|
317761
|
- |
|
clearswift
|
mimesweeper_for_web
|
Clearswift MIMEsweeper For Web (a.k.a. WEBsweeper) 4.0 through 5.1 allows remote attackers to bypass filtering via a URL that does not include a .exe extension but returns an executable file.
|
NVD-CWE-Other
|
CVE-2005-4526
|
2024-02-14 10:17 |
2005-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
317762
|
- |
|
adp
|
adp_forum
|
ADP Forum 2.0 through 2.0.3 stores sensitive information in plaintext files under the web document root with insufficient access control, which allows remote attackers to obtain user credentials via …
|
NVD-CWE-Other
|
CVE-2005-4249
|
2024-02-14 10:17 |
2005-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
317763
|
- |
|
ethereal_group
|
ethereal
|
Stack-based buffer overflow in the dissect_ospf_v3_address_prefix function in the OSPF protocol dissector in Ethereal 0.10.12, and possibly other versions, allows remote attackers to execute arbitrar…
|
NVD-CWE-Other
|
CVE-2005-3651
|
2024-02-14 10:17 |
2005-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
317764
|
- |
|
redgraphic
|
sapid_cms
|
SAPID CMS before 1.2.3.03 allows remote attackers to bypass authentication via direct requests to the usr/system files (1) insert_file.php, (2) insert_image.php, (3) insert_link.php, (4) insert_qcfil…
|
CWE-287
Improper Authentication
|
CVE-2005-4006
|
2024-02-14 10:17 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
317765
|
- |
|
redgraphic
|
sapid_cms
|
Multiple unspecified vulnerabilities in SAPID CMS before 1.2.3.03, related to newly registered users and possibly authorization checks, have unknown impact and attack vectors involving (1) mvc/contro…
|
NVD-CWE-noinfo
|
CVE-2005-4007
|
2024-02-14 10:17 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
317766
|
- |
|
phpx
|
phpx
|
SQL injection vulnerability in auth.inc.php in PHPX 3.5.9 and earlier allows remote attackers to execute arbitrary SQL commands, bypass authentication, and upload arbitrary PHP code via the username …
|
NVD-CWE-Other
|
CVE-2005-3968
|
2024-02-14 10:17 |
2005-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
317767
|
- |
|
-
|
-
|
Directory traversal vulnerability in index.php in PHP Upload Center allows remote attackers to read arbitrary files via "../" sequences in the filename parameter.
|
NVD-CWE-Other
|
CVE-2005-3947
|
2024-02-14 10:17 |
2005-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
317768
|
- |
|
randshop
|
randshop
|
SQL injection vulnerability in themes/kategorie/index.php in Randshop allows remote attackers to execute arbitrary SQL commands via the (1) kategorieid and (2) katid parameters.
|
NVD-CWE-Other
|
CVE-2005-3924
|
2024-02-14 10:17 |
2005-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
317769
|
- |
|
orbitscripts
|
smartppc_pro
|
Multiple cross-site scripting (XSS) vulnerabilities in SmartPPC Pro allow remote attackers to inject arbitrary web script or HTML via the username parameter in (1) directory.php, (2) frames.php, and …
|
NVD-CWE-Other
|
CVE-2005-3814
|
2024-02-14 10:17 |
2005-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
317770
|
- |
|
phppost
|
phppost
|
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Post (PHPp) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the subject in a post, or the user parameter to (2) pr…
|
CWE-79
Cross-site Scripting
|
CVE-2005-3770
|
2024-02-14 10:17 |
2005-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|