7.5
    High

    CVE-2004-1536

    Last Modified: 13 Mar 2013

    SQL injection vulnerability in index.php in the ibProArcade module for Invision Power Board (IPB) 1.x and 2.x allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:axl daivy
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1535

    Last Modified: 13 Mar 2013

    PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_path parameter to reference a URL on a remote web server that contains the code.

    Source:Jerome Athias
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1533

    Last Modified: 19 Apr 2016

    Buffer overflow in pop3svr.exe for DMS POP3 1.5.3.27 and earlier allows remote attackers to cause a denial of service (service crash) via a long (1) username or (2) password.

    Source:Reed Arvin
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1531

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter.

    Source:RusH
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1521

    Last Modified: 16 Mar 2016

    Eudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable encoded attachments, which makes it easier for remote attackers to read arbitrary files via spoofed "Converted" headers.

    Source:anonymous
    Published:31 Dec 2004
    4.6
    Medium

    CVE-2004-1520

    Last Modified: 12 Apr 2016

    Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command.

    Source:Zatlander
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1519

    Last Modified: 23 Feb 2015

    SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands via (1) the bug_id parameter in a viewvotes operation or (2) the project parameter in an add operation.

    Source:Steffen Rösemann
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1515

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.

    Source:anonymous
    Published:31 Dec 2004
    2.1
    Low

    CVE-2004-1500

    Last Modified: 11 Mar 2013

    Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.

    Source:Luigi Auriemma
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1499

    Last Modified: 11 Mar 2013

    Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.

    Source:Behrang Fouladi
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1493

    Last Modified: 16 Apr 2026

    Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (server crash) via multiple connections with long nicknames, possibly triggering a buffer overflow.

    Source:Luigi Auriemma
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1491

    Last Modified: 17 Mar 2013

    Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec entry.

    Source:Giovanni Delvecchio
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1488

    Last Modified: 17 Mar 2013

    wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.

    Source:Jan Minar
    Published:10 Dec 2004
    5
    Medium

    CVE-2004-1484

    Last Modified: 12 Apr 2016

    Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly option, allows remote attackers or local users to execute arbitrary code via format string specifiers in a syslog message.

    Source:CoKi
    Published:31 Dec 2004
    5.1
    Medium

    CVE-2004-1475

    Last Modified: 30 Mar 2016

    Multiple stack-based buffer overflows in xine-lib 1-rc2 through 1-rc5 allow attackers to execute arbitrary code via (1) long VideoCD vcd:// MRLs or (2) long subtitle lines.

    Source:c0ntex
    Published:31 Dec 2004
    7.1
    High

    CVE-2004-1471

    Last Modified: 17 Jan 2013

    Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a wrapper line.

    Source:Gyan Chawdhary
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1470

    Last Modified: 5 Mar 2013

    CRLF injection vulnerability in SnipSnap 0.5.2a, and other versions before 1.0b1, allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server.

    Source:Maestro De-Seguridad
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1467

    Last Modified: 27 Jan 2013

    Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.0.00.003 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) date or search text field in the calendar module, (2) Field parameter, Filter parameter, QField parameter, Start parameter or Search field in the address module, (3) Subject field in the message module or (4) Subject field in the Ticket module.

    Source:Joxean Koret
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1466

    Last Modified: 26 Jan 2013

    The set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds after they have been uploaded using save_photos.php, which allows remote attackers to upload and execute execute arbitrary scripts before they are deleted, if the temporary directory is under the web root.

    Source:aCiDBiTS
    Published:31 Dec 2004
    3.7
    Low

    CVE-2004-1465

    Last Modified: 13 May 2016

    Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors, including the command line.

    Source:ATmaCA
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1456

    Last Modified: 28 Mar 2016

    filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.

    Source:anonymous
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1444

    Last Modified: 16 Jan 2013

    Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ command in an HTTP GET request.

    Source:Vickenty Fesunov
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1442

    Last Modified: 23 Dec 2012

    Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web script or HTML via a macro filename, which is not properly handled by error messages such as "DTWP001E."

    Source:Carsten Eiram
    Published:31 Dec 2004
    9.3
    Critical

    CVE-2004-1441

    Last Modified: 21 Jan 2013

    Cross-site scripting (XSS) vulnerability in icq.cgi in Board Power 2.04PF allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Source:Alexander Antipov
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1439

    Last Modified: 27 Oct 2016

    Buffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1) USER, (2) PASS, (3) RETR,(4) CWD, (5) XMKD, and (6) XRMD.

    Source:Tal Zeltzer
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1437

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the digest authentication functionality in Pavuk 0.9.28-r2 and earlier allow remote attackers to execute arbitrary code.

    Source:infamous41md
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1423

    Last Modified: 19 Jan 2018

    Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php.

    Source:GulfTech Security
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1422

    Last Modified: 19 Jan 2018

    WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php settings.

    Source:GulfTech Security
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1421

    Last Modified: 19 Jan 2018

    Multiple PHP remote file inclusion vulnerabilities (1) step_one.php, (2) step_one_tables.php, (3) step_two_tables.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to execute arbitrary PHP code by modifying the server_inc parameter to reference a URL on a remote web server that contains the code.

    Source:GulfTech Security
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1420

    Last Modified: 19 Jan 2018

    Multiple cross-site scripting (XSS) vulnerabilities in header.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) site_title or (2) http_images parameter.

    Source:GulfTech Security
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1418

    Last Modified: 28 Apr 2013

    Cross-site scripting (XSS) vulnerability in WPKontakt 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an e-mail address, which is not quoted when a parsing error is generated.

    Source:Poznan Supercomputing
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1417

    Last Modified: 19 Jan 2018

    Cross-site scripting (XSS) vulnerability in login.php in PsychoStats 2.2.4 Beta and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter.

    Source:GulfTech Security
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1415

    Last Modified: 28 Apr 2013

    SQL injection vulnerability in (1) disp_album.php and possibly (2) disp_img.php in 2Bgal 2.4 and 2.5.1 allows remote attackers to execute arbitrary SQL commands via the id_album parameter.

    Source:zib
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1413

    Last Modified: 5 Jan 2018

    Multiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands via the (1) subcat, (2) rate, (3) questiondetails, (4) ticketkey22, (5) email22 parameters to index.php, or (6) the e-mail field of the Forgot Key feature.

    Source:GulfTech Security
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1412

    Last Modified: 5 Jan 2018

    Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.x allows remote attackers to inject arbitrary web script or HTML via the searchm parameter.

    Source:GulfTech Security
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1410

    Last Modified: 25 Apr 2013

    Cross-site scripting (XSS) vulnerability in Gadu-Gadu build 155 and earlier allows remote attackers to inject arbitrary web script via a URL, which is echoed in a popup window that displays a parsing error message, a different vulnerability than CVE-2004-1229.

    Source:Jaroslaw Sajko
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1406

    Last Modified: 25 Apr 2013

    SQL injection vulnerability in ikonboard.cgi in Ikonboard 3.1.0 through 3.1.3 allows remote attackers to inject arbitrary SQL commands via the (1) st or (2) keywords parameter.

    Source:anonymous
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1405

    Last Modified: 25 Apr 2013

    MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.

    Source:Jeremy Bae
    Published:31 Dec 2004
    10
    Critical

    CVE-2004-1402

    Last Modified: 18 Mar 2013

    SQL injection vulnerability in iWebNegar allows remote attackers to execute arbitrary SQL commands via (1) the string parameter for index.php, (2) comments.php, or (3) the administrator login page.

    Source:Shervin Khaleghjou
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1401

    Last Modified: 18 Mar 2013

    SQL injection vulnerability in verify.asp in Asp-rider allows remote attackers to execute arbitrary SQL statements and bypass authentication via the username parameter.

    Source:Shervin Khaleghjou
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1400

    Last Modified: 18 Mar 2013

    The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unauthorized access via a direct request to main.asp.

    Source:ali reza AcTiOnSpIdEr
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1395

    Last Modified: 16 Apr 2026

    The Lithtech engine, as used in (1) Contract Jack 1.1 and earlier, (2) No one lives forever 2 1.3 and earlier, (3) Tron 2.0 1.042 and earlier, (4) F.E.A.R. (First Encounter Assault and Recon), and possibly other games, allows remote attackers to cause a denial of service (connection refused) via a UDP packet that causes recvfrom to generate a return code that causes the listening loop to exit, as demonstrated using zero byte packets or packets between 8193 and 12280 bytes, which result in conditions that are not "Operation would block."

    Source:Luigi Auriemma
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1392

    Last Modified: 28 Oct 2017

    PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.

    Source:FraMe
    Published:15 Dec 2004
    6
    Medium

    CVE-2004-1389

    Last Modified: 1 Apr 2017

    Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1, and 4.5, DataCenter 3.4, 3.4.1, and 4.5, Enterprise Server 5.1, and NetBackup Server 5.0 and 5.1, allows attackers to execute arbitrary commands via the bpjava-susvc process, possibly related to the call-back feature.

    Source:patrick
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1388

    Last Modified: 6 Mar 2011

    Format string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7 allows remote attackers to execute arbitrary code via certain GPS requests containing format string specifiers that are not properly handled in syslog calls.

    Source:Metasploit
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1385

    Last Modified: 5 Jan 2018

    phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID such as shell metacharacters, (2) an invalid appname parameter to preferences.php or (3) an invalid menuaction parameter to index.php, which reveals the web server path in an error message.

    Source:GulfTech Security
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1384

    Last Modified: 5 Jan 2018

    Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) kp3, (2) type, (3) msg, (4) forum_id, (5) pos, (6) cats_app, (7) cat_id, (8) msgball[msgnum], (9) fldball[acctnum] parameters to index.php or (10) ticket_id to viewticket_details.php.

    Source:GulfTech Security
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1383

    Last Modified: 5 Jan 2018

    Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrary SQL statements via the (1) order, (2) project_id, (3) pro_main, or (4) hours_id parameters to index.php or (5) ticket_id to viewticket_details.php.

    Source:GulfTech Security
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1381

    Last Modified: 12 Apr 2016

    Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported using form fields, which allows remote attackers to steal sensitive data that is intended for other sites, which could facilitate phishing attacks.

    Source:Jakob Balle
    Published:20 Oct 2004
    5
    Medium

    CVE-2004-1380

    Last Modified: 12 Apr 2016

    Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows and facilitate phishing attacks, aka the "Dialog Box Spoofing Vulnerability."

    Source:Jakob Balle
    Published:20 Oct 2004