4.3
    Medium

    CVE-2004-2564

    Last Modified: 6 Sept 2017

    Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in show.asp and (2) the title parameter in showperf.asp.

    Source:Oliver Karow
    Published:31 Dec 2004
    5.8
    Medium

    CVE-2004-2563

    Last Modified: 22 Jan 2013

    Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and database information, and conduct cross-site scripting (XSS) attacks, via a direct request to tmtrack.dll with modified LoginPage and Template parameters.

    Source:Noam Rathaus
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2562

    Last Modified: 22 Jan 2013

    SQL injection vulnerability in jobedit.asp in Leigh Business Enterprises (LBE) Web Helpdesk before 4.0.0.81 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Noam Rathaus
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2561

    Last Modified: 22 Jan 2013

    Multiple SQL injection vulnerabilities in Internet Software Sciences Web+Center 4.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the ISS_TECH_CENTER_LOGIN cookie in search.asp and (2) one or more cookies in DoCustomerOptions.asp.

    Source:Noam Rathaus
    Published:31 Dec 2004
    2.1
    Low

    CVE-2004-2555

    Last Modified: 16 Jan 2013

    Riverdeep FoolProof Security 3.9.x on Windows 98 and Windows ME uses weak cryptography (arithmetic and XOR operations) to relate the Control password to the Administrator password, which allows local users to calculate the Administrator password if they know the Control password and password recovery key.

    Source:Cyrillium Security
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2551

    Last Modified: 22 Jan 2013

    Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the sys_comment_id parameter in editcommentenduser.asp, (2) the sys_suspend_id parameter in editsuspensionuser.asp, (3) the table parameter in export_data.asp, (4) the sys_analgroup parameter in manageanalgrouppreference.asp, (5) the sys_asset_id parameter in quickinfoassetrequests.asp, (6) the sys_eusername parameter in quickinfoenduserrequests.asp, and the sys_request_id parameter in (7) requestauditlog.asp, (8) requestcommentsenduser.asp, (9) selectrequestapplytemplate.asp, and (10) selectrequestlink.asp, resulting in an ability to create a new HelpBox user account and read, modify, or delete data from the backend database.

    Source:Noam Rathaus
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2549

    Last Modified: 31 Dec 2012

    Nortel Wireless LAN (WLAN) Access Point (AP) 2220, 2221, and 2225 allow remote attackers to cause a denial of service (service crash) via a TCP request with a large string, followed by 8 newline characters, to (1) the Telnet service on TCP port 23 and (2) the HTTP service on TCP port 80, possibly due to a buffer overflow.

    Source:Alex Hernandez
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2548

    Last Modified: 16 Jan 2013

    Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547).

    Source:Donnie Werner
    Published:31 Dec 2004
    2.6
    Low

    CVE-2004-2547

    Last Modified: 16 Jan 2013

    NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message.

    Source:Donnie Werner
    Published:31 Dec 2004
    7.8
    High

    CVE-2004-2534

    Last Modified: 16 Apr 2026

    Fastream NETFile Server 7.1.2 does not properly handle keep-alive connection timeouts and does not close the connection after a HEAD request, which allows remote attackers to perform a denial of service (connection consumption) by sending a large number HTTP HEAD requests.

    Source:karak0rsan
    Published:31 Dec 2004
    10
    Critical

    CVE-2004-2532

    Last Modified: 26 Dec 2016

    Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server using the default administrator account, creating a new user, logging in as that new user, and then using the SITE EXEC command.

    Source:Andrés Acunha
    Published:31 Dec 2004
    2.6
    Low

    CVE-2004-2530

    Last Modified: 27 Jan 2013

    Visual truncation vulnerability in Gadu-Gadu allows remote attackers to spoof the file extension on transmitted files via a filename with a large number of spaces followed by the real extension, which is not displayed in the dialog box.

    Source:Bartosz Kwitkowski
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2528

    Last Modified: 24 Jan 2013

    Cross-site scripting (XSS) vulnerability in sresult.exe in Webcam Watchdog 4.0.1a allows remote attackers to inject arbitrary web script or HTML via the cam parameter.

    Source:dr_insane
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2526

    Last Modified: 24 Jan 2013

    Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter.

    Source:anonymous
    Published:31 Dec 2004
    6.5
    Medium

    CVE-2004-2523

    Last Modified: 16 Apr 2026

    Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in the message argument.

    Source:infamous41md
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2522

    Last Modified: 21 Jan 2013

    Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject arbitrary web script or HTML via the (1) template or (2) language parameter.

    Source:dr_insane
    Published:31 Dec 2004
    4
    Medium

    CVE-2004-2520

    Last Modified: 21 Jan 2013

    POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (application crash) via a large numeric value in the (1) LIST, (2) RETR, or (3) UIDL commands.

    Source:dr_insane
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2519

    Last Modified: 21 Jan 2013

    Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specifiers in the LANGUAGE parameter to (1) index.tmpl and (2) web.tmpl, such as (a) slash "/", (b) backslash "\", (c) dot ".",, (d) dot dot "..", and (e) internal slash "lang//en".

    Source:dr_insane
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2518

    Last Modified: 21 Jan 2013

    Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00") to a URL or (2) an invalid LANGUAGE parameter to web.tmpl, which reveals the full installation path in an error message.

    Source:dr_insane
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2517

    Last Modified: 30 Mar 2016

    myServer 0.7.1 allows remote attackers to cause a denial of service (crash) via a long HTTP POST request in a View=Logon operation to index.html.

    Source:Tom Ferris
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2516

    Last Modified: 5 Mar 2013

    Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET command with a large number of "./" sequences followed by "../" sequences.

    Source:scrap
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2514

    Last Modified: 24 Jan 2013

    Cross-site scripting (XSS) vulnerability in modules/private_messages/index.php in PowerPortal 1.x allows remote attackers to inject arbitrary web script or HTML via the (1) SUBJECT or (2) MESSAGE field.

    Source:vampz
    Published:31 Dec 2004
    10
    Critical

    CVE-2004-2513

    Last Modified: 25 May 2016

    Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via a long SELECT command.

    Source:Reed Arvin
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2512

    Last Modified: 27 Jun 2017

    CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP response splitting attacks to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the PHPSESSID parameter.

    Source:Alexander Antipov
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2511

    Last Modified: 27 Jun 2017

    Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the year, (2) month, and (3) day parameters in calendar.php; (4) the cid and (5) url parameters in index.php; (6) the cid parameter in annoucement.php; (7) the cid parameter in news.php; (8) the cid parameter in contents.php; (9) the q parameter in search.php; and (10) the country parameter in register.php.

    Source:Alexander Antipov
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2510

    Last Modified: 17 Mar 2013

    Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to inject arbitrary web script or HTML via the Cat parameter.

    Source:dw. & ms.
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2509

    Last Modified: 17 Mar 2013

    Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads 6.2.3 and 6.5 allow remote attackers to inject arbitrary web script or HTML via the Cat parameter.

    Source:dw. & ms.
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2508

    Last Modified: 18 Jan 2013

    Cross-site scripting (XSS) vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to inject arbitrary web script or HTML via the next_file parameter.

    Source:scriptX
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2507

    Last Modified: 16 Jan 2013

    Absolute path traversal vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to read arbitrary files via an absolute pathname in the next_file parameter.

    Source:John Doe
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2505

    Last Modified: 10 Jan 2013

    Macromedia ColdFusion MX before 6.1 does not restrict the size of error messages, which allows remote attackers to cause a denial of service (memory consumption and crash) by sending repeated GET or POST requests that trigger error messages that use long strings of data.

    Source:K. K. Mookhey
    Published:31 Dec 2004
    2.1
    Low

    CVE-2004-2502

    Last Modified: 21 Jan 2013

    im-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the imswitcher[PID] temporary file.

    Source:SEKINE Tatsuo
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2501

    Last Modified: 16 Apr 2026

    Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute arbitrary code via (1) a long command string or (2) a long string to the MEIMAP service and then terminating the connection.

    Source:class101
    Published:31 Dec 2004
    7.8
    High

    CVE-2004-2496

    Last Modified: 16 Apr 2026

    The HTTP daemon in OpenText FirstClass 7.1 and 8.0 allows remote attackers to cause a denial of service (service availability loss) via a large number of POST requests to /Search.

    Source:dila
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2494

    Last Modified: 20 Jan 2013

    Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or HTML via the erromsg parameter.

    Source:dr_insane
    Published:31 Dec 2004
    2.6
    Low

    CVE-2004-2491

    Last Modified: 24 Jan 2013

    A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which allows remote attackers to spoof the URL in the address bar via the window.open and location.replace HTML parameters, which facilitates phishing attacks.

    Source:bitlance winter
    Published:31 Dec 2004
    4
    Medium

    CVE-2004-2487

    Last Modified: 4 Jan 2013

    Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) "..", (2) "\..\" (backslash dot dot), or (3) "/../" sequences in (a) RETR (get), (b) NLST (ls), (c) LIST (ls), (d) RNFR, or (e) RNTO FTP commands.

    Source:Ziv Kamir
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2480

    Last Modified: 14 Jan 2013

    Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via "@@" sequences in a URL within Internet Explorer.

    Source:Nuno Costa
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2475

    Last Modified: 6 Mar 2013

    Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol does not cross privilege boundaries, since it is not allowed in the Internet Zone. Thus this might not be a vulnerability.

    Source:ViperSV
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2466

    Last Modified: 27 Oct 2016

    chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was later reported that 2.2 is also affected.

    Source:NetJackal
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2464

    Last Modified: 6 Jan 2013

    Directory traversal vulnerability in ADA Image Server (ImgSvr) 0.4 allows remote attackers to read arbitrary files or list directories via hex-encoded "..//" sequences ("%2e%2e%2f%2f"). NOTE: it was later reported that 0.6.21 and earlier is also affected.

    Source:dr_insane
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2456

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a userinfo action.

    Source:anonymous
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2451

    Last Modified: 9 Jan 2013

    Roger Wilco 1.4.1.6 and earlier, or Roger Wilco Base Station 0.30a or earlier, allows remote attackers to send audio to arbitrary channels, aka the "Voices from the deep" bug.

    Source:Luigi Auriemma
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2449

    Last Modified: 9 Jan 2013

    Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial of service (application crash) via a long, malformed UDP datagram.

    Source:Luigi Auriemma
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2447

    Last Modified: 6 Jan 2013

    Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web script or HTML via the Mailbox parameter to (1) viewmail.tagz, (2) the index script under /user/, (3) members.tagz, (4) general.tagz, (5) advanced.tagz, or (6) list.tagz.

    Source:dr_insane
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2445

    Last Modified: 31 Jan 2017

    Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a .. (dot dot) in the gadget parameter.

    Source:Fernando Quintero
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2444

    Last Modified: 31 Jan 2017

    Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Source:Fernando Quintero
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2443

    Last Modified: 31 Jan 2017

    Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of a null password, which is compared against the logged session variable by the logged_on function in application.php.

    Source:Fernando Quintero
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2442

    Last Modified: 16 Apr 2026

    Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Servers and Gateways 4.61 and earlier, and other products, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on the target system.

    Source:oc192
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2434

    Last Modified: 28 Mar 2016

    Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace), which triggers a null dereference when the user attempts to save the link using "Save As" and Internet Explorer prepares an error message with an attacker-controlled format string.

    Source:anonymous
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2425

    Last Modified: 27 Jan 2013

    Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.

    Source:bashis
    Published:31 Dec 2004