|
278371
|
- |
|
lyris_technologies_inc
|
listmanager
|
The TCLHTTPd service in Lyris ListManager before 8.9b allows remote attackers to obtain source code for arbitrary .tml (TCL) files via (1) a request with a trailing null byte (%00), which might also …
|
NVD-CWE-Other
|
CVE-2005-4147
|
2018-10-20 00:40 |
2005-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278372
|
- |
|
lyris_technologies_inc
|
listmanager
|
Lyris ListManager 8.5, and possibly other versions before 8.8, includes sensitive information in the env hidden variable, which allows remote attackers to obtain information such as the installation …
|
NVD-CWE-Other
|
CVE-2005-4148
|
2018-10-20 00:40 |
2005-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278373
|
- |
|
lyris_technologies_inc
|
listmanager
|
Lyris ListManager 8.8 through 8.9b allows remote attackers to obtain sensitive information by causing errors in TML scripts, such as via direct requests, which leaks the installation path, SQL querie…
|
NVD-CWE-Other
|
CVE-2005-4149
|
2018-10-20 00:40 |
2005-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278374
|
- |
|
pgp
|
desktop
|
The Wipe Free Space utility in PGP Desktop Home 8.0 and Desktop Professional 9.0.3 Build 2932 and earlier does not clear file slack space in the last cluster for the file, which allows local users to…
|
NVD-CWE-Other
|
CVE-2005-4151
|
2018-10-20 00:40 |
2005-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278375
|
- |
|
soti
|
pocket_controller-professional
|
Soti Pocket Controller-Professional 5.0 allows remote attackers to turn off, reboot, or hard reset a PDA via a series of initialization, command, and reset packets sent to port 5492.
|
NVD-CWE-Other
|
CVE-2005-4152
|
2018-10-20 00:40 |
2005-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278376
|
- |
|
-
|
-
|
Directory traversal vulnerability in getdox.php in Torrential 1.2 allows remote attackers to read arbitrary files via "../" sequences in the query string argument.
|
NVD-CWE-Other
|
CVE-2005-4160
|
2018-10-20 00:40 |
2005-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278377
|
- |
|
insyde
|
insyde_bios
|
Insyde BIOS V190 does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memor…
|
NVD-CWE-Other
|
CVE-2005-4175
|
2018-10-20 00:40 |
2005-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278378
|
- |
|
-
|
-
|
AWARD Bios Modular 4.50pg does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physi…
|
NVD-CWE-Other
|
CVE-2005-4176
|
2018-10-20 00:40 |
2005-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278379
|
- |
|
internet_scout internet_scout_project
|
scout_portal_toolkit
|
Multiple SQL injection vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the ParentId parameter in SPT--BrowseResources.…
|
CWE-89
SQL Injection
|
CVE-2005-4195
|
2018-10-20 00:40 |
2005-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278380
|
- |
|
nortel
|
ssl_vpn
|
tunnelform.yaws in Nortel SSL VPN 4.2.1.6 allows remote attackers to execute arbitrary commands via a link in the a parameter, which is executed with extra privileges in a cryptographically signed Ja…
|
NVD-CWE-Other
|
CVE-2005-4197
|
2018-10-20 00:40 |
2005-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|