NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
72401  CVE-2004-2024  The distribution of Zen Cart 1.1.4 before patch 2 includes certain debugging code in the Admin password retrieval functionality, which allows attackers to gain administrative privileges via password_forgotten.php.    7.5  High  2016-12-20  2008-09-05  View
72402  CVE-2004-2025  SQL injection vulnerability in application_top.php for Zen Cart 1.1.3 before patch 2 may allow remote attackers to execute arbitrary SQL commands via the products_id parameter.    7.5  High  2016-12-20  2008-09-05  View
72403  CVE-2004-2026  Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format string specifiers in syslog messages.    7.5  High  2017-07-18  2017-07-10  View
72404  CVE-2004-2027  Buffer overflow in Icecast 2.0.0 and earlier allows remote attackers to cause a denial of service (crash) via a long Basic Authorization header that triggers an out-of-bounds read.    Medium  2017-07-18  2017-07-10  View
72405  CVE-2004-2028  Cross-site scripting (XSS) vulnerability in stats.php in e107 allows remote attackers to inject arbitrary web script or HTML via the referer parameter to log.php.    4.3  Medium  2017-07-18  2017-07-10  View

Page 2033 of 17672, showing 5 records out of 88360 total, starting on record 10161, ending on 10165

Actions