|
346281
|
- |
|
pegasi_web_server
|
pegasi_web_server
|
Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the web root via a .. (dot dot) directly after the initial '/' (slash) in the URI.
|
NVD-CWE-Other
|
CVE-2004-2617
|
2017-07-20 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346282
|
- |
|
pegasi_web_server
|
pegasi_web_server
|
Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the URI, directly after the initial '/' (slash).
|
NVD-CWE-Other
|
CVE-2004-2618
|
2017-07-20 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346283
|
- |
|
paul_l_daniels
|
ripmime
|
ripMIME 1.3.2.3 and earlier allows remote attackers to bypass e-mail protection via a base64 MIME encoded attachment containing invalid characters that are not properly extracted.
|
NVD-CWE-Other
|
CVE-2004-2619
|
2017-07-20 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346284
|
- |
|
nortel
|
contivity
|
Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway certificate until after a dialog box has been displayed to the user, which creates…
|
NVD-CWE-Other
|
CVE-2004-2621
|
2017-07-20 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346285
|
- |
|
altiris
|
deployment_server_extension_for_ibm_director
|
AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrato…
|
NVD-CWE-Other
|
CVE-2004-2622
|
2017-07-20 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346286
|
- |
|
matthew_skala
|
rippy_the_aggregator
|
Unknown vulnerability in Rippy the Aggregator before 0.10, when register_globals is enabled, has unknown attack vectors and impact, possibly related to the "user-controlled filter."
|
NVD-CWE-Other
|
CVE-2004-2623
|
2017-07-20 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346287
|
- |
|
wackowiki
|
wackowiki
|
Cross-site scripting (XSS) vulnerability in "TextSearch" in WackoWiki 3.5 allows remote attackers to inject arbitrary web script or HTML via the "phrase" parameter.
|
NVD-CWE-Other
|
CVE-2004-2624
|
2017-07-20 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346288
|
- |
|
outblaze
|
outblaze_email
|
Cross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTML via Javascript in an attribute of an IMG tag.
|
NVD-CWE-Other
|
CVE-2004-2625
|
2017-07-20 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346289
|
- |
|
siemens
|
s55
|
GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SMS messages by overlaying a confirmation message with a malicious message.
|
NVD-CWE-Other
|
CVE-2004-2626
|
2017-07-20 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346290
|
- |
|
-
|
-
|
Java 2 Micro Edition (J2ME) does not properly validate bytecode, which allows remote attackers to escape the Kilobyte Virtual Machine (KVM) sandbox and execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2004-2627
|
2017-07-20 10:29 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|