4.3
    Medium

    CVE-2004-2076

    Last Modified: 27 Dec 2012

    Cross-site scripting (XSS) vulnerability in search.php for Jelsoft vBulletin 3.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Source:Rafel Ivgi The-Insider
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2074

    Last Modified: 7 Nov 2016

    Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands.

    Source:Metasploit
    Published:31 Dec 2004
    7.2
    High

    CVE-2004-2073

    Last Modified: 6 Sept 2016

    Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server via a modified chroot-again exploit using the chmod command.

    Source:Markus Mueller
    Published:6 Feb 2004
    6.8
    Medium

    CVE-2004-2072

    Last Modified: 25 Dec 2012

    Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter.

    Source:David Sopas Ferreira
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2071

    Last Modified: 18 Apr 2015

    Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authentication in the web interface via an HTTP GET request with two slashes ("//") after the server name.

    Source:Ziv Kamir
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2067

    Last Modified: 31 Jan 2017

    SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.

    Source:Fernando Quintero
    Published:29 Jul 2004
    4.3
    Medium

    CVE-2004-2064

    Last Modified: 24 Jan 2013

    Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web script via the (1) Email or (2) Website fields.

    Source:Joseph Moniz
    Published:29 Jul 2004
    4.3
    Medium

    CVE-2004-2063

    Last Modified: 24 Jan 2013

    Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inject arbitrary HTML or web script via the feedback parameter.

    Source:Josh Gilmour
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2062

    Last Modified: 24 Jan 2013

    SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2) parent_id, or (3) mode parameters.

    Source:Josh Gilmour
    Published:31 Dec 2004
    9.8
    Critical

    CVE-2004-2061

    Last Modified: 27 Oct 2016

    RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.

    Source:Phil Robinson
    Published:27 Jul 2004
    5
    Medium

    CVE-2004-2060

    Last Modified: 23 Jan 2013

    ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.

    Source:Ferruh Mavituna
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2059

    Last Modified: 23 Jan 2013

    Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SearchFor parameter in [TABLE-NAME]_search.asp, (2) SQL parameter in [TABLE-NAME]_edit.asp, (3) SearchFor parameter in [TABLE]_list.asp, or (4) SQL parameter in export.asp.

    Source:Ferruh Mavituna
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2053

    Last Modified: 23 Jan 2013

    PHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitrary PHP code via the site parameter.

    Source:Francisco Alisson
    Published:24 Jul 2004
    5
    Medium

    CVE-2004-2047

    Last Modified: 22 Jan 2013

    Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the pathext parameter.

    Published:23 Jul 2004
    5
    Medium

    CVE-2004-2045

    Last Modified: 16 Apr 2026

    The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of service (device reboot) via an HTTP request with a long username.

    Source:Seth Alan Woolley
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2044

    Last Modified: 16 Jan 2013

    PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER['PHP_SELF'] to identify the calling script, which allows remote attackers to directly access scripts, obtain path information via a PHP error message, and possibly gain access, as demonstrated using an HTTP request that contains the "admin.php" string.

    Source:Squid
    Published:1 Jun 2004
    5
    Medium

    CVE-2004-2043

    Last Modified: 16 Nov 2017

    Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows remote attackers to cause a denial of service (crash) via a long database name, as demonstrated using the gsec command.

    Source:Aviram Jenik
    Published:1 May 2004
    4.3
    Medium

    CVE-2004-2040

    Last Modified: 15 Jan 2013

    Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 parameter to clock_menu.php, (2) "email article to a friend" field, (3) "submit news" field, or (4) avmsg parameter to usersettings.php.

    Source:Janek Vind
    Published:29 May 2004
    4.3
    Medium

    CVE-2004-2038

    Last Modified: 15 Jan 2013

    Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) before LDU 700 allows remote attackers to inject arbitrary web script or HTML via a BBcode img tag in (1) functions.php, (2) header.php or (3) auth.inc.php.

    Source:Tim De Gier
    Published:29 May 2004
    7.5
    High

    CVE-2004-2037

    Last Modified: 15 Jan 2013

    Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long CWD command, as demonstrated in one example by using the "cd" command in an interactive FTP client.

    Source:storm
    Published:24 Mar 2004
    7.5
    High

    CVE-2004-2036

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject arbitrary SQL commands via the id parameter.

    Source:Maciek Wierciski
    Published:28 May 2004
    5
    Medium

    CVE-2004-2035

    Last Modified: 19 Dec 2018

    MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of trailing CRLF sequences.

    Source:Donato Ferrante
    Published:26 May 2004
    5
    Medium

    CVE-2004-2033

    Last Modified: 15 Jan 2013

    Orenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.

    Source:badpack3t
    Published:26 May 2004
    7.5
    High

    CVE-2004-2032

    Last Modified: 15 Jan 2013

    Netgear RP114 allows remote attackers to bypass the keyword based URL filtering by requesting a long URL, as demonstrated using a large number of %20 (hex-encoded space) sequences.

    Source:Marc Ruef
    Published:24 May 2004
    4.3
    Medium

    CVE-2004-2030

    Last Modified: 15 Jan 2013

    Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the message subject.

    Source:Sandeep Giri
    Published:22 May 2004
    5
    Medium

    CVE-2004-2029

    Last Modified: 25 May 2016

    The Util_DecodeHTTPAuth function in BNBT BitTorrent Tracker Beta 7.5 Release 2 and earlier allows remote attackers to cause a denial of service (crash) via a Basic Authorization HTTP request with a "A==" value.

    Source:Sowhat
    Published:22 May 2004
    4.3
    Medium

    CVE-2004-2028

    Last Modified: 15 Jan 2013

    Cross-site scripting (XSS) vulnerability in stats.php in e107 allows remote attackers to inject arbitrary web script or HTML via the referer parameter to log.php.

    Source:Chinchilla
    Published:21 May 2004
    7.5
    High

    CVE-2004-2026

    Last Modified: 13 Jan 2013

    Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format string specifiers in syslog messages.

    Source:Nilanjan De
    Published:31 Dec 2004
    2.1
    Low

    CVE-2004-2022

    Last Modified: 15 Jan 2013

    ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the system command, which leads to a stack-based buffer overflow. NOTE: it is unclear whether this bug is in Perl or the OS API that is used by Perl.

    Source:Oliver Karow
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-2021

    Last Modified: 15 Jan 2013

    Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the filename argument.

    Source:Rene
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-2018

    Last Modified: 15 Jan 2013

    PHP remote file inclusion vulnerability in index.php in Php-Nuke 6.x through 7.3 allows remote attackers to execute arbitrary PHP code by modifying the modpath parameter to reference a URL on a remote web server that contains the code.

    Source:waraxe
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-2017

    Last Modified: 15 Jan 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Turbo Traffic Trader C (TTT-C) 1.0 allow remote attackers to inject arbitrary HTML or web script, as demonstrated via (1) the link parameter to ttt-out, (2) the X-Forwarded-For header in a GET request to ttt-in, (3) the Referer header in a GET request to ttt-in, or the (4) site name or (5) site URL fields in the main control panel.

    Source:Kaloyan Olegov Georgiev
    Published:31 Dec 2004
    2.6
    Low

    CVE-2004-2014

    Last Modified: 15 Jan 2013

    Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.

    Source:Hugo Vazquez
    Published:16 May 2004
    7.2
    High

    CVE-2004-2012

    Last Modified: 15 Jan 2013

    The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges.

    Source:Stefan Esser
    Published:31 Dec 2004
    4.6
    Medium

    CVE-2004-2008

    Last Modified: 14 Jan 2013

    SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter.

    Source:Janek Vind
    Published:8 May 2004
    4.3
    Medium

    CVE-2004-2007

    Last Modified: 14 Jan 2013

    Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to inject arbitrary HTML or web script via the (1) cat parameter in a CatView function or (2) jokeid parameter in a JokeView function.

    Source:Janek Vind
    Published:8 May 2004
    5.1
    Medium

    CVE-2004-2005

    Last Modified: 14 Jan 2013

    Buffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-mail with (1) a link to a long URL to the C drive or (2) a long attachment name.

    Source:Paul Szabo
    Published:6 May 2004
    7.5
    High

    CVE-2004-2003

    Last Modified: 14 Jan 2013

    Buffer overflow in the ssl_prcert function in the SSLway filter (sslway.c) for DeleGate 8.9.2 and earlier allows remote attackers to execute arbitrary code via a certificate with a long (1) subject or (2) issuer name field.

    Source:Joel Eriksson
    Published:6 May 2004
    7.5
    High

    CVE-2004-2000

    Last Modified: 30 Jan 2014

    SQL injection vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL via the (1) orderby or (2) sid parameters to modules.php.

    Source:S@BUN
    Published:5 May 2004
    4.3
    Medium

    CVE-2004-1996

    Last Modified: 9 Dec 2016

    Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size tag.

    Source:Cheng Peng Su
    Published:5 May 2004
    6.5
    Medium

    CVE-2004-1995

    Last Modified: 13 Jan 2013

    Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.

    Source:Stuart Jamieson
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1992

    Last Modified: 10 Jan 2013

    Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read.

    Source:storm
    Published:20 Apr 2004
    7.5
    High

    CVE-2004-1989

    Last Modified: 15 Dec 2016

    PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modifying the THEME_DIR parameter to reference a URL on a remote web server that contains user_list_info_box.inc.

    Source:Janek Vind
    Published:30 Apr 2004
    7.5
    High

    CVE-2004-1988

    Last Modified: 21 Dec 2016

    PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by modifying the CPG_M_DIR to reference a URL on a remote web server that contains functions.inc.php.

    Source:Janek Vind
    Published:30 Apr 2004
    5
    Medium

    CVE-2004-1986

    Last Modified: 21 Dec 2016

    Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the startdir parameter.

    Source:Janek Vind
    Published:4 Apr 2004
    4.3
    Medium

    CVE-2004-1985

    Last Modified: 15 Dec 2016

    Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter.

    Source:Janek Vind
    Published:30 Apr 2004
    2.1
    Low

    CVE-2004-1983

    Last Modified: 6 Sept 2016

    The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local users to cause a denial of service (infinite loop) via unknown attack vectors.

    Source:Shadowinteger
    Published:2 May 2004
    4.3
    Medium

    CVE-2004-1978

    Last Modified: 13 Jan 2013

    Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script via the text parameter.

    Source:Bartek Nowotarski
    Published:30 Apr 2004
    4.3
    Medium

    CVE-2004-1975

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the category module in pafiledb.php for paFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a vulnerability that is closely related to CVE-2004-1551.

    Source:indoushka
    Published:27 Apr 2004
    5
    Medium

    CVE-2004-1973

    Last Modified: 13 Jan 2013

    DiGi Web Server allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request that contains a large number of / (slash) characters, which consumes resources when DiGi converts the slashes to \ (backslash) characters.

    Source:Donato Ferrante
    Published:27 Apr 2004