7.5
    High

    CVE-2004-2221

    Last Modified: 16 Apr 2026

    Buffer overflow in SoftCart.exe in Mercantec SoftCart 4.00b allows remote attackers to execute arbitrary code via a long parameter in an HTTP GET request.

    Source:skape
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2218

    Last Modified: 30 Mar 2016

    SQL injection vulnerability in pmwh.php in PHPMyWebHosting 0.3.4 and earlier allows remote attackers to modify SQL statements via the password parameter.

    Source:Noam Rathaus
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2202

    Last Modified: 9 Mar 2013

    Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server's underlying database via the (1) cat_id or (2) sub_id parameters in adDetail.asp, or (2) the password parameter in the login form.

    Source:Soroosh Dalili
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2201

    Last Modified: 11 Oct 2017

    SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDetail.asp, or (3) password parameter in the login form.

    Source:Soroosh Dalili
    Published:31 Dec 2004
    6.4
    Medium

    CVE-2004-2198

    Last Modified: 11 Oct 2017

    account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId parameter on the "My Account" page.

    Source:Soroosh Dalili
    Published:31 Dec 2004
    6.4
    Medium

    CVE-2004-2184

    Last Modified: 10 Mar 2013

    Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write arbitrary files via "../" or "..\" sequences in commands such as (1) dir or (2) put.

    Source:Luigi Auriemma
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2181

    Last Modified: 22 May 2013

    Multiple SQL injection vulnerabilities in WowBB Forum 1.61 allow remote attackers to execute arbitrary SQL commands via the (1) sort_by or (2) page parameters to view_user.php, or the (3) forum_id parameter to view_topic.php. NOTE: the sort_by vector was later reported to be present in WowBB 1.65.

    Source:Megasky
    Published:31 Dec 2004
    4.6
    Medium

    CVE-2004-2176

    Last Modified: 10 Mar 2013

    The Internet Connection Firewall (ICF) in Microsoft Windows XP SP2 is configured by default to trust sessmgr.exe, which allows local users to use sessmgr.exe to create a local listening port that bypasses the ICF access controls.

    Source:americanidiot
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2175

    Last Modified: 2 Jan 2017

    Multiple SQL injection vulnerabilities in ReviewPost PHP Pro allow remote attackers to execute arbitrary SQL commands via the (1) product parameter to showproduct.php or (2) cat parameter to showcat.php.

    Source:G00db0y
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2172

    Last Modified: 27 Dec 2012

    EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via a chosen plaintext attack.

    Source:Nick Gudov
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2171

    Last Modified: 23 Dec 2012

    Cross-site scripting (XSS) vulnerability in Cherokee before 0.4.8 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting error page.

    Source:César Fernández
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2170

    Last Modified: 24 Dec 2012

    Directory traversal vulnerability in sample_showcode.html in Caravan 2.00/03d and earlier allows remote attackers to read arbitrary files via the fname parameter.

    Source:dr_insane
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2167

    Last Modified: 15 Nov 2017

    Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary code via (1) the expandmacro function, and possibly (2) Environments and (3) TranslateCommand.

    Source:D. J. Bernstein
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2162

    Last Modified: 6 Mar 2013

    Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the search field of the Address Module or (2) the t parameter to app_new.php.

    Source:Joxean Koret
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2161

    Last Modified: 6 Mar 2013

    SQL injection vulnerability in file_overview.php in TUTOS 1.1 allows remote attackers to execute arbitrary SQL commands via the link_id parameter.

    Source:Joxean Koret
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2158

    Last Modified: 31 Oct 2016

    SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter to (1) exit.php or (2) comment.php.

    Source:aCiDBiTS
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2151

    Last Modified: 16 Apr 2026

    Chatman 1.1.1 RC1 and earlier allows remote attackers to cause a denial of service (memory consumption or application crash) via a very large data size.

    Source:Luigi Auriemma
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2143

    Last Modified: 6 Mar 2013

    SQL injection vulnerability in the ReMOSitory Server add-on module to Mambo Portal 4.5.1 (1.09) and earlier allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in the com_remository option.

    Source:khoaimi
    Published:31 Dec 2004
    2.1
    Low

    CVE-2004-2135

    Last Modified: 28 May 2013

    cryptoloop on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked files to be detected without decryption.

    Source:Markku-Juhani O. Saarinen
    Published:26 May 2004
    4.6
    Medium

    CVE-2004-2134

    Last Modified: 23 Dec 2012

    Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the passwords.

    Source:Pete Finnigan
    Published:28 Jan 2004
    5
    Medium

    CVE-2004-2132

    Last Modified: 23 Dec 2012

    Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter.

    Source:Zone-h Security Team
    Published:29 Jan 2004
    7.2
    High

    CVE-2004-2131

    Last Modified: 23 Dec 2012

    Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment variable.

    Source:pask
    Published:27 Jan 2004
    4.3
    Medium

    CVE-2004-2130

    Last Modified: 18 Dec 2012

    Multiple cross-site scripting (XSS) vulnerabilities in privmsg.php in phpBB 2.0.6 allow remote attackers to execute arbitrary script or HTML via the (1) folder or (2) mode variables.

    Source:Ben Drysdale
    Published:23 Dec 2004
    5
    Medium

    CVE-2004-2129

    Last Modified: 11 Jul 2017

    SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow.

    Source:Donato Ferrante
    Published:31 Dec 2004
    6.8
    Medium

    CVE-2004-2128

    Last Modified: 27 Sept 2016

    Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as other users via the query string to ISAPISkeleton.dll.

    Source:Oliver Karow
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2127

    Last Modified: 23 Dec 2012

    Directory traversal vulnerability in Web Blog 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file variable.

    Source:Zone-h Security Team
    Published:20 Jan 2004
    5
    Medium

    CVE-2004-2124

    Last Modified: 23 Dec 2012

    The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412.

    Source:Bharat Mediratta
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2121

    Last Modified: 23 Dec 2012

    Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download arbitrary files via (1) multi-dot "......" sequences, or (2) "%5c%2e%2e" (encoded "\..") sequences, in the URL.

    Source:Rafel Ivgi The-Insider
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2120

    Last Modified: 23 Dec 2012

    Reptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET requests without the HTTP version.

    Source:Donato Ferrante
    Published:23 Jan 2004
    4.3
    Medium

    CVE-2004-2119

    Last Modified: 23 Dec 2012

    Cross-site scripting (XSS) vulnerability in Tiny Server 1.1 allows remote attackers to inject arbitrary web script or HTML via the URL.

    Source:Donato Ferrante
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2117

    Last Modified: 23 Dec 2012

    Tiny Server 1.1 allows remote attackers to cause a denial of service (crash) via malformed HTTP requests such as (1) a GET request without the HTTP version (HTTP/1.1), or (2) a request without GET or the HTTP version.

    Source:Donato Ferrante
    Published:24 Jan 2004
    5
    Medium

    CVE-2004-2116

    Last Modified: 23 Dec 2012

    Directory traversal vulnerability in Tiny Server 1.1 allows remote attackers to read or download arbitrary files via a .. (dot dot) in the URL.

    Source:Donato Ferrante
    Published:31 Dec 2004
    6.8
    Medium

    CVE-2004-2115

    Last Modified: 23 Dec 2012

    Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request.

    Source:Rafel Ivgi The-Insider
    Published:31 Dec 2004
    10
    Critical

    CVE-2004-2114

    Last Modified: 23 Dec 2012

    Stack-based and heap-based buffer overflows in ProxyNow! 2.75 and earlier allow remote attackers to execute arbitrary code via a GET request with a long ftp:// URL.

    Source:Peter Winter-Smith
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2113

    Last Modified: 6 Sept 2016

    Cross-site scripting (XSS) vulnerability in BremsServer 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the URL.

    Source:Donato Ferrante
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2112

    Last Modified: 6 Sept 2016

    Directory traversal vulnerability in BremsServer 1.2.4 allows remote attackers to read arbitrary files via ".." (dot dot) sequences in the URL.

    Source:Donato Ferrante
    Published:31 Dec 2004
    8.5
    High

    CVE-2004-2111

    Last Modified: 22 Nov 2017

    Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename.

    Source:lion
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2107

    Last Modified: 23 Dec 2012

    Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote attackers to use the finjan-parameter-type header to (1) restart the service, (2) use the getlastmsg command to view log information, or (3) use the online command to force a policy update from the database server.

    Source:David Byrne
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2104

    Last Modified: 23 Dec 2012

    Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm.

    Source:Rafel Ivgi The-Insider
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2102

    Last Modified: 23 Dec 2012

    Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web script or HTML via the test parameter.

    Source:Rafel Ivgi The-Insider
    Published:31 Dec 2004
    5.1
    Medium

    CVE-2004-2099

    Last Modified: 16 Apr 2026

    Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary code via long (1) gamename, (2) gamever, (3) hostname, (4) gametype, (5) mapname or (6) gamemode commands.

    Source:Luigi Auriemma
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2096

    Last Modified: 20 Dec 2012

    Cross-site scripting (XSS) vulnerability in Mephistoles httpd 0.6.0 final allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the URL.

    Source:Donato Ferrante
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2094

    Last Modified: 20 Dec 2012

    Cross-site scripting (XSS) vulnerability in WebcamXP 1.06.945 allows remote attackers to inject arbitrary HTML or web script as other users via a URL that contains the script.

    Source:Rafel Ivgi The-Insider
    Published:31 Dec 2004
    4.6
    Medium

    CVE-2004-2093

    Last Modified: 15 Apr 2017

    Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment variable. NOTE: since rsync is not setuid, this issue does not provide any additional privileges beyond those that are already available to the user. Therefore this issue may be REJECTED in the future.

    Source:Abhisek Datta
    Published:9 Feb 2004
    5
    Medium

    CVE-2004-2090

    Last Modified: 25 Dec 2012

    Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.

    Source:Jelmer
    Published:7 Feb 2004
    5
    Medium

    CVE-2004-2086

    Last Modified: 6 Sept 2017

    Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a long query parameter.

    Published:6 Feb 2004
    5
    Medium

    CVE-2004-2082

    Last Modified: 27 Dec 2012

    The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsystem.exe crash) via a GET request wit a large number of leading "/" (slash) characters.

    Source:intuit e.b.
    Published:13 Feb 2004
    5
    Medium

    CVE-2004-2081

    Last Modified: 27 Dec 2012

    The samiftp.dll library in Sami FTP Server 1.1.3 allows local users to cause a denial of service (pmsystem.exe crash) by issuing (1) a CD command with a tilde (~) character or dot dot (/../) or (2) a GET command for an unavailable file.

    Source:intuit e.b.
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2078

    Last Modified: 25 Dec 2012

    Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss of logged events) via a long request to TCP port 80, possibly triggering a buffer overflow.

    Source:Bruno Morisson
    Published:9 Feb 2004
    5
    Medium

    CVE-2004-2077

    Last Modified: 25 Dec 2012

    Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values or incorrect size fields.

    Source:scrap
    Published:8 Feb 2004