|
347571
|
- |
|
megabook
|
megabook
|
Multiple cross-site scripting (XSS) vulnerabilities in admin.cgi in MegaBook 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) entryid or (2) password parameter.
|
NVD-CWE-Other
|
CVE-2005-1494
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347572
|
- |
|
oracle
|
application_server oracle10g oracle9i
|
Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object, which makes it easier for attackers to escape detection.
|
NVD-CWE-Other
|
CVE-2005-1495
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347573
|
- |
|
oracle
|
application_server oracle10g oracle9i
|
Applying patchset 10.1.0.4 is fixing this issue for Oracle 10g. Oracle 9i is still vulnerable.
|
NVD-CWE-Other
|
CVE-2005-1495
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347574
|
- |
|
oracle
|
application_server oracle10g
|
The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.
|
NVD-CWE-Other
|
CVE-2005-1496
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347575
|
- |
|
oracle
|
application_server oracle10g
|
Applying patchset 10.1.0.4 is fixing this issue.
|
NVD-CWE-Other
|
CVE-2005-1496
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347576
|
- |
|
mywebland
|
mybloggie
|
index.php in myBloggie 2.1.1 allows remote attackers to obtain sensitive information via an invalid post_id parameter, which reveals the path in an error message.
|
NVD-CWE-Other
|
CVE-2005-1497
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347577
|
- |
|
mywebland
|
mybloggie
|
Multiple cross-site scripting (XSS) vulnerabilities in myBloggie 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) year parameter in viewmode.php, or the (2) cat_id, (3)…
|
NVD-CWE-Other
|
CVE-2005-1498
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347578
|
- |
|
mywebland
|
mybloggie
|
Download newest myBloggie from http://mywebland.com/
|
NVD-CWE-Other
|
CVE-2005-1498
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347579
|
- |
|
mywebland
|
mybloggie
|
delcomment.php in myBloggie 2.1.1 allows remote attackers to delete arbitrary comments by modifying the comment_id parameter.
|
NVD-CWE-Other
|
CVE-2005-1499
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347580
|
- |
|
mywebland
|
mybloggie
|
Multiple SQL injection vulnerabilities in myBloggie 2.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the keyword parameter in search.php; or (2) the date_no parameter in viewdat…
|
CWE-89
SQL Injection
|
CVE-2005-1500
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|