2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-1399Directory traversal vulnerability in the Attachment module 2.3.10 and earlier for phpBB allows remote attackers to read ...
CVE-2004-1400The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unaut...
CVE-2004-1401SQL injection vulnerability in verify.asp in Asp-rider allows remote attackers to execute arbitrary SQL statements and b...
CVE-2004-1402SQL injection vulnerability in iWebNegar allows remote attackers to execute arbitrary SQL commands via (1) the string pa...
CVE-2004-1403PHP remote file inclusion vulnerability in index.php in GNUBoard 3.39 and earlier allows remote attackers to execute arb...
CVE-2004-1404Attachment Mod 2.3.10 module for phpBB, when used with Apache mod_mime, does not properly handle files with multiple fil...
CVE-2004-1405MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, su...
CVE-2004-1406SQL injection vulnerability in ikonboard.cgi in Ikonboard 3.1.0 through 3.1.3 allows remote attackers to inject arbitrar...
CVE-2004-1407Multiple directory traversal vulnerabilities in singapore Image Gallery Web Application 0.9.10 allow remote attackers to...
CVE-2004-1408The addImage method for admin.class.php in Image Gallery Web Application 0.9.10 does not properly check filenames, which...
CVE-2004-1409Multiple cross-site scripting vulnerabilities in Image Gallery Web Application 0.9.10 allow remote attackers to inject a...
CVE-2004-1410Cross-site scripting (XSS) vulnerability in Gadu-Gadu build 155 and earlier allows remote attackers to inject arbitrary ...
CVE-2004-1411Gadu-Gadu build 155 and earlier allows remote attackers to cause a denial of service (infinite loop) via a message that ...
CVE-2004-1412Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.x allows remote attackers to inject arbitrary...
CVE-2004-1413Multiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands v...
CVE-2004-1414Gadu-Gadu 6.1 build 156 allows remote attackers to cause a denial of service (application hang) via a message that conta...
CVE-2004-1415SQL injection vulnerability in (1) disp_album.php and possibly (2) disp_img.php in 2Bgal 2.4 and 2.5.1 allows remote att...
CVE-2004-1416pnxr3260.dll in the RealOne 2.0 build 6.0.11.868 browser plugin, as used in Internet Explorer, allows remote attackers t...
CVE-2004-1417Cross-site scripting (XSS) vulnerability in login.php in PsychoStats 2.2.4 Beta and earlier allows remote attackers to i...
CVE-2004-1418Cross-site scripting (XSS) vulnerability in WPKontakt 3.0.1 and earlier allows remote attackers to inject arbitrary web ...
CVE-2004-1419PHP remote file inclusion vulnerability in ZeroBoard 4.1pl4 and earlier allows remote attackers to execute arbitrary PHP...
CVE-2004-1420Multiple cross-site scripting (XSS) vulnerabilities in header.php in WHM AutoPilot 2.4.6.5 and earlier allow remote atta...
CVE-2004-1421Multiple PHP remote file inclusion vulnerabilities (1) step_one.php, (2) step_one_tables.php, (3) step_two_tables.php in...
CVE-2004-1422WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php s...
CVE-2004-2339HIGH8.4Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege to execute arbitrar...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now