2004
    9.3
    Critical

    CVE-2004-2687

    Last Modified: 1 Apr 2017

    distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.

    Source:H D Moore
    Published:31 Dec 2004
    7.2
    High

    CVE-2004-2686

    Last Modified: 9 Jan 2013

    Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure.

    Source:Sinan Eren
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2685

    Last Modified: 7 Mar 2019

    Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long address in a ping (p) command to the Telnet proxy service, a different vector than CVE-2004-2416.

    Source:KaGra
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2677

    Last Modified: 5 Dec 2016

    Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format specifiers in the (1) clientRcptTo array, and the (2) Received and (3) messageID variables, possibly involving HELO and hostname arguments.

    Source:Carlos Barros
    Published:31 Dec 2004
    6.8
    Medium

    CVE-2004-2675

    Last Modified: 31 Dec 2012

    ArGoSoft FTP Server before 1.4.1.6 allows remote authenticated users to cause a denial of service (crash) via a SITE PASS command with a long password parameter, which causes the database to be corrupted.

    Source:Beyond Security
    Published:31 Dec 2004
    6.8
    Medium

    CVE-2004-2670

    Last Modified: 24 Jan 2013

    Multiple cross-site scripting (XSS) vulnerabilities in mod.php in eNdonesia 8.3 allow remote attackers to inject arbitrary web script or HTML via (1) the mod parameter in a viewcat operation or (2) the query parameter in a search operation in the publisher module.

    Source:Ahmad Muammar
    Published:31 Dec 2004
    7.8
    High

    CVE-2004-2652

    Last Modified: 28 Apr 2013

    The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null dereference.

    Source:Marcin Zgorecki
    Published:31 Dec 2004
    5.8
    Medium

    CVE-2004-2649

    Last Modified: 14 Jan 2013

    Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of characters (e.g. spaces coded as "&#32") in the middle of the URL.

    Source:Brett Glass
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2647

    Last Modified: 24 Jan 2013

    Free Web Chat 2.0 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections from the same user.

    Source:Donato Ferrante
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2646

    Last Modified: 24 Jan 2013

    The addUser function in UserManager.java in Free Web Chat 2.0 allows remote attackers to cause a denial of service (uncaught NullPointerException) via unknown attack vectors that cause the usrName variable to be null.

    Source:Donato Ferrante
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2640

    Last Modified: 10 Mar 2013

    Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequences or (2) absolute paths to the template parameter.

    Source:anonymous
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2636

    Last Modified: 16 Jan 2013

    TinyWeb 1.9 allows remote attackers to read source code of scripts via "/./" in the URL.

    Source:Ziv Kamir
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2631

    Last Modified: 28 Mar 2016

    Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name.

    Source:Nasir Simbolon
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2628

    Last Modified: 24 Jan 2013

    Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such as "C:").

    Source:CoolICE
    Published:31 Dec 2004
    3.7
    Low

    CVE-2004-2626

    Last Modified: 13 Jan 2013

    GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SMS messages by overlaying a confirmation message with a malicious message.

    Source:FtR
    Published:31 Dec 2004
    5.1
    Medium

    CVE-2004-2625

    Last Modified: 21 Jan 2013

    Cross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTML via Javascript in an attribute of an IMG tag.

    Source:DarkBicho
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2618

    Last Modified: 1 Jan 2013

    Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the URI, directly after the initial '/' (slash).

    Source:Donato Ferrante
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2617

    Last Modified: 1 Jan 2013

    Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the web root via a .. (dot dot) directly after the initial '/' (slash) in the URI.

    Source:Donato Ferrante
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2614

    Last Modified: 14 Jan 2013

    Buffer overflow in MyWeb 3.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.

    Source:badpack3t
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2592

    Last Modified: 27 Oct 2017

    Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a modified client that asks the server to send data stored at a negative array offset, which is not handled when processing Configstrings and Baselines.

    Source:Richard Stanway
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2574

    Last Modified: 27 Apr 2013

    Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary web script or HTML via the date parameter in a calendar.uicalendar.planner menuaction.

    Source:Cedric Cochin
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2573

    Last Modified: 27 Apr 2013

    PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute arbitrary PHP code via an external URL in the appdir parameter.

    Source:Cedric Cochin
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2566

    Last Modified: 19 Jan 2018

    Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat, and (4) LiveFocusGroup, allow remote attackers to inject arbitrary web script or HTML via the q parameter in (a) search.jsp, (b) findclub!execute.jspa, and (c) search!execute.jspa.

    Source:GulfTech Security
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2565

    Last Modified: 6 Sept 2017

    Multiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, when the administrative IP address restrictions have been modified from the default, allow remote authenticated users to read arbitrary files via (1) a "..\" (dot dot backslash) in the file parameter to showini.asp, or (2) an absolute path with drive letter in the log parameter to showlog.asp.

    Source:Oliver Karow
    Published:31 Dec 2004