Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-2567 SQL Injection and Cross-Site Scripting vulnerability in ReciPants
Multiple SQL injection vulnerabilities in ReciPants 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) user id, (2) recipe id, (3) category id, and (4) other ID number fields.
network
low complexity
recipants
7.5
2004-12-31 CVE-2004-2561 SQL Injection vulnerability in Internet Sofware Sciences Web+Center 4.0.1
Multiple SQL injection vulnerabilities in Internet Software Sciences Web+Center 4.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the ISS_TECH_CENTER_LOGIN cookie in search.asp and (2) one or more cookies in DoCustomerOptions.asp.
network
low complexity
internet-sofware-sciences
7.5
2004-12-31 CVE-2004-2560 Remote Arbitrary File Upload vulnerability in DokuWiki
DokuWiki before 2004-10-19, when used on a web server that permits execution based on file extension, allows remote attackers to execute arbitrary code by uploading a file with an appropriate extension such as ".php" or ".cgi".
network
low complexity
andreas-gohr
7.5
2004-12-31 CVE-2004-2559 Denial-Of-Service vulnerability in Dokuwiki
DokuWiki before 2004-10-19 allows remote attackers to access administrative functionality including (1) Mediaselectiondialog, (2) Recent changes, (3) feed, and (4) search, possibly due to the lack of ACL checks.
network
low complexity
andreas-gohr
7.5
2004-12-31 CVE-2004-2558 Product Unspecified Credential Impersonation vulnerability in IBM
Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manager 4.2, Configuration Manager for Automated Teller Machines 2.1.0, and IBM WebSphere Everyplace Server, Service Provider Offering for Multi-platforms 2.1.3 to 2.15 allow remote attackers to hijack sessions of authenticated users via unknown attack vectors involving certain cookies, aka "Potential Credential Impersonation Attack."
network
low complexity
ibm
7.5
2004-12-31 CVE-2004-2554 Local Privilege Escalation vulnerability in Novell Client Firewall 2.0
Novell Client Firewall (NCF) 2.0, as based on the Agnitum Outpost Firewall, allows local users to execute arbitrary code with SYSTEM privileges by opening the NCF tray icon and using the Help functionality to launch programs with SYSTEM privileges.
local
low complexity
novell
7.2
2004-12-31 CVE-2004-2551 SQL Injection vulnerability in Layton Technology Helpbox 3.0.1
Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the sys_comment_id parameter in editcommentenduser.asp, (2) the sys_suspend_id parameter in editsuspensionuser.asp, (3) the table parameter in export_data.asp, (4) the sys_analgroup parameter in manageanalgrouppreference.asp, (5) the sys_asset_id parameter in quickinfoassetrequests.asp, (6) the sys_eusername parameter in quickinfoenduserrequests.asp, and the sys_request_id parameter in (7) requestauditlog.asp, (8) requestcommentsenduser.asp, (9) selectrequestapplytemplate.asp, and (10) selectrequestlink.asp, resulting in an ability to create a new HelpBox user account and read, modify, or delete data from the backend database.
network
low complexity
layton-technology
7.5
2004-12-31 CVE-2004-2542 Undisclosed SQL Injection vulnerability in Dynix WebPac
Multiple SQL injection vulnerabilities in Dynix (formerly known as epixtech) WebPAC allow remote attackers to execute arbitrary SQL commands via unknown attack vectors, resulting in an ability to execute stored procedures, bypass login authentication, and cause an unspecified denial of service to backend databases.
network
low complexity
dynix
7.5
2004-12-31 CVE-2004-2539 Remote Undisclosed Denial Of Service vulnerability in Network Appliance Data Ontap and Netcache
Unknown vulnerability in Network Appliance NetCache 5.2 and Data ONTAP 6.0 allows remote attackers to cause a denial of service (panic and reboot) and possibly other impacts via unknown attack vectors, possibly related to unspecified worms, as identified by bug ID
network
low complexity
network-appliance
7.8
2004-12-31 CVE-2004-2536 Local IO Access Inheritance vulnerability in Linux Kernel
The exit_thread function (process.c) in Linux kernel 2.6 through 2.6.5 does not invalidate the per-TSS io_bitmap pointers if a process obtains IO access permissions from the ioperm function but does not drop those permissions when it exits, which allows other processes to access the per-TSS pointers, access restricted memory locations, and possibly gain privileges.
network
low complexity
linux
7.5