CSV
182,488 results for "vulnerability" Page 82
CVE-2004-0521

SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php.

Aug 18, 2004 18 affected product(s) NVD
10.0
CVSS
3.2%
EPSS
⚡ 40.9
CVE-2003-1042

SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to execute arbitrary SQL via the product name.

Aug 18, 2004 18 affected product(s) NVD
10.0
CVSS
2.6%
EPSS
⚡ 40.8
CVE-2003-1043

SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges to execute arbitrary SQL via the id parameter to editkeywords.cgi.

Aug 18, 2004 18 affected product(s) NVD
10.0
CVSS
2.6%
EPSS
⚡ 40.8
CVE-2004-1682

Format string vulnerability in QNX 6.1 FTP client allows remote authenticated users to gain group bin privileges via format string specifiers in the QUOTE command.

Aug 15, 2004 1 affected product(s) NVD
10.0
CVSS
2.5%
EPSS
⚡ 40.7
CVE-2004-0513

Unspecified vulnerability in Mac OS X before 10.3.4 has unknown impact and attack vectors related to "logging when tracing system calls."

Aug 18, 2004 1 affected product(s) NVD
10.0
CVSS
1.7%
EPSS
⚡ 40.5
CVE-2004-0801

Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands.

Sep 16, 2004 10 affected product(s) NVD
7.5
CVSS
4.3%
EPSS
⚡ 31.3
CVE-2004-1737

SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.

Aug 16, 2004 20 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2004-1722

SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule parameter.

Aug 17, 2004 1 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2004-1660

PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath parameter to (1) show_archives.php or (2) show_news.php.

Aug 30, 2004 1 affected product(s) NVD
7.5
CVSS
1.7%
EPSS
⚡ 30.5
CVE-2004-0518

Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to "the use of SSH and reporting errors," has unknown impact and attack vectors.

Aug 18, 2004 8 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2004-1732

SQL injection vulnerability in out.ViewFolder.php in MyDMS before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the folderid parameter.

Aug 20, 2004 2 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2004-1647

SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, OPass, or NPass to CPassChangePassword.asp, (3) users_edit.asp, or (4) users_add.asp.

Aug 30, 2004 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2004-1654

SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commands via cal_template.

Sep 1, 2004 5 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2004-0490

cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.

Aug 18, 2004 13 affected product(s) NVD
7.2
CVSS
4.5%
EPSS
⚡ 30.1
CVE-2004-0520

Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.

Aug 18, 2004 21 affected product(s) NVD
6.8
CVSS
7.1%
EPSS
⚡ 29.3
CVE-2004-0514

Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of directory services lookups."

Aug 18, 2004 8 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2004-1716

Cross-site scripting (XSS) vulnerability in PForum before 1.26 allows remote attackers to inject arbitrary web script or HTML via the (1) IRC Server or (2) AIM ID fields in the user profile.

Aug 16, 2004 2 affected product(s) NVD
6.8
CVSS
2.4%
EPSS
⚡ 27.9
CVE-2004-1742

Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a .. (dot dot) in the viewcat parameter.

Aug 24, 2004 1 affected product(s) NVD
5.0
CVSS
7.2%
EPSS
⚡ 22.2
CVE-2004-1678

Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary Perl modules via ".." sequences terminated by a %00 (null) character in the lang parameter, which can leak portions of the requested files if a compilation error message occurs.

Sep 13, 2004 1 affected product(s) NVD
5.0
CVSS
7.2%
EPSS
⚡ 22.2
CVE-2004-1646

Directory traversal vulnerability in Xedus 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

Aug 30, 2004 1 affected product(s) NVD
5.0
CVSS
7.1%
EPSS
⚡ 22.1