CSV
182,489 results for "vulnerability" Page 86
CVE-2004-0393

Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format string specifiers in a buffer that can not be resolved, which is provided to the syslog function.

Dec 6, 2004 5 affected product(s) NVD
10.0
CVSS
17.4%
EPSS
⚡ 45.2
CVE-2004-0277

Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username.

Nov 23, 2004 1 affected product(s) NVD
10.0
CVSS
13.6%
EPSS
⚡ 44.1
CVE-2004-0300

SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.

Nov 23, 2004 3 affected product(s) NVD
10.0
CVSS
5.2%
EPSS
⚡ 41.6
CVE-2004-0304

SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.

Nov 23, 2004 1 affected product(s) NVD
10.0
CVSS
4.1%
EPSS
⚡ 41.2
CVE-2004-0239

SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.

Nov 23, 2004 6 affected product(s) NVD
10.0
CVSS
3.3%
EPSS
⚡ 41
CVE-2004-0250

SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat parameter in showcat.php.

Nov 23, 2004 6 affected product(s) NVD
10.0
CVSS
3.2%
EPSS
⚡ 41
CVE-2004-0348

SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter.

Nov 23, 2004 1 affected product(s) NVD
10.0
CVSS
3.3%
EPSS
⚡ 41
CVE-2004-0338

SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.

Nov 23, 2004 8 affected product(s) NVD
10.0
CVSS
2.4%
EPSS
⚡ 40.7
CVE-2004-0253

IBM Cloudscape 5.1 running jdk 1.4.2_03 allows remote attackers to execute arbitrary programs or cause a denial of service via certain SQL code, possibly due to a SQL injection vulnerability.

Nov 23, 2004 1 affected product(s) NVD
10.0
CVSS
2.0%
EPSS
⚡ 40.6
CVE-2004-0308

Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connection to the VxWorks shell.

Nov 24, 2004 10 affected product(s) NVD
10.0
CVSS
1.7%
EPSS
⚡ 40.5
CVE-2004-0273

Directory traversal vulnerability in RealOne Player, RealOne Player 2.0, and RealOne Enterprise Desktop allows remote attackers to upload arbitrary files via an RMP file that contains .. (dot dot) sequences in a .rjs skin file.

Nov 23, 2004 10 affected product(s) NVD
9.3
CVSS
4.0%
EPSS
⚡ 38.4
CVE-2004-0272

SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.

Nov 23, 2004 2 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2004-0360

Unknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via unknown attack vectors.

Nov 23, 2004 4 affected product(s) NVD
7.2
CVSS
1.0%
EPSS
⚡ 29.1
CVE-2004-0359

Cross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other users via the (1) c, (2) f, (3) showtopic, (4) showuser, or (5) username parameters.

Nov 23, 2004 2 affected product(s) NVD
6.8
CVSS
5.6%
EPSS
⚡ 28.9
CVE-2004-0265

Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in the News or Reviews modules.

Nov 23, 2004 13 affected product(s) NVD
6.8
CVSS
4.6%
EPSS
⚡ 28.6
CVE-2004-0301

Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter.

Nov 23, 2004 3 affected product(s) NVD
6.8
CVSS
4.2%
EPSS
⚡ 28.5
CVE-2004-0358

Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed parameter during the newslogo_upload action in admin.php.

Nov 23, 2004 4 affected product(s) NVD
6.8
CVSS
4.2%
EPSS
⚡ 28.5
CVE-2004-0269

SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.

Nov 23, 2004 26 affected product(s) NVD
6.4
CVSS
8.1%
EPSS
⚡ 28
CVE-2004-0251

Cross-site scripting (XSS) vulnerability in rxgoogle.cgi allows remote attackers to execute arbitrary script as other users via the query parameter.

Nov 23, 2004 1 affected product(s) NVD
6.8
CVSS
2.0%
EPSS
⚡ 27.8
CVE-2004-0254

Cross-site scripting (XSS) vulnerability in Discuz! Board 2.x and 3.x allows remote attackers to execute arbitrary script as other users via an img tag.

Nov 23, 2004 2 affected product(s) NVD
6.8
CVSS
2.0%
EPSS
⚡ 27.8