Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29929 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-1584 1 Wordpress 1 Wordpress 2026-06-16 5.0 MEDIUM N/A
CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter.
CVE-2004-1583 1 Tridcomm 1 Tridcomm 2026-06-16 6.4 MEDIUM N/A
Directory traversal vulnerability in the FTP server in TriDComm 1.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in FTP commands such as (1) DIR, (2) GET, or (3) PUT.
CVE-2004-1582 1 Blackboard Internet Newsboard System 1 Blackboard Internet Newsboard System 2026-06-16 7.5 HIGH N/A
PHP remote file inclusion vulnerability in BlackBoard 1.5.1 allows remote attackers to execute arbitrary PHP code by modifying the libpath parameter (incorrectly called "libpach") to reference a URL on a remote web server that contains _more.php, as demonstrated using checkdb.inc.php.
CVE-2004-1581 1 Blackboard 1 Blackboard 2026-06-16 5.0 MEDIUM N/A
BlackBoard 1.5.1 allows remote attackers to gain sensitive information via a direct request to (1) checkdb.inc.php, (2) admin.inc.php or (3) cp.inc.php, which reveals the path in a PHP error message.
CVE-2004-1580 1 Devellion 1 Cubecart 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
CVE-2004-1579 1 Devellion 1 Cubecart 2026-06-16 5.0 MEDIUM N/A
index.php in CubeCart 2.0.1 allows remote attackers to gain sensitive information via an HTTP request with an invalid cat_id parameter, which reveals the full path in a PHP error message.
CVE-2004-1578 1 Invision Power Services 1 Invision Power Board 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header.
CVE-2004-1577 1 Greg Donald 1 Phplinks 2026-06-16 5.0 MEDIUM N/A
index.php in PHP Links allows remote attackers to gain sensitive information via an invalid show parameter, which reveals the full path in an error message.
CVE-2004-1576 1 Megalo 1 Judge Dredd Dredd Vs. Death 2026-06-16 5.0 MEDIUM N/A
Format string vulnerability in Judge Dredd: Dredd vs. Death 1.01 and earlier allows remote attackers to cause a denial of service (application crash) via format string specifiers in a chat message.
CVE-2004-1575 1 Apache 1 Xerces-c\+\+ 2026-06-16 5.0 MEDIUM N/A
The XML parser in Xerces-C++ 2.5.0 allows remote attackers to cause a denial of service (CPU consumption) via XML attributes in a crafted XML document.
CVE-2004-1574 1 Vypress 1 Vypres Messenger 2026-06-16 7.5 HIGH N/A
Buffer overflow in Vypress Messenger 3.5.1 and earlier allows remote attackers to execute arbitrary code via a message with a long first field.
CVE-2004-1573 2 Aj-fork, Cutephp 2 Aj-fork, Cutenews 2026-06-16 7.2 HIGH N/A
The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbitrary PHP code and gain privileges as the administrator.
CVE-2004-1572 1 Aj-fork 1 Aj-fork 2026-06-16 5.0 MEDIUM N/A
AJ-Fork 167 does not restrict access to directories such as (1) data, (2) inc, (3) plugins, (4) skins, or (5) tools, which allows remote attackers to list files in those directories via a direct HTTP request.
CVE-2004-1571 1 Aj-fork 1 Aj-fork 2026-06-16 5.0 MEDIUM N/A
AJ-Fork 167 allows remote attackers to gain sensitive information via a direct request to (1) auto-acronyms.php, (2) auto-archive.php, (3) ount-article-views.php, (4) kses.php, (5) custom-quick-tags.php, (6) disable-all-comments.php, (7) easy-date-format.php, (8) enable-disable-comments.php, (9) filter-by-author.php, (10) format-switcher.php, (11) long-to-short.php, (12) prospective-posting.php, or (13) sort-by-xfield.php, which displays the full path in an error message.
CVE-2004-1570 1 Eaden Mckee 1 Bblog 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in bBlog 0.7.2 and 0.7.3 allows remote attackers to execute arbitrary SQL commands via the p parameter.
CVE-2004-1569 1 Illustrate 2 Dbpoweramp Audio Player, Dbpoweramp Music Converter 2026-06-16 4.0 MEDIUM N/A
Buffer overflow in (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe in dBpowerAMP Audio Player 2.0 and dbPowerAmp Music Converter 10.0 allows remote attackers to cause a denial of service or execute arbitrary code via a .pls or .m3u playlist that contains long File1 (filename) fields.
CVE-2004-1568 1 Parachat 1 Parachat Server 2026-06-16 5.0 MEDIUM N/A
Directory traversal vulnerability in ParaChat Server 5.5 allows remote attackers to read arbitrary files via a ..%5C (hex-encoded dot dot) in the URL.
CVE-2004-1567 1 Silent-storm 1 Silent-storm Portal 2026-06-16 7.5 HIGH N/A
profile.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to gain privileges by setting the mail parameter to 1, which is the value for an administrator.
CVE-2004-1566 1 Silent-storm 1 Silent-storm Portal 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to execute arbitrary web script or HTML via the module parameter.
CVE-2004-1565 1 W-agora 1 W-agora 2026-06-16 5.0 MEDIUM N/A
list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.