4.3
    Medium

    CVE-2004-1882

    Last Modified: 5 Jan 2013

    Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or HTML via the strImageTag parameter.

    Source:Nick Gudov
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1881

    Last Modified: 5 Jan 2013

    SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via the strItems parameter.

    Source:Nick Gudov
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1878

    Last Modified: 5 Jan 2013

    LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl preceded by // (double leading slash).

    Source:Martin Eiszner
    Published:30 Mar 2004
    9.3
    Critical

    CVE-2004-1875

    Last Modified: 30 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to testfile.html, (2) file parameter to erredit.html, (3) dns parameter to dnslook.html, (4) account parameter to ignorelist.html, (5) account parameter to showlog.html, (6) db parameter to repairdb.html, (7) login parameter to doaddftp.html (8) account parameter to editmsg.htm, or (9) ip parameter to del.html. NOTE: the dnslook.html vector was later reported to exist in cPanel 10.

    Source:Aria-Security Team
    Published:30 Mar 2004
    7.5
    High

    CVE-2004-1873

    Last Modified: 27 Oct 2016

    SQL injection vulnerability in category.asp in A-CART Pro and A-CART 2.0 allows remote attackers to gain privileges via the catcode parameter.

    Source:laurent gaffie
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1872

    Last Modified: 5 Jan 2013

    Cross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote attackers to inject arbitrary web script or HTML via the @import URL function in a CSS style tag.

    Source:Simon Boulet
    Published:29 Mar 2004
    4.3
    Medium

    CVE-2004-1871

    Last Modified: 19 Jan 2018

    Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ppuser, (2) password, (3) stype, (4) perpage, (5) sort, (6) page, (7) si, or (8) cat parameters to showmembers.php, or the (9) photo name, (10) photo description, (11) album name, or (12) album description fields.

    Source:GulfTech Security
    Published:29 Mar 2004
    7.5
    High

    CVE-2004-1870

    Last Modified: 19 Jan 2018

    Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comments.php, (3) credit parameter to comments.php, (4) cat parameter to index.php, (5) ppuser parameter to showgallery.php, (6) cat parameter to showgallery.php, (7) cat parameter to uploadphoto.php, (8) albumid parameter to useralbums.php, or (9) albumid parameter to useralbums.php.

    Source:GulfTech Security
    Published:29 Mar 2004
    7.5
    High

    CVE-2004-1868

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE tag.

    Source:VizibleSoft
    Published:25 Mar 2004
    4.3
    Medium

    CVE-2004-1867

    Last Modified: 5 Jan 2013

    Cross-site scripting (XSS) vulnerability in guest.cgi in Fresh Guest Book allows remote attackers to inject arbitrary web script or HTML via the Name field.

    Source:koi8-r Shelz
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1866

    Last Modified: 4 Jan 2013

    nstxd in Nstx 1.1 beta3 and earlier allows remote attackers to cause a denial of service (crash) via a large packet, which triggers a null dereference.

    Source:laurent oudot
    Published:26 Mar 2004
    4.6
    Medium

    CVE-2004-1861

    Last Modified: 4 Jan 2013

    Invision NetSupport School Pro uses a weak encryption algorithm to encrypt passwords, which allows local users to obtain passwords.

    Source:spiffomatic 64
    Published:25 Mar 2004
    5
    Medium

    CVE-2004-1859

    Last Modified: 19 Jul 2017

    Directory traversal vulnerability in Trend Micro Interscan Web Viruswall in InterScan VirusWall 3.5x allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

    Source:Tri Huynh
    Published:24 Mar 2004
    2.1
    Low

    CVE-2004-1857

    Last Modified: 4 Jan 2013

    Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to read arbitrary files via a .. (dot dot) in the setinclude parameter.

    Source:wirepair
    Published:24 Mar 2004
    5
    Medium

    CVE-2004-1856

    Last Modified: 4 Jan 2013

    devices_update_printer_fw_upload.hts in HP Web JetAdmin 7.5.2546, when no password is set, allows remote attackers to upload arbitrary files to the printer directory.

    Source:wirepair
    Published:24 Mar 2004
    5
    Medium

    CVE-2004-1855

    Last Modified: 3 Jan 2013

    Dark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers to gain sensitive information via a man-in-the-middle attack.

    Source:Todd Chapman
    Published:23 Mar 2004
    7.5
    High

    CVE-2004-1854

    Last Modified: 9 Jan 2013

    Buffer overflow in the logging function in Picophone 1.63 and earlier allows remote attackers to execute arbitrary code via a large packet.

    Source:Luigi Auriemma
    Published:24 Mar 2004
    7.5
    High

    CVE-2004-1847

    Last Modified: 3 Jan 2013

    News Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN parameter in the NEWS_LOGIN cookie.

    Source:Manuel Lopez
    Published:20 Mar 2004
    7.5
    High

    CVE-2004-1846

    Last Modified: 3 Jan 2013

    Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via the (1) ID parameter to more.asp, (2) ID parameter to category_news.asp, or (3) filter parameter to news_sort.asp.

    Source:Manuel Lopez
    Published:20 Mar 2004
    4.3
    Medium

    CVE-2004-1845

    Last Modified: 3 Jan 2013

    Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp.

    Source:Manuel Lopez
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1844

    Last Modified: 3 Jan 2013

    Cross-site scripting (XSS) vulnerability in Member Management System 2.1 allows remote attackers to inject arbitrary web script or HTML via (1) the err parameter to error.asp or (2) register.asp.

    Source:Manuel Lopez
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1843

    Last Modified: 3 Jan 2013

    SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1) resend.asp or (2) news_view.asp.

    Source:Manuel Lopez
    Published:20 Mar 2004
    8.8
    High

    CVE-2004-1842

    Last Modified: 2 Jan 2013

    Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php.

    Source:Janek Vind
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1838

    Last Modified: 3 Jan 2013

    Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the URL.

    Source:Donato Ferrante
    Published:22 Mar 2004
    7.5
    High

    CVE-2004-1836

    Last Modified: 3 Jan 2013

    SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments action.

    Source:JeiAr
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1835

    Last Modified: 19 Jan 2018

    Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters.

    Source:GulfTech Security
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1830

    Last Modified: 3 Jan 2013

    error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a PHP error message.

    Source:Janek Vind
    Published:18 Mar 2004
    4.3
    Medium

    CVE-2004-1829

    Last Modified: 3 Jan 2013

    Multiple cross-site scripting (XSS) vulnerabilities in error.php in Gijza.net Error Manager 2.1 for PHP-Nuke 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pagetitle or (2) error parameters, or (3) certain parameters in the error log.

    Source:Janek Vind
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-1828

    Last Modified: 3 Jan 2013

    Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and delete database tables via a direct request to uninstall.php.

    Source:saudi linux
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1827

    Last Modified: 2 Jan 2013

    Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.

    Source:Cheng Peng Su
    Published:15 Mar 2004
    7.5
    High

    CVE-2004-1826

    Last Modified: 2 Jan 2013

    SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:JeiAr
    Published:16 Mar 2004
    4.3
    Medium

    CVE-2004-1825

    Last Modified: 2 Jan 2013

    Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters.

    Source:JeiAr
    Published:16 Mar 2004
    4.3
    Medium

    CVE-2004-1824

    Last Modified: 17 Oct 2012

    Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.0 allows remote attackers to inject arbitrary web script or HTML via the what parameter to memberlist.php.

    Source:Sp.IC
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1823

    Last Modified: 2 Jan 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4 allows remote attackers to inject arbitrary web script or HTML via the (1) page parameter to showthread.php or (2) order parameter to forumdisplay.php.

    Source:JeiAr
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1822

    Last Modified: 2 Jan 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_REFERER parameter to login.php, (2) HTTP_REFERER parameter to register.php, or (3) target parameter to profile.php.

    Source:JeiAr
    Published:15 Mar 2004
    7.5
    High

    CVE-2004-1821

    Last Modified: 2 Jan 2013

    SQL injection vulnerability in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to gain privileges or perform unauthorized database operations via the gid parameter.

    Source:Janek Vind
    Published:15 Mar 2004
    7.5
    High

    CVE-2004-1820

    Last Modified: 2 Jan 2013

    PHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary PHP code by modifying the basepath parameter to reference a URL on a remote web server that contains fileFunctions.php.

    Source:Janek Vind
    Published:15 Mar 2004
    6.8
    Medium

    CVE-2004-1818

    Last Modified: 2 Jan 2013

    Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary script as other users by injecting arbitrary script into the z parameter.

    Source:Janek Vind
    Published:15 Mar 2004
    4.3
    Medium

    CVE-2004-1817

    Last Modified: 2 Jan 2013

    Cross-site scripting (XSS) vulnerability in modules.php in Php-Nuke 7.1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) Your Name field, (2) e-mail field, (3) nicname field, (4) fname parameter, (5) ratenum parameter, or (6) search field.

    Source:Janek Vind
    Published:15 Mar 2004
    7.5
    High

    CVE-2004-1813

    Last Modified: 2 Jan 2013

    VocalTec VGW4/8 Gateway 8.0 allows remote attackers to bypass authentication via an HTTP request to home.asp with a trailing slash (/).

    Source:Rafel Ivgi The-Insider
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1805

    Last Modified: 1 Jan 2013

    Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in class names.

    Source:Luigi Auriemma
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1801

    Last Modified: 31 Dec 2012

    Directory traversal vulnerability in PWebServer 0.3.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

    Source:Donato Ferrante
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1797

    Last Modified: 20 Dec 2012

    Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Source:David S. Ferreira
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1796

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header] parameter to hotnews-engine.inc.php3 or (2) config[incdir] parameter to hnmain.inc.php3.

    Source:team_elite
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1793

    Last Modified: 19 Dec 2012

    Stack-based buffer overflow in swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote authenticated users to execute arbitrary code via a long message parameter in a SendMsg action to action.htm.

    Source:MrNice
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1792

    Last Modified: 19 Dec 2012

    swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a long packet with two CRLF sequences to the service management port (TCP 8000).

    Source:Peter Winter-Smith
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1790

    Last Modified: 20 Dec 2012

    Cross-site scripting (XSS) vulnerability in the web management interface in Edimax AR-6004 ADSL Routers allows remote attackers to inject arbitrary web script or HTML via the URL.

    Source:Rafel Ivgi
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1789

    Last Modified: 20 Dec 2012

    Cross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to inject arbitrary web script or HTML via the rpAuth_1 page.

    Source:Rafel Ivgi
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1788

    Last Modified: 20 Dec 2012

    ASP-Nuke 1.3 and earlier places user credentials under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to main.mdb.

    Source:Vietnamese Security Group
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1786

    Last Modified: 20 Dec 2012

    PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb.

    Source:newbie6290
    Published:4 Jan 2004