Show filters
545 Total Results
Displaying 511-520 of 545
Sort by:
Attacker Value
Unknown

CVE-2004-2617

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the web root via a .. (dot dot) directly after the initial '/' (slash) in the URI.
0
Attacker Value
Unknown

CVE-2004-2516

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET command with a large number of "./" sequences followed by "../" sequences.
0
Attacker Value
Unknown

CVE-2004-2119

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Tiny Server 1.1 allows remote attackers to inject arbitrary web script or HTML via the URL.
0
Attacker Value
Unknown

CVE-2004-2408

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Linux VServer 1.27 and earlier, 1.3.9 and earlier, and 1.9.1 and earlier shares /proc permissions across all virtual and host servers, which allows local users with the ability to set permissions in /proc to obtain system information or cause a denial of service on other virtual servers or the host server.
0
Attacker Value
Unknown

CVE-2004-2618

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the URI, directly after the initial '/' (slash).
0
Attacker Value
Unknown

CVE-2004-2327

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Vizer Web Server 1.9.1 allows remote attackers to cause a denial of service (crash) via multiple malformed requests including (1) requests without GET, (2) GET requests without HTTP, (3) or long GET requests.
0
Attacker Value
Unknown

CVE-2004-2613

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Unspecified vulnerability in procfs in the Linux-VServer stable branch for the 2.4 kernel before 1.23 and Linux-VServer development branch for the 2.4 kernel before 1.3.5 has unspecified impact and attack vectors, related to "write access to specific proc entries from a vserver context", a different vulnerability than CVE-2004-2408.
0
Attacker Value
Unknown

CVE-2004-0255

Disclosure Date: November 23, 2004 (last updated February 22, 2025)
Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow.
0
Attacker Value
Unknown

CVE-2004-0342

Disclosure Date: November 23, 2004 (last updated February 22, 2025)
WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error.
Attacker Value
Unknown

CVE-2004-0287

Disclosure Date: November 23, 2004 (last updated February 22, 2025)
Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow.
0