CSV
182,514 results for "vulnerability" Page 97
CVE-2004-2142

Unknown vulnerability in the remote tape support (remote.c) in the RMT client for Jorg Schilling sdd 1.28 and 1.31 has unknown impact and attack vectors.

Dec 31, 2004 2 affected product(s) NVD
10.0
CVSS
1.7%
EPSS
⚡ 40.5
CVE-2004-2158

SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter to (1) exit.php or (2) comment.php.

Dec 31, 2004 1 affected product(s) NVD
7.5
CVSS
4.1%
EPSS
⚡ 31.2
CVE-2004-2161

SQL injection vulnerability in file_overview.php in TUTOS 1.1 allows remote attackers to execute arbitrary SQL commands via the link_id parameter.

Dec 31, 2004 1 affected product(s) NVD
7.5
CVSS
3.5%
EPSS
⚡ 31
CVE-2004-2062

SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2) parent_id, or (3) mode parameters.

Dec 31, 2004 7 affected product(s) NVD
7.5
CVSS
2.4%
EPSS
⚡ 30.7
CVE-2004-2074

Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands.

Dec 31, 2004 1 affected product(s) NVD
5.0
CVSS
35.8%
EPSS
⚡ 30.7
CVE-2004-2139

Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl.

Dec 31, 2004 2 affected product(s) NVD
7.5
CVSS
2.1%
EPSS
⚡ 30.6
CVE-2004-2173

SQL injection vulnerability in advSearch_h.asp in EarlyImpact ProductCart allows remote attackers to execute arbitrary SQL commands via the priceUntil parameter.

Dec 31, 2004 17 affected product(s) NVD
7.5
CVSS
2.0%
EPSS
⚡ 30.6
CVE-2004-2057

SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements.

Dec 31, 2004 6 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.5
CVE-2004-2143

SQL injection vulnerability in the ReMOSitory Server add-on module to Mambo Portal 4.5.1 (1.09) and earlier allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in the com_remository option.

Dec 31, 2004 1 affected product(s) NVD
7.5
CVSS
1.7%
EPSS
⚡ 30.5
CVE-2004-2056

SQL injection vulnerability in action.php in Nucleus CMS 3.01 allows remote attackers to execute arbitrary SQL statements via the itemid parameter.

Dec 31, 2004 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2004-2145

SQL injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows remote attackers to execute arbitrary SQL commands via the (1) sortdir or (2) criteria parameter to ladder-log.asp or the (3) memberid or (4) teamid parameter to view-profile.asp.

Dec 31, 2004 2 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2004-2110

SQL injection vulnerability in register.php in Phorum before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the hide_email parameter.

Dec 31, 2004 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2004-2070

The Altiris Client Service for Windows 5.6 SP1 Hotfix E (5.6.181) allows local users to execute arbitrary commands by opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2005-1590.

Dec 31, 2004 NVD
7.2
CVSS
0.5%
EPSS
⚡ 28.9
CVE-2004-2148

Unknown local vulnerability in the "change user" feature of Slava Astashonok Fprobe 1.0.5 and earlier has unknown impact and attack vectors.

Dec 31, 2004 6 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2004-2072

Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter.

Dec 31, 2004 1 affected product(s) NVD
6.8
CVSS
4.2%
EPSS
⚡ 28.5
CVE-2004-2128

Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as other users via the query string to ISAPISkeleton.dll.

Dec 31, 2004 NVD
6.8
CVSS
2.3%
EPSS
⚡ 27.9
CVE-2004-2138

Cross-site scripting (XSS) vulnerability in AWSguest.php in AllWebScripts MySQLGuest allows remote attackers to inject arbitrary HTML and PHP code via the (1) Name, (2) Email, (3) Homepage or (4) Comments field.

Dec 31, 2004 1 affected product(s) NVD
6.8
CVSS
1.5%
EPSS
⚡ 27.6
CVE-2004-2160

Format string vulnerability in xml_elem.c for XMLStarlet Command Line XML Toolkit 0.9.3 may allow attackers to cause a denial of service or execute arbitrary code.

Dec 31, 2004 1 affected product(s) NVD
6.4
CVSS
1.7%
EPSS
⚡ 26.1
CVE-2004-2116

Directory traversal vulnerability in Tiny Server 1.1 allows remote attackers to read or download arbitrary files via a .. (dot dot) in the URL.

Dec 31, 2004 1 affected product(s) NVD
5.0
CVSS
8.7%
EPSS
⚡ 22.6
CVE-2004-2124

The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412.

Dec 31, 2004 5 affected product(s) NVD
5.0
CVSS
7.4%
EPSS
⚡ 22.2