CSV
182,513 results for "vulnerability" Page 96
CVE-2004-2026

Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format string specifiers in syslog messages.

Dec 31, 2004 6 affected product(s) NVD
7.5
CVSS
6.6%
EPSS
⚡ 32
CVE-2004-1900

Format string vulnerability in the logging function in IGI 2 Covert Strike server 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in RCON commands.

Dec 31, 2004 4 affected product(s) NVD
7.5
CVSS
3.8%
EPSS
⚡ 31.1
CVE-2004-2018

PHP remote file inclusion vulnerability in index.php in Php-Nuke 6.x through 7.3 allows remote attackers to execute arbitrary PHP code by modifying the modpath parameter to reference a URL on a remote web server that contains the code.

Dec 31, 2004 15 affected product(s) NVD
7.5
CVSS
3.8%
EPSS
⚡ 31.1
CVE-2004-1881

SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via the strItems parameter.

Dec 31, 2004 2 affected product(s) NVD
7.5
CVSS
3.1%
EPSS
⚡ 30.9
CVE-2004-2010

PHP remote file inclusion vulnerability in index.php in phpShop 0.7.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the base_dir parameter to reference a URL on a remote web server that contains phpshop.cfg.

Dec 31, 2004 NVD
7.5
CVSS
2.6%
EPSS
⚡ 30.8
CVE-2004-2062

SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2) parent_id, or (3) mode parameters.

Dec 31, 2004 7 affected product(s) NVD
7.5
CVSS
2.4%
EPSS
⚡ 30.7
CVE-2004-2074

Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands.

Dec 31, 2004 1 affected product(s) NVD
5.0
CVSS
35.8%
EPSS
⚡ 30.7
CVE-2004-1949

SQL injection vulnerability in PostNuke 7.2.6 and earlier allows remote attackers to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset parameter to changeinfo.php in the Your_Account module.

Dec 31, 2004 1 affected product(s) NVD
7.5
CVSS
2.0%
EPSS
⚡ 30.6
CVE-2004-1914

SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via the eid parameter.

Dec 31, 2004 2 affected product(s) NVD
7.5
CVSS
1.7%
EPSS
⚡ 30.5
CVE-2004-2023

SQL injection vulnerability in login.php in Zen Cart 1.1.2d, 1.1.4 before patch 1, and possibly other versions allows remote attackers to execute arbitrary SQL via the (1) admin_name or (2) admin_pass parameters.

Dec 31, 2004 2 affected product(s) NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.5
CVE-2004-2057

SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements.

Dec 31, 2004 6 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.5
CVE-2004-1955

SQL injection vulnerability in modules.php in phProfession 2.5 allows remote attackers to execute arbitrary SQL code via the offset parameter.

Dec 31, 2004 1 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2004-1962

SQL injection vulnerability in index.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection filters by using "/**/" sequences in the targeted fields.

Dec 31, 2004 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2004-2056

SQL injection vulnerability in action.php in Nucleus CMS 3.01 allows remote attackers to execute arbitrary SQL statements via the itemid parameter.

Dec 31, 2004 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2004-2025

SQL injection vulnerability in application_top.php for Zen Cart 1.1.3 before patch 2 may allow remote attackers to execute arbitrary SQL commands via the products_id parameter.

Dec 31, 2004 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2004-2110

SQL injection vulnerability in register.php in Phorum before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the hide_email parameter.

Dec 31, 2004 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2004-2070

The Altiris Client Service for Windows 5.6 SP1 Hotfix E (5.6.181) allows local users to execute arbitrary commands by opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2005-1590.

Dec 31, 2004 NVD
7.2
CVSS
0.5%
EPSS
⚡ 28.9
CVE-2004-2072

Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter.

Dec 31, 2004 1 affected product(s) NVD
6.8
CVSS
4.2%
EPSS
⚡ 28.5
CVE-2004-1995 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.

Dec 31, 2004 1 affected product(s) NVD
6.5
CVSS
1.8%
EPSS
⚡ 26.5
CVE-2004-2116

Directory traversal vulnerability in Tiny Server 1.1 allows remote attackers to read or download arbitrary files via a .. (dot dot) in the URL.

Dec 31, 2004 1 affected product(s) NVD
5.0
CVSS
8.7%
EPSS
⚡ 22.6