CSV
182,488 results for "vulnerability" Page 85
CVE-2004-0847 CRITICAL Exploit

The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."

Nov 3, 2004 2 affected product(s) NVD
9.8
CVSS
75.7%
EPSS
⚡ 71.9
CVE-2004-0209

Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."

Nov 3, 2004 3 affected product(s) NVD
10.0
CVSS
57.4%
EPSS
⚡ 57.2
CVE-2004-0277

Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username.

Nov 23, 2004 1 affected product(s) NVD
10.0
CVSS
13.6%
EPSS
⚡ 44.1
CVE-2004-0300

SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.

Nov 23, 2004 3 affected product(s) NVD
10.0
CVSS
5.2%
EPSS
⚡ 41.6
CVE-2004-0304

SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.

Nov 23, 2004 1 affected product(s) NVD
10.0
CVSS
4.1%
EPSS
⚡ 41.2
CVE-2004-0239

SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.

Nov 23, 2004 6 affected product(s) NVD
10.0
CVSS
3.3%
EPSS
⚡ 41
CVE-2004-0250

SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat parameter in showcat.php.

Nov 23, 2004 6 affected product(s) NVD
10.0
CVSS
3.2%
EPSS
⚡ 41
CVE-2004-0236

SQL injection vulnerability in login.asp in thePHOTOtool allows remote attackers to gain unauthorized access via the password field.

Nov 23, 2004 1 affected product(s) NVD
10.0
CVSS
2.2%
EPSS
⚡ 40.7
CVE-2004-0253

IBM Cloudscape 5.1 running jdk 1.4.2_03 allows remote attackers to execute arbitrary programs or cause a denial of service via certain SQL code, possibly due to a SQL injection vulnerability.

Nov 23, 2004 1 affected product(s) NVD
10.0
CVSS
2.0%
EPSS
⚡ 40.6
CVE-2004-0846

Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.

Nov 3, 2004 7 affected product(s) NVD
7.5
CVSS
28.3%
EPSS
⚡ 38.5
CVE-2004-0273

Directory traversal vulnerability in RealOne Player, RealOne Player 2.0, and RealOne Enterprise Desktop allows remote attackers to upload arbitrary files via an RMP file that contains .. (dot dot) sequences in a .rjs skin file.

Nov 23, 2004 10 affected product(s) NVD
9.3
CVSS
4.0%
EPSS
⚡ 38.4
CVE-2004-1628

Format string vulnerability in log.c in rssh before 2.2.2 allows remote authenticated users to execute arbitrary code.

Oct 23, 2004 1 affected product(s) NVD
9.0
CVSS
4.7%
EPSS
⚡ 37.4
CVE-2004-1622

SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.

Oct 21, 2004 2 affected product(s) NVD
7.5
CVSS
2.4%
EPSS
⚡ 30.7
CVE-2004-0272

SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.

Nov 23, 2004 2 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2004-0843

Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."

Nov 3, 2004 2 affected product(s) NVD
5.0
CVSS
33.8%
EPSS
⚡ 30.1
CVE-2004-0844

Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Character Set Systems Vulnerability."

Nov 3, 2004 1 affected product(s) NVD
5.0
CVSS
32.8%
EPSS
⚡ 29.8
CVE-2004-0265

Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in the News or Reviews modules.

Nov 23, 2004 13 affected product(s) NVD
6.8
CVSS
4.6%
EPSS
⚡ 28.6
CVE-2004-0301

Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter.

Nov 23, 2004 3 affected product(s) NVD
6.8
CVSS
4.2%
EPSS
⚡ 28.5
CVE-2004-0269

SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.

Nov 23, 2004 26 affected product(s) NVD
6.4
CVSS
8.1%
EPSS
⚡ 28
CVE-2004-0251

Cross-site scripting (XSS) vulnerability in rxgoogle.cgi allows remote attackers to execute arbitrary script as other users via the query parameter.

Nov 23, 2004 1 affected product(s) NVD
6.8
CVSS
2.0%
EPSS
⚡ 27.8