7.2
    High

    CVE-2004-2418

    Last Modified: 16 Apr 2026

    Buffer overflow in SlimFTPd 3.15 and earlier allows local users to execute arbitrary code via a long command, such as (1) CWD, (2) STOR, (3) MKD, and (4) STAT.

    Source:class101
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2416

    Last Modified: 16 Apr 2026

    Buffer overflow in the logging component of CCProxy allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Source:Ruder
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2413

    Last Modified: 8 Jan 2018

    SQL injection vulnerability in VP-ASP Shopping Cart 4.0 through 5.0 allows remote attackers to execute arbitrary SQL commands via the (1) Processed0 and (2) Processed1 parameters in a POST request to shopproductselect.asp.

    Source:IMAN Sharafoddin
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2411

    Last Modified: 18 Jan 2013

    The CleanseMessage function in shop$db.asp for VP-ASP Shopping Cart 4.0 through 5.0 does not sufficiently cleanse inputs, which allows remote attackers to conduct cross-site scripting (XSS) attacks that do not use <script> tags, as demonstrated via javascript in IMG tags to (1) the cat parameter in shopdisplayproducts.asp or (2) the msg parameter in shoperror.asp, and possibly other vectors.

    Source:Thomas Ryan
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2385

    Last Modified: 2 Jan 2013

    EMU Webmail 5.2.7 allows remote attackers to obtain sensitive path information (home directory) via an HTTP request for init.emu.

    Source:dr_insane
    Published:31 Dec 2004
    5.1
    Medium

    CVE-2004-2383

    Last Modified: 31 Dec 2012

    Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from other domains via an HTML document with Javascript that is outside a frameset that includes the target domain, then forcing the frameset to maintain focus. NOTE: the discloser claimed that the vendor does not categorize this as a vulnerability, but it can be used in a spoofing scenario; the discloser provides alternate scenarios. Spoofing scenarios are currently included in CVE.

    Source:iDefense
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2375

    Last Modified: 31 Dec 2012

    Buffer overflow in the POP3 server in 1st Class Mail Server 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an APOP USER command with a long second parameter (digest).

    Source:JeFFOsZ
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2374

    Last Modified: 30 Dec 2012

    BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php, which includes the pathname in the source of the resulting HTML.

    Source:Rafel Ivgi
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2373

    Last Modified: 29 Dec 2012

    The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allow remote attackers to use a shell: URI to exploit other vulnerabilities that involve predictable locations.

    Source:Michael Evanchik
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2371

    Last Modified: 31 Dec 2012

    Multiple Red Storm web-based games, including Ghost Recon 1.4 and earlier, Desert Siege, and The Sum of all Fears 1.1.1.0 and earlier, do not properly check return values from certain functions, which allows remote attackers to cause a denial of service (hang) via packets that contain text strings with incorrect size values.

    Source:Luigi Auriemma
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2368

    Last Modified: 30 Dec 2012

    PHP remote file inclusion vulnerability in header.php in Opt-X 0.7.2 allows remote attackers to execute arbitrary PHP code via the systempath parameter.

    Source:Zone-h Security Team
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2367

    Last Modified: 3 Jan 2013

    The Control Panel applet in WFTPD and WFTPD Pro 3.21 R1 and R2 allows remote authenticated users to cause a denial of service (crash) via a long FTP command.

    Source:Beyond Security
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2366

    Last Modified: 3 Jan 2013

    Buffer overflow in GlobalSCAPE Secure FTP Server 2.0 B03.11.2004.2 allows remote attackers to cause a denial of service (crash) via a SITE command with a long argument.

    Source:storm
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2364

    Last Modified: 14 Dec 2016

    Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs that are automatically executed on behalf of the administrator, as demonstrated using (1) admin/page.php, (2) admin/news.php, (3) admin/user.php, (4) admin/images.php, (5) admin/page.php, or (6) admin/forums.php.

    Source:JeiAr
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2363

    Last Modified: 13 Jan 2013

    Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allows remote attackers to conduct cross-site scripting (XSS) attacks via hex-encoded tags, which bypass the check for literal "<", ">", "(", and ")" characters, as demonstrated using the limit parameter to forums.php and a variety of other vectors.

    Source:JeiAr
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2360

    Last Modified: 9 Jan 2013

    Targem Battle Mages 1.0 allows remote attackers to cause a denial of service (infinite loop) via a UDP packet with incomplete data, which causes the server to enter an infinite loop while waiting to read the rest of the data that is not sent.

    Source:Luigi Auriemma
    Published:31 Dec 2004
    10
    Critical

    CVE-2004-2359

    Last Modified: 30 Dec 2012

    Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started from the systray applet, which allows local users to gain privileges by accessing the Help functionality.

    Source:Ian Vitek
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2355

    Last Modified: 16 Jan 2013

    Cross-site scripting (XSS) vulnerability in Crafty Syntax Live Help (CSLH) before 2.7.4 allows remote attackers to inject arbitrary web script or HTML via the name field of a livehelp or chat session.

    Source:HNK Technology Solutions
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2350

    Last Modified: 2 Jan 2013

    SQL injection vulnerability in search.php for phpBB 1.0 through 2.0.6 allows remote attackers to execute arbitrary SQL and gain privileges via the search_results parameter.

    Source:pokleyzz
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2347

    Last Modified: 24 Dec 2012

    blog.cgi in Leif M. Wright Web Blog 1.1 and 1.1.5 allows remote attackers to execute arbitrary commands via shell metacharacters such as '|' in the file parameter of ViewFile requests.

    Source:ActualMInd
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2344

    Last Modified: 15 Jan 2013

    Unknown vulnerability in the ASN.1/H.323/H.225 stack of VocalTec VGW120 and VGW480 allows remote attackers to cause a denial of service.

    Source:Alexander
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2334

    Last Modified: 2 Jan 2013

    Multiple cross-site scripting (XSS) vulnerabilities in EMU Webmail 5.2.7 allow remote attackers to inject arbitrary web script or HTML via (1) a hex-encoded value to the variable parameter in emumail.fcgi, (2) the folder parameter in emumail.fcgi, or Javascript in the (3) username or (4) password field in the login page.

    Source:dr_insane
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2326

    Last Modified: 2 Jan 2013

    SQL injection vulnerability in IP3 Networks NetAccess Appliance before firmware 3.1.18b13 allows remote attackers to bypass authentication via the (1) login or (2) password. NOTE: this issue was later reported to also affect firmware 4.0.34.

    Source:Syam Yanuar
    Published:31 Dec 2004
    7.2
    High

    CVE-2004-2312

    Last Modified: 3 Jan 2013

    Buffer overflow in GNU make for IBM AIX 4.3.3, when installed setgid, allows local users to gain privileges via a long CC argument.

    Source:watercloud
    Published:31 Dec 2004
    3.6
    Low

    CVE-2004-2311

    Last Modified: 2 Jan 2013

    Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or determine the existence of files via a .. (dot dot) in the new folder dialog.

    Source:dr_insane
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2310

    Last Modified: 3 Jan 2013

    Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbitrary web script or HTML via a Domino command in the Quick Console.

    Source:dr_insane
    Published:31 Dec 2004
    2.1
    Low

    CVE-2004-2309

    Last Modified: 24 Dec 2012

    Directory traversal vulnerability in Crob FTP Server 3.5.1 allows local users to browse outside the FTP root via multiple ../ (dot dot slash) in the DIR command.

    Source:Zero X
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2308

    Last Modified: 2 Jan 2013

    Cross-site scripting (XSS) vulnerability in cPanel 9.1.0 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the dir parameter in dohtaccess.html.

    Source:Fable
    Published:31 Dec 2004
    3.6
    Low

    CVE-2004-2303

    Last Modified: 30 Dec 2012

    MTools Mformat before 3.9.9, when installed setuid root, creates files with world-readable and world-writable permissions, which allows local users to read and overwrite files.

    Source:Sebastian Krahmer
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2299

    Last Modified: 11 Jul 2017

    Buffer overflow in Omnicron OmniHTTPd 3.0a and earlier allows remote attackers to execute arbitrary code via an HTTP GET request with a long Range header.

    Source:CoolICE
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2297

    Last Modified: 17 Jan 2013

    The Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large, out-of-range score parameter.

    Source:Janek Vind
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2295

    Last Modified: 17 Jan 2013

    SQL injection vulnerability in the Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers to execute arbitrary SQL commands via the order parameter.

    Source:Janek Vind
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2294

    Last Modified: 17 Jan 2013

    Canonicalize-before-filter error in the send_review function in the Reviews module for PHP-Nuke 6.0 to 7.3 allows remote attackers to inject arbitrary web script or HTML via hex-encoded XSS sequences in the text parameter, which is checked for dangerous sequences before it is canonicalized, leading to a cross-site scripting (XSS) vulnerability.

    Source:Janek Vind
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2293

    Last Modified: 17 Jan 2013

    Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.0 to 7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) eid parameter or (2) query parameter to the Encyclopedia module, (3) preview_review function in the Reviews module as demonstrated by the url, cover, rlanguage, and hits parameters, or (4) savecomment function in the Reviews module, as demonstrated using the uname parameter. NOTE: the Faq/categories and Encyclopedia/ltr issues are already covered by CVE-2005-1023.

    Source:Janek Vind
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2291

    Last Modified: 16 Apr 2026

    Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script that uses Shell Helper objects and a shortcut (link) to execute the target script.

    Source:Jelmer
    Published:31 Dec 2004
    10
    Critical

    CVE-2004-2289

    Last Modified: 22 Jan 2013

    Microsoft Windows XP Explorer allows local users to execute arbitrary code via a system folder with a Desktop.ini file containing a .ShellClassInfo specifier with a CLSID value that is associated with an executable file.

    Source:Roozbeh Afrasiabi
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2288

    Last Modified: 15 Jan 2013

    Cross-site scripting (XSS) vulnerability in index.php in Jelsoft vBulletin allows remote attackers to spoof parts of a website via the loc parameter.

    Source:p0rk
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2287

    Last Modified: 15 Jan 2013

    Directory traversal vulnerability in explorer.php in DSM Light Web File Browser 2.0 allows remote attackers to read arbitrary files via .. (dot dot) in the wdir parameter.

    Source:Humberto
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2286

    Last Modified: 15 Jan 2013

    Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large multiplier, which may trigger a buffer overflow.

    Source:Matt Murphy
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2280

    Last Modified: 21 Jan 2013

    Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial of service (crash) via unknown vectors related to Java applets, as identified by KSPR62F4KN.

    Source:Jouko Pynnonen
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2277

    Last Modified: 27 Jan 2013

    Buffer overflow in aGSM Half-Life client allows remote Half-Life servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server response.

    Source:Dimetrius
    Published:31 Dec 2004
    10
    Critical

    CVE-2004-2275

    Last Modified: 16 Apr 2026

    i-mall.cgi in I-Mall Commerce allows remote attackers to execute arbitrary commands via shell metacharacters via the p parameter.

    Source:Jerome Athias
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2271

    Last Modified: 12 Apr 2016

    Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Source:class101
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2263

    Last Modified: 12 Jan 2017

    SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements via the vc2 cookie.

    Source:Noam Rathaus
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2262

    Last Modified: 22 Nov 2017

    ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.

    Source:sysbug
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2254

    Last Modified: 14 Jan 2013

    SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified utoken parameter.

    Source:GSS IT
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2253

    Last Modified: 9 Jan 2013

    Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in the page parameter of the show command.

    Source:dr_insane
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2246

    Last Modified: 11 Mar 2013

    Cross-site scripting (XSS) vulnerability in Goollery before 0.04b allows remote attackers to inject arbitrary HTML or web script via the conversation_id parameter to viewpic.php.

    Source:Lostmon
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2245

    Last Modified: 11 Mar 2013

    Cross-site scripting (XSS) vulnerability in Goollery 0.03 allows remote attackers to inject arbitrary HTML or web script via the (1) page parameter to viewalbum.php or (2) btopage parameter to viewpic.php.

    Source:Lostmon
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2242

    Last Modified: 24 Jan 2013

    Cross-site scripting (XSS) vulnerability in search.php in Phorum, possibly 5.0.7 beta and earlier, allows remote attackers to inject arbitrary HTML or web script via the subject parameter.

    Source:vampz
    Published:31 Dec 2004