Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-2189 Cross-Site Scripting And SQL Injection vulnerability in DMXReady Site Chassis Manager
SQL injection vulnerability in DMXReady Site Chassis Manager allows remote attackers to execute arbitrary SQL commands via unknown vectors.
network
low complexity
dmxready
7.5
2004-12-31 CVE-2004-2188 Cross-Site Scripting And SQL Injection vulnerability in DMXReady Site Chassis Manager
Cross-site scripting (XSS) vulnerability in DMXReady Site Chassis Manager allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
dmxready
4.3
2004-12-31 CVE-2004-2187 Remote Input Validation vulnerability in Mediawiki 1.3.5
Unknown vulnerability in ImagePage for MediaWiki 1.3.5, related to "filename validation," has unknown impact and attack vectors.
network
low complexity
mediawiki
5.0
2004-12-31 CVE-2004-2186 Remote Input Validation vulnerability in Mediawiki 1.3.5
SQL injection vulnerability in MediaWiki 1.3.5 allows remote attackers to execute arbitrary SQL commands via SpecialMaintenance.
network
low complexity
mediawiki
7.5
2004-12-31 CVE-2004-2185 Remote Input Validation vulnerability in Mediawiki 1.3.5
Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki 1.3.5 allow remote attackers to execute arbitrary scripts and/or SQL queries via (1) the UnicodeConverter extension, (2) raw page views, (3) SpecialIpblocklist, (4) SpecialEmailuser, (5) SpecialMaintenance, and (6) ImagePage.
network
mediawiki
6.8
2004-12-31 CVE-2004-2184 Directory Traversal vulnerability in Yak! Chat Client FTP Server
Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write arbitrary files via "../" or "..\" sequences in commands such as (1) dir or (2) put.
network
low complexity
digicraft-software
6.4
2004-12-31 CVE-2004-2183 Remote Command Execution vulnerability in Wehelpbus 0.1
Unknown vulnerability in WeHelpBUS 0.1 allows remote attackers to execute arbitrary shell commands via the query string.
network
low complexity
wehelpbus
7.5
2004-12-31 CVE-2004-2182 Improper Authentication vulnerability in Macromedia Jrun 4.0/4.0Build61650
Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information used by the session server.
network
low complexity
macromedia CWE-287
7.5
2004-12-31 CVE-2004-2181 Remote Input Validation vulnerability in WowBB Forum 1.61/1.65
Multiple SQL injection vulnerabilities in WowBB Forum 1.61 allow remote attackers to execute arbitrary SQL commands via the (1) sort_by or (2) page parameters to view_user.php, or the (3) forum_id parameter to view_topic.php.
network
low complexity
wowbb
7.5
2004-12-31 CVE-2004-2180 Remote Input Validation vulnerability in Wowbb web Forum 1.61
Multiple cross-site scripting (XSS) vulnerabilities in WowBB Forum 1.61 allow remote attackers to inject arbitrary web script or HTML via the (1) country parameter to view_user.php, (2) show parameter to view_forum.php, (3) letter parameter to view_user.php, (4) highlight parameter to view_topic.php, (5) show parameter to index.php, (6) q parameter to search.php, (7) Referer header to admin.php, or the (8) user_email parameter to login.php.
network
wowbb
4.3