|
356451
|
5.0 |
MEDIUM
|
-
|
-
|
Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to obtain the full path of the application via an invalid mode parameter to community.html, which leaks the path in an error …
|
NVD-CWE-Other
|
CVE-2005-4373
|
2008-09-20 13:43 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356452
|
4.3 |
MEDIUM
|
libertas_solutions
|
libertas_enterprise_cms
|
Cross-site scripting (XSS) vulnerability in search/index.php in Libertas Enterprise CMS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page_search parameter.
|
NVD-CWE-Other
|
CVE-2005-4399
|
2008-09-20 13:43 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356453
|
4.3 |
MEDIUM
|
liferay
|
liferay_portal_enterprise
|
Cross-site scripting (XSS) vulnerability in downloads/portal_ent in Liferay Portal Enterprise 3.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) _77_struts_a…
|
NVD-CWE-Other
|
CVE-2005-4400
|
2008-09-20 13:43 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356454
|
4.3 |
MEDIUM
|
lutece
|
lutece
|
Cross-site scripting (XSS) vulnerability in Lutece 1.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the query parameter.
|
NVD-CWE-Other
|
CVE-2005-4401
|
2008-09-20 13:43 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356455
|
7.5 |
HIGH
|
qcm
|
marwel
|
SQL injection vulnerability in index.php in Marwel 2.7 and earlier allows remote attackers to execute arbitrary SQL commands via the show parameter.
|
NVD-CWE-Other
|
CVE-2005-4403
|
2008-09-20 13:43 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356456
|
7.5 |
HIGH
|
tmc_visionpool
|
mercury_cms
|
SQL injection vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.
|
NVD-CWE-Other
|
CVE-2005-4406
|
2008-09-20 13:43 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356457
|
4.3 |
MEDIUM
|
tmc_visionpool
|
mercury_cms
|
Cross-site scripting (XSS) vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) content and (2) criteria parameters.
|
NVD-CWE-Other
|
CVE-2005-4407
|
2008-09-20 13:43 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356458
|
7.5 |
HIGH
|
pc_media
|
miraserver
|
Multiple SQL injection vulnerabilities in Miraserver 1.0 RC4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) id parameter to newsitem…
|
NVD-CWE-Other
|
CVE-2005-4408
|
2008-09-20 13:43 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356459
|
4.3 |
MEDIUM
|
mmbase
|
mmbase
|
Cross-site scripting (XSS) vulnerability in MMBase 1.7.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.
|
NVD-CWE-Other
|
CVE-2005-4409
|
2008-09-20 13:43 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356460
|
4.3 |
MEDIUM
|
nqcontent
|
nqcontent
|
Cross-site scripting (XSS) vulnerability in NQcontent 3 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the text parameter.
|
NVD-CWE-Other
|
CVE-2005-4410
|
2008-09-20 13:43 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356461
|
7.5 |
HIGH
|
cs-cart
|
cs-cart
|
SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php.
|
NVD-CWE-Other
|
CVE-2005-4429
|
2008-09-20 13:43 |
2005-12-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356462
|
7.5 |
HIGH
|
-
|
-
|
SQL injection vulnerability in LogicBill 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) __mode and (2) __id parameters to helpdesk.php.
|
NVD-CWE-Other
|
CVE-2005-4430
|
2008-09-20 13:43 |
2005-12-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356463
|
7.5 |
HIGH
|
wowbb
|
wowbb
|
SQL injection vulnerability in WowBB 1.65 allows remote attackers to execute arbitrary SQL commands via the q parameter to search.php. NOTE: the view_user.php/sort_by vector is already covered by CVE…
|
NVD-CWE-Other
|
CVE-2005-4431
|
2008-09-20 13:43 |
2005-12-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356464
|
6.8 |
MEDIUM
|
alkacon
|
opencms
|
Cross-site scripting (XSS) vulnerability in OpenCms 6.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.
|
NVD-CWE-Other
|
CVE-2005-4475
|
2008-09-20 13:43 |
2005-12-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356465
|
6.8 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in papaya CMS 4.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the bab[searchfor] parameter.
|
NVD-CWE-Other
|
CVE-2005-4477
|
2008-09-20 13:43 |
2005-12-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356466
|
6.8 |
MEDIUM
|
plexcor
|
plexcor_cms
|
Cross-site scripting (XSS) vulnerability in Plexcor CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.
|
NVD-CWE-Other
|
CVE-2005-4480
|
2008-09-20 13:43 |
2005-12-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356467
|
4.3 |
MEDIUM
|
text-e
|
text-e_cms
|
Cross-site scripting (XSS) vulnerability in Text-e 1.6.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.
|
NVD-CWE-Other
|
CVE-2005-4498
|
2008-09-20 13:43 |
2005-12-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356468
|
4.3 |
MEDIUM
|
waxtrapp
|
waxtrapp
|
Cross-site scripting (XSS) vulnerability in WAXTRAPP 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.
|
NVD-CWE-Other
|
CVE-2005-4512
|
2008-09-20 13:43 |
2005-12-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356469
|
4.3 |
MEDIUM
|
ooapp
|
ooapp_guestbook
|
Cross-site scripting (XSS) vulnerability in home.php in OoApp Guestbook 2.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
NVD-CWE-Other
|
CVE-2005-4598
|
2008-09-20 13:43 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356470
|
7.5 |
HIGH
|
phpoutsourcing
|
zorum
|
SQL injection vulnerability in index.php in phpoutsourcing Zorum Forum 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the rollid parameter in the showhtmllist method.
|
NVD-CWE-Other
|
CVE-2005-4619
|
2008-09-20 13:43 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356471
|
4.3 |
MEDIUM
|
jelsoft
|
vbulletin
|
Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which th…
|
NVD-CWE-Other
|
CVE-2005-4621
|
2008-09-20 13:43 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356472
|
7.5 |
HIGH
|
help_desk_point_software
|
helpdeskpoint
|
SQL injection vulnerability in index.php in HelpDeskPoint 2.38 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.
|
NVD-CWE-Other
|
CVE-2005-4628
|
2008-09-20 13:43 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356473
|
7.5 |
HIGH
|
smbcms
|
smbcms
|
SQL injection vulnerability in SMBCMS 2.1 allows remote attackers to execute arbitrary SQL commands via unspecified search parameters.
|
NVD-CWE-Other
|
CVE-2005-4629
|
2008-09-20 13:43 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356474
|
7.5 |
HIGH
|
ryan_lath
|
zina
|
SQL injection vulnerability in index.php in Zina 0.12.07 and earlier allows remote attackers to execute arbitrary SQL commands via the p parameter.
|
NVD-CWE-Other
|
CVE-2005-4631
|
2008-09-20 13:43 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356475
|
7.5 |
HIGH
|
vote_pro
|
vote_pro
|
SQL injection vulnerability in poll_frame.php in Vote! Pro 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the poll_id parameter.
|
CWE-89
SQLインジェクション
|
CVE-2005-4632
|
2008-09-20 13:43 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356476
|
7.5 |
HIGH
|
activecampaign
|
supporttrio
|
SQL injection vulnerability in index.php in ActiveCampaign SupportTrio 1.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the provenance of this information …
|
NVD-CWE-Other
|
CVE-2005-4634
|
2008-09-20 13:43 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356477
|
7.5 |
HIGH
|
class-1
|
poll_software
|
SQL injection vulnerability in index.php in class-1 Poll Software 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) pollid or (2) previouspoll parameters.
|
NVD-CWE-Other
|
CVE-2005-4640
|
2008-09-20 13:43 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356478
|
7.5 |
HIGH
|
eazycms
|
eazycms
|
SQL injection vulnerability in home.php in eazyCMS 2.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.
|
NVD-CWE-Other
|
CVE-2005-4641
|
2008-09-20 13:43 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356479
|
6.4 |
MEDIUM
|
alstrasoft
|
epay
|
SQL injection vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the pmodule parameter.
|
NVD-CWE-Other
|
CVE-2005-4651
|
2008-09-20 13:43 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356480
|
7.5 |
HIGH
|
sysbotz
|
systems_panel
|
Multiple SQL injection vulnerabilities in Sysbotz Systems Panel 1.0.6 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the cid parameter in knowledgebase/index.php, (2) th…
|
NVD-CWE-Other
|
CVE-2005-4719
|
2008-09-20 13:43 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356481
|
5.0 |
MEDIUM
|
nelogic_technologies
|
nephp_publisher
|
Multiple SQL injection vulnerabilities in index.php in NeLogic Nephp Publisher 4.5.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) nnet_catid parameters.
|
NVD-CWE-Other
|
CVE-2005-4743
|
2008-09-20 13:43 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356482
|
5.0 |
MEDIUM
|
sergids
|
top_music_module
|
Multiple SQL injection vulnerabilities in SergiDs Top Music module 3.0 PR3 and earlier for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the (1) idartist, (2) idsong, and (3) …
|
NVD-CWE-Other
|
CVE-2005-4781
|
2008-09-20 13:43 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356483
|
4.3 |
MEDIUM
|
locazo
|
locazolist_classifieds
|
Cross-site scripting (XSS) vulnerability in searchdb.asp in LocazoList 1.03c and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.
|
NVD-CWE-Other
|
CVE-2005-4205
|
2008-09-20 13:42 |
2005-12-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356484
|
7.5 |
HIGH
|
php_web_scripts
|
link_up_gold
|
SQL injection vulnerability in poll.php in Link Up Gold 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the number parameter.
|
NVD-CWE-Other
|
CVE-2005-4230
|
2008-09-20 13:42 |
2005-12-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356485
|
7.5 |
HIGH
|
php_web_scripts
|
ad_manager_pro
|
SQL injection vulnerability in advertiser_statistic.php in Ad Manager Pro 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ad_number parameter.
|
NVD-CWE-Other
|
CVE-2005-4233
|
2008-09-20 13:42 |
2005-12-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356486
|
7.5 |
HIGH
|
vcd-db
|
vcd-db
|
SQL injection vulnerability in search.php in VCD-db 0.98 and earlier allows remote attackers to execute arbitrary SQL commands via the by parameter.
|
NVD-CWE-Other
|
CVE-2005-4240
|
2008-09-20 13:42 |
2005-12-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356487
|
4.3 |
MEDIUM
|
edatcat
|
edatcat_shopping_cart_system
|
Cross-site scripting (XSS) vulnerability in EDCstore.pl in eDatCat 0.3 allows remote attackers to inject arbitrary web script or HTML via the user_action parameter.
|
NVD-CWE-Other
|
CVE-2005-4289
|
2008-09-20 13:42 |
2005-12-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356488
|
7.5 |
HIGH
|
indexcor
|
ezdatabase
|
SQL injection vulnerability in index.php for ezDatabase 2.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the db_id parameter.
|
NVD-CWE-Other
|
CVE-2005-4303
|
2008-09-20 13:42 |
2005-12-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356489
|
5.0 |
MEDIUM
|
indexcor
|
ezdatabase
|
index.php in ezDatabase 2.1.2 and earlier allows remote attackers to obtain sensitive information via an invalid cat_id parameter, which leaks the full pathname in an error message. NOTE: these deta…
|
NVD-CWE-Other
|
CVE-2005-4304
|
2008-09-20 13:42 |
2005-12-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356490
|
7.5 |
HIGH
|
scriptscenter
|
ezupload_pro
|
index.php in ezUpload Pro 2.2 and earlier allows remote attackers to include files via the mode parameter.
|
NVD-CWE-Other
|
CVE-2005-4308
|
2008-09-20 13:42 |
2005-12-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356491
|
4.3 |
MEDIUM
|
binary-concepts
|
binary_board_system
|
Multiple cross-site scripting (XSS) vulnerabilities in Binary Board System (BBS) 0.2.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) inreplyto, (2) article, an…
|
NVD-CWE-Other
|
CVE-2005-4333
|
2008-09-20 13:42 |
2005-12-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356492
|
7.8 |
HIGH
|
courseforum
|
projectforum
|
ProjectForum 4.7.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted pageid parameter to admin/versions.html.
|
NVD-CWE-Other
|
CVE-2005-4335
|
2008-09-20 13:42 |
2005-12-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356493
|
6.4 |
MEDIUM
|
fad_solutions
|
drzes_hms
|
Multiple SQL injection vulnerabilities in DRZES HMS 3.2 allow remote attackers to execute arbitrary SQL commands via the (1) plan_id parameter to (a) domains.php, (b) viewusage.php, (c) pop_accounts.…
|
NVD-CWE-Other
|
CVE-2005-4366
|
2008-09-20 13:42 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356494
|
5.8 |
MEDIUM
|
fad_solutions
|
drzes_hms
|
Cross-site scripting (XSS) vulnerability in register_domain.php in DRZES HMS 3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the "Domain…
|
NVD-CWE-Other
|
CVE-2005-4367
|
2008-09-20 13:42 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356495
|
7.5 |
HIGH
|
asps
|
shopping_cart
|
Multiple SQL injection vulnerabilities in Absolute Shopping Package Solutions (ASPS) Shopping Cart Professional 2.9d and earlier, and Lite 2.1 and earlier, allow remote attackers to execute arbitrary…
|
NVD-CWE-Other
|
CVE-2005-4003
|
2008-09-20 13:41 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356496
|
7.5 |
HIGH
|
jax_calendar
|
jax_calendar
|
SQL injection vulnerability in jax_calendar.php in Jax Calendar 1.34 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter, and possibly the (2) Y and (3) m parameter…
|
NVD-CWE-Other
|
CVE-2005-4008
|
2008-09-20 13:41 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356497
|
7.5 |
HIGH
|
php_lite
|
calendar_express
|
Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid and (2) catid parameters to (a) day.php, (…
|
NVD-CWE-Other
|
CVE-2005-4009
|
2008-09-20 13:41 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356498
|
5.0 |
MEDIUM
|
-
|
-
|
property.php in Widget Property 1.1.19 allows remote attackers to obtain the full server path via an invalid lang value, which leaks the path in the resulting error message.
|
NVD-CWE-Other
|
CVE-2005-4017
|
2008-09-20 13:41 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356499
|
7.5 |
HIGH
|
simplemedia
|
simplebbs
|
SQL injection vulnerability in SimpleBBS 1.1 allows remote attackers to execute arbitrary SQL commands via unspecified search module parameters.
|
CWE-89
SQLインジェクション
|
CVE-2005-4027
|
2008-09-20 13:41 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356500
|
7.2 |
HIGH
|
redhat
|
linux
|
uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfa…
|
NVD-CWE-Other
|
CVE-2003-0019
|
2008-09-11 09:05 |
2003-02-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|