Latest CVE Feed
-
7.5
HIGHCVE-2004-1934
PHP remote file inclusion vulnerability in affich.php in Gemitel 3.50 allows remote attackers to execute arbitrary PHP code via the base parameter.... Read more
Affected Products : gemitel- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1038
The AGate component for SAP Internet Transaction Server (ITS) allows remote attackers to obtain sensitive information via a ~command parameter with an AgateInstallCheck value, which provides a list of installed DLLs and full pathnames.... Read more
Affected Products : internet_transaction_server- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1037
Format string vulnerability in the WGate component for SAP Internet Transaction Server (ITS) allows remote attackers to execute arbitrary code via a high "trace level."... Read more
Affected Products : internet_transaction_server- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1579
SAP GUI (Sapgui) 4.6D allows remote attackers to cause a denial of service (crash) via a connection to a high-numbered port, which generates an "unknown connection data" error.... Read more
Affected Products : sapgui- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-1034
The RPM installation of SAP DB 7.x creates the (1) dbmsrv or (2) lserver programs with world-writable permissions, which allows local users to gain privileges by modifying those programs.... Read more
Affected Products : sap_db- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0107
The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.... Read more
- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0151
Unknown vulnerability in xitalk 1.1.11 and earlier allows local users to execute arbitrary commands.... Read more
Affected Products : xitalk- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0150
Buffer overflow in the getaddrinfo function in Python 2.2 before 2.2.2, when IPv6 support is disabled, allows remote attackers to execute arbitrary code via an IPv6 address that is obtained using DNS.... Read more
Affected Products : python- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1578
The default installation of SAP R/3, when using Oracle and SQL*net V2 3.x, 4.x, and 6.10, allows remote attackers to obtain arbitrary, sensitive SAP data by directly connecting to the Oracle database and executing queries against the database, which is no... Read more
Affected Products : sap_r_3- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1577
SAP R/3 2.0B to 4.6D installs several clients with default users and passwords, which allows remote attackers to gain privileges via the (1) SAP*, (2) SAPCPIC, (3) DDIC, (4) EARLYWATCH, or (5) TMSADM accounts.... Read more
Affected Products : sap_r_3- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1576
lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users to gain privileges with a malicious lserversrv that is called from a directory that has a symlink to the lserver prog... Read more
Affected Products : sap_db- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1936
ZoneAlarm Pro 4.5.538.001 and possibly other versions allows remote attackers to bypass e-mail protection via attachments whose names contain certain non-English characters.... Read more
Affected Products : zonealarm- Published: Apr. 14, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1939
Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows remote attackers to inject arbitrary web script or HTML via double encoded slashes (%252F) in the key parameter.... Read more
Affected Products : zaep_antispam- Published: Apr. 14, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1944
Eudora 6.1 and 6.0.3 for Windows allows remote attackers to cause a denial of service (crash) via a deeply nested multipart MIME message.... Read more
Affected Products : eudora- Published: Apr. 14, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-1758
BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.... Read more
Affected Products : weblogic_server- Published: Apr. 13, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1929
SQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass authentication and gain access by injecting base64-encoded SQL code into the user parameter.... Read more
Affected Products : php-nuke- Published: Apr. 13, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1756
BEA WebLogic Server and WebLogic Express 8.1 SP2 and earlier, and 7.0 SP4 and earlier, when using 2-way SSL with a custom trust manager, may accept a certificate chain even if the trust manager rejects it, which allows remote attackers to spoof other user... Read more
Affected Products : weblogic_server- Published: Apr. 13, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1932
SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.... Read more
Affected Products : php-nuke- Published: Apr. 12, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1933
Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass access controls and read unauthorized messages.... Read more
Affected Products : ux- Published: Apr. 12, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1925
Multiple SQL injection vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sort_mode parameter in (1) tiki-usermenu.php, (2) tiki-list_file_gallery.php, (3) tiki-directory_ran... Read more
Affected Products : tikiwiki_cms\/groupware- Published: Apr. 12, 2004
- Modified: Apr. 03, 2025