CVE Database - 2004

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

88
Matching CVEs
15853
Critical
26962
High
69389
High WAF Coverage

CVE-2004-1166

HIGH
7.50 CVSS 2.0

CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.

Code Injection
WAF: Medium

CVE-2004-1386

HIGH
7.50 CVSS 2.0

TikiWiki before 1.8.4.1 does not properly verify uploaded images, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2005-0200.

Improper Input Validation
WAF: Medium

CVE-2004-1417

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in login.php in PsychoStats 2.2.4 Beta and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2004-1419

MEDIUM
6.80 CVSS 2.0

PHP remote file inclusion vulnerability in ZeroBoard 4.1pl4 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) _zb_path parameter to outlogin.php or (2) dir parameter to write.php to reference a URL on a remote web server that contains the code.

Code Injection
WAF: Medium

CVE-2004-1423

HIGH
7.50 CVSS 2.0

Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php.

Code Injection
WAF: Medium

CVE-2004-1424

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2004-1444

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ command in an HTTP GET request.

Path Traversal
WAF: High

CVE-2004-1464

MEDIUM
5.90 CVSS 3.1

Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.

Uncontrolled Resource Consumption
WAF: Medium

CVE-2004-1553

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a processlogin action to album.asp, as reachable from the login action.

SQL Injection
WAF: High

CVE-2004-1777

MEDIUM
5.00 CVSS 2.0

A "range check error" in Skype for Windows before 0.98.0.28 allows local and remote attackers to cause a denial of service (application crash) via long command line arguments or a long callto:// URL, a different vulnerability than CVE-2004-1114.

Improper Input Validation
WAF: Medium

CVE-2004-1842

HIGH
8.80 CVSS 3.1

Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2004-1863

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allow remote attackers to inject arbitrary web script or HTML via (1) the u2uheader parameter in editprofile.php, the restrict parameter in (2) member.php, (3) misc.php, and (4) today.php, and (5) an arbitrary parameter in phpinfo.php.

Cross-Site Scripting (XSS)
WAF: High

CVE-2004-1995

MEDIUM
6.50 CVSS 3.1

Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2004-2182

HIGH
7.50 CVSS 2.0

Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information used by the session server.

Improper Authentication
WAF: Low

CVE-2004-2260

MEDIUM
5.00 CVSS 2.0

Opera Browser 7.23, and other versions before 7.50, updates the address bar as soon as the user clicks a link, which allows remote attackers to redirect to other sites via the onUnload attribute.

Open Redirect
WAF: Medium

CVE-2004-2262

HIGH
7.50 CVSS 2.0

ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.

Unrestricted File Upload
WAF: Medium

CVE-2004-2533

MEDIUM
5.00 CVSS 2.0

Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111.

Improper Input Validation
WAF: Medium

CVE-2004-2592

MEDIUM
5.00 CVSS 2.0

Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a modified client that asks the server to send data stored at a negative array offset, which is not handled when processing Configstrings and Baselines.

Improper Input Validation
WAF: Medium

CVE-2004-2596

MEDIUM
5.00 CVSS 2.0

Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections from the same IP address.

Improper Input Validation
WAF: Medium

CVE-2004-2649

MEDIUM
5.80 CVSS 2.0

Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of characters (e.g. spaces coded as "&#32") in the middle of the URL.

Improper Input Validation
WAF: Medium

CVE-2004-2686

HIGH
7.20 CVSS 2.0

Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure.

Path Traversal
WAF: High

CVE-2004-2688

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. NOTE: this issue might overlap vector 3 in CVE-2006-3358.

Cross-Site Scripting (XSS)
WAF: High

CVE-2004-2695

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows remote attackers to execute arbitrary SQL statements via the x_invoice_num parameter. NOTE: this issue might be related to CVE-2006-4267.

SQL Injection
WAF: High

CVE-2004-2701

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2004-2702

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter. NOTE: this might be the same vector as CVE-2006-6451.

Cross-Site Scripting (XSS)
WAF: High

CVE-2004-2704

MEDIUM
4.30 CVSS 2.0

Hastymail 1.0.1 and earlier (stable) and 1.1 and earlier (development) does not send the "attachment" parameter in the Content-Disposition field for attachments, which causes the attachment to be rendered inline by Internet Explorer when the victim clicks the download link, which facilitates cross-site scripting (XSS) and possibly other attacks.

Cross-Site Scripting (XSS)
WAF: High

CVE-2004-2706

MEDIUM
5.00 CVSS 2.0

Unspecified vulnerability in Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service (crash) via conference packets with error messages.

Improper Input Validation
WAF: Medium

CVE-2004-2715

HIGH
7.50 CVSS 2.0

edituser.php3 in PHPMyChat 0.14.5 allow remote attackers to bypass authentication and gain administrative privileges by setting the do_not_login parameter to false.

Improper Authentication
WAF: Low

CVE-2004-2716

HIGH
7.50 CVSS 2.0

Multiple SQL injection vulnerabilities in usersL.php3 in PHPMyChat 0.14.5 allow remote attackers to execute arbitrary SQL commands via the (1) sortBy, (2) sortOrder, (3) startReg, (4) U, (5) LastCheck , and (6) R parameters.

SQL Injection
WAF: High

CVE-2004-2717

LOW
2.60 CVSS 2.0

Multiple directory traversal vulnerabilities in admin.php3 in PHPMyChat 0.14.5 allow remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the (1) sheet and (2) What parameters.

Path Traversal
WAF: High

CVE-2004-2720

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in register.asp in Snitz Forums 2000 3.4.04 and earlier allows remote attackers to inject arbitrary web script or HTML via javascript events in the Email parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2004-2724

HIGH
7.10 CVSS 2.0

LionMax Software Chat Anywhere 2.72a allows remote attackers to cause a denial of service (server crash and client CPU consumption) via a username beginning with percent (%) followed by a null character.

Improper Authentication
WAF: Low

CVE-2004-2725

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in Aztek Forum 4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter in (a) search.php, (2) the email parameter in (b) subscribe.php, and (3) the return and (4) title parameters in (c) forum_2.php.

Cross-Site Scripting (XSS)
WAF: High

CVE-2004-2732

MEDIUM
4.30 CVSS 2.0

nbmember.cgi in Netbilling 2.0 allows remote attackers to obtain sensitive information via the cmd=test option, which can be leveraged to determine the access key.

OS Command Injection
WAF: High

CVE-2004-2734

HIGH
10.00 CVSS 2.0

webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access control to the WEB-INF folder.

Improper Authentication
WAF: Low

CVE-2004-2735

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in P4DB 2.01 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) SET_PREFERENCES parameter in SetPreferences.cgi; (2) BRANCH parameter in branchView.cgi; (3) FSPC and (4) COMPLETE parameters in changeByUsers.cgi; (5) FSPC, (6) LABEL, (7) EXLABEL, (8) STATUS, (9) MAXCH, (10) FIRSTCH, (11) CHOFFSETDISP, (12) SEARCHDESC, (13) SEARCH_INVERT, (14) USER, (15) GROUP, and (16) CLIENT parameters in changeList.cgi; (17) CH parameter in changeView.cgi; (18) USER parameter in clientList.cgi; (19) CLIENT parameter in clientView.cgi; (20) FSPC parameter in depotTreeBrowser.cgi; (21) FSPC parameter in depotStats.cgi; (22) FSPC, (23) REV, (24) ACT, (25) FSPC2, (26) REV2, (27) CH, and (28) CONTEXT parameters in fileDiffView.cgi; (29) FSPC and (30) REV parameters in fileDownLoad.cgi; (31) FSPC, (32) LISTLAB, and (33) SHOWBRANCH parameters in fileLogView.cgi; (34) FSPC and (35) LABEL parameters in fileSearch.cgi; (36) FSPC, (37) REV, and (38) FORCE parameters in fileViewer.cgi; (39) FSPC parameter in filesChangedSince.cgi; (40) GROUP parameter in groupView.cgi; (41) TYPE, (42) FSPC, and (43) REV parameters in htmlFileView.cgi; (44) CMD parameter in javaDataView.cgi; (45) JOBVIEW and (46) FLD parameters in jobList.cgi; (47) JOB parameter in jobView.cgi; (48) LABEL1 and (49) LABEL2 parameters in labelDiffView.cgi; (50) LABEL parameter in labelView.cgi; (51) FSPC parameter in searchPattern.cgi; (52) TYPE, (53) FSPC, and (54) REV parameters in specialFileView.cgi; (55) GROUPSONLY parameter in userList.cgi; or (56) USER parameter in userView.cgi.

Cross-Site Scripting (XSS)
WAF: High

CVE-2004-2736

MEDIUM
5.00 CVSS 2.0

Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cookie.

Improper Authentication
WAF: Low

CVE-2004-2737

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary SQL commands via the where parameter.

SQL Injection
WAF: High

CVE-2004-2738

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in check_user_id.php in ZeroBoard 4.1pl4 and earlier allows remote attackers to inject arbitrary web script or HTML via the user_id parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2004-2740

MEDIUM
4.30 CVSS 2.0

PHP remote file inclusion vulnerability in authform.inc.php in PHProjekt 4.2.3 and earlier allows remote attackers to include arbitrary PHP code via a URL in the path_pre parameter.

Code Injection
WAF: Medium

CVE-2004-2741

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the "help window" (help.php) in Horde Application Framework 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) module, (2) topic, or (3) module parameters.

Cross-Site Scripting (XSS)
WAF: High

CVE-2004-2742

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the report viewer in Crystal Enterprise 8.5, 9, and 10 allows remote attackers to inject arbitrary web script or HTML via script in the URL to a report (RPT) file.

Cross-Site Scripting (XSS)
WAF: High

CVE-2004-2745

HIGH
7.80 CVSS 2.0

Directory traversal vulnerability in Anteco Visual Technologies OwnServer 1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.

Path Traversal
WAF: High

CVE-2004-2746

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in adminlogin.asp in XTREME ASP Photo Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

SQL Injection
WAF: High

CVE-2004-2747

MEDIUM
4.00 CVSS 2.0

Directory traversal vulnerability in Pablo Software Solutions Quick 'n Easy FTP Server 1.77, and possibly earlier versions, allows remote authenticated users to determine the existence of arbitrary files via a .. (dot dot) in the DEL command, which triggers different error messages depending on whether the file exists or not.

Path Traversal
WAF: High

CVE-2004-2749

MEDIUM
4.30 CVSS 2.0

Directory traversal vulnerability in wra/public/wralogin in 2Wire Gateway, possibly as used in HomePortal and other product lines, allows remote attackers to read arbitrary files via a .. (dot dot) in the return parameter. NOTE: this issue was reported as XSS, but this might be a terminology error.

Path Traversal
WAF: High

CVE-2004-2750

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in browser.php in JBrowser 1.0 through 2.1 allows remote attackers to read arbitrary files via the directory parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Path Traversal
WAF: High

CVE-2004-2751

MEDIUM
6.80 CVSS 2.0

SQL injection vulnerability in the members_list module in PostNuke 0.726, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the sortby parameter.

SQL Injection
WAF: High

CVE-2004-2752

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote attackers to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action.

Cross-Site Scripting (XSS)
WAF: High

CVE-2004-2754

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the ID_MEMBER parameter to the (1) recentTopics and (2) welcome functions.

SQL Injection
WAF: High
Page 1 of 2 (88 CVEs)