NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 72421 | CVE-2004-2044 | PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER['PHP_SELF'] to identify the calling script, which allows remote attackers to directly access scripts, obtain path information via a PHP error message, and possibly gain access, as demonstrated using an HTTP request that contains the "admin.php" string. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 72422 | CVE-2004-2045 | The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of service (device reboot) via an HTTP request with a long username. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72423 | CVE-2004-2046 | Unknown vulnerability in APC PowerChute Business Edition 6.0 through 7.0.1 allows remote attackers to cause a denial of service via unknown attack vectors. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72424 | CVE-2004-2047 | Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the pathext parameter. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72425 | CVE-2004-2048 | radmin in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier starts a process port 25072 that can be accessed with a default "jstwo" password, which allows remote attackers to gain access. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View |
Page 2037 of 17672, showing 5 records out of 88360 total, starting on record 10181, ending on 10185