|
357651
|
7.5 |
HIGH
|
media2_cms
|
media2_cms_shop
|
SQL injection vulnerability in default.asp in Media2 CMS Shop 18.x allows remote attackers to execute arbitrary SQL commands via the item parameter. NOTE: the provenance of this issue is unknown; th…
|
NVD-CWE-Other
|
CVE-2005-4404
|
2008-09-6 05:56 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357652
|
2.1 |
LOW
|
citrix
|
program_neighborhood_client
|
Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the…
|
NVD-CWE-Other
|
CVE-2005-4412
|
2008-09-6 05:56 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357653
|
4.3 |
MEDIUM
|
ibm
|
websphere_application_server
|
Multiple cross-site scripting (XSS) vulnerabilities in sample scripts in IBM WebSphere Application Server 6 allow remote attackers to inject arbitrary web script or HTML via the (1) E-mail address fi…
|
NVD-CWE-Other
|
CVE-2005-4413
|
2008-09-6 05:56 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357654
|
10.0 |
HIGH
|
open_lab
|
teamwork
|
Unspecified vulnerability in Teamwork 3 before alpha 1.7 has unknown impact and attack vectors, related to "a menu security bug."
|
NVD-CWE-Other
|
CVE-2005-4414
|
2008-09-6 05:56 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357655
|
4.3 |
MEDIUM
|
tml
|
tml
|
Cross-site scripting (XSS) vulnerability in index.php in TML CMS 0.5 allows remote attackers to inject arbitrary web script or HTML via the form parameter.
|
NVD-CWE-Other
|
CVE-2005-4415
|
2008-09-6 05:56 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357656
|
7.5 |
HIGH
|
tml
|
tml
|
SQL injection vulnerability in index.php in TML CMS 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2005-4416
|
2008-09-6 05:56 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357657
|
6.5 |
MEDIUM
|
toenda_software_development
|
toendacms
|
Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then acc…
|
NVD-CWE-Other
|
CVE-2005-4422
|
2008-09-6 05:56 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357658
|
6.5 |
MEDIUM
|
-
|
-
|
Unrestricted file upload vulnerability in PHPFM before 0.2.3 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension to an accessible directory, a…
|
NVD-CWE-Other
|
CVE-2005-4423
|
2008-09-6 05:56 |
2005-12-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357659
|
7.2 |
HIGH
|
openldap
|
openldap
|
Untrusted search path vulnerability in OpenLDAP before 2.2.28-r3 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary buil…
|
NVD-CWE-Other
|
CVE-2005-4442
|
2008-09-6 05:56 |
2005-12-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357660
|
7.2 |
HIGH
|
gauche
|
gauche
|
Untrusted search path vulnerability in Gauche before 0.8.6-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build d…
|
NVD-CWE-Other
|
CVE-2005-4443
|
2008-09-6 05:56 |
2005-12-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357661
|
4.3 |
MEDIUM
|
aspbite
|
aspbite
|
Cross-site scripting (XSS) vulnerability in index.asp in ASPBite 8.x allows remote attackers to inject arbitrary web script or HTML via the strSearch parameter.
|
NVD-CWE-Other
|
CVE-2005-4446
|
2008-09-6 05:56 |
2005-12-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357662
|
7.5 |
HIGH
|
phpmyadmin
|
phpmyadmin
|
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to server_privileges.php, as demo…
|
NVD-CWE-Other
|
CVE-2005-4450
|
2008-09-6 05:56 |
2005-12-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357663
|
5.0 |
MEDIUM
|
livejournal
|
livejournal
|
cleanhtml.pl 1.129 in LiveJournal CVS before Dec 13 2005 allows remote attackers to inject scripting languages via the XSL namespace in XML, via vectors such as customview.cgi.
|
NVD-CWE-Other
|
CVE-2005-4455
|
2008-09-6 05:56 |
2005-12-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357664
|
7.8 |
HIGH
|
mailenable
|
mailenable_enterprise mailenable_professional
|
Multiple buffer overflows in MailEnable Professional 1.71 and Enterprise 1.1 before patch ME-10009 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via …
|
NVD-CWE-Other
|
CVE-2005-4456
|
2008-09-6 05:56 |
2005-12-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357665
|
7.5 |
HIGH
|
mailenable
|
mailenable_enterprise
|
MailEnable Enterprise 1.1 before patch ME-10009 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via several "..." (triple dot) sequences in a UID FETC…
|
NVD-CWE-Other
|
CVE-2005-4457
|
2008-09-6 05:56 |
2005-12-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357666
|
5.0 |
MEDIUM
|
-
|
-
|
cancel_account.php in WHM AutoPilot 2.5.30 and earlier allows remote attackers to cancel requests for arbitrary accounts via a modified c parameter.
|
NVD-CWE-Other
|
CVE-2005-3687
|
2008-09-6 05:55 |
2005-11-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357667
|
7.5 |
HIGH
|
uresk_links
|
uresk_links
|
Unspecified vulnerability in the administration interface in Uresk Links 2.0 Lite allows remote attackers to bypass authentication via unspecified vectors in index.php.
|
NVD-CWE-Other
|
CVE-2005-3697
|
2008-09-6 05:55 |
2005-11-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357668
|
7.5 |
HIGH
|
php_easy_download
|
php_easy_download
|
PHP Easy Download allows remote attackers to bypass authentication via edit.php.
|
NVD-CWE-Other
|
CVE-2005-3698
|
2008-09-6 05:55 |
2005-11-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357669
|
7.5 |
HIGH
|
revize_cms
|
revize_cms
|
SQL injection vulnerability in debug/query_results.jsp in Idetix Software Systems Revize CMS allows remote attackers to execute arbitrary SQL commands via the query parameter.
|
NVD-CWE-Other
|
CVE-2005-3727
|
2008-09-6 05:55 |
2005-11-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357670
|
5.0 |
MEDIUM
|
revize_cms
|
revize_cms
|
Idetix Software Systems Revize CMS stores conf/revize.xml under the web document root with insufficient access control, which allows remote attackers to obtain sensitive configuration information.
|
NVD-CWE-Other
|
CVE-2005-3728
|
2008-09-6 05:55 |
2005-11-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357671
|
5.0 |
MEDIUM
|
revize_cms
|
revize_cms
|
Idetix Software Systems Revize CMS allows remote attackers to obtain sensitive information via direct requests to files in the revize/debug directory, such as (1) apptables.html and (2) main.html.
|
NVD-CWE-Other
|
CVE-2005-3729
|
2008-09-6 05:55 |
2005-11-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357672
|
4.3 |
MEDIUM
|
revize_cms
|
revize_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in HTTPTranslatorServlet in Idetix Software Systems Revize CMS allow remote attackers to inject arbitrary web script or HTML via the (1) resourcety…
|
NVD-CWE-Other
|
CVE-2005-3730
|
2008-09-6 05:55 |
2005-11-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357673
|
10.0 |
HIGH
|
yassl
|
yassl
|
Unspecified vulnerability in yaSSL before 1.0.6 has unknown impact and attack vectors, related to "certificate chain processing."
|
NVD-CWE-Other
|
CVE-2005-3731
|
2008-09-6 05:55 |
2005-11-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357674
|
4.3 |
MEDIUM
|
coastal_data_management
|
e-quick_cart
|
Multiple cross-site scripting (XSS) vulnerabilities in e-Quick Cart allow remote attackers to inject arbitrary web script or HTML via the (1) strgifttoname parameter in shopgift.asp, (2) strfirstname…
|
NVD-CWE-Other
|
CVE-2005-3736
|
2008-09-6 05:55 |
2005-11-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357675
|
7.5 |
HIGH
|
almondsoft
|
almond_classifieds
|
Almond Classifieds does not properly verify the password, which allows attackers to bypass access restrictions.
|
NVD-CWE-Other
|
CVE-2005-3741
|
2008-09-6 05:55 |
2005-11-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357676
|
7.5 |
HIGH
|
simplepoll
|
simplepoll
|
SQL injection vulnerability in results.php in SimplePoll allows remote attackers to execute arbitrary SQL commands via the pollid parameter.
|
NVD-CWE-Other
|
CVE-2005-3743
|
2008-09-6 05:55 |
2005-11-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357677
|
4.3 |
MEDIUM
|
apsis
|
pound
|
HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with c…
|
NVD-CWE-Other
|
CVE-2005-3751
|
2008-09-6 05:55 |
2005-11-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357678
|
10.0 |
HIGH
|
ldapdiff
|
ldapdiff
|
Unspecified vulnerability in ldapdiff before 1.1.1 has unknown impact and attack vectors, related to "ldapdiff.conf path construction".
|
NVD-CWE-Other
|
CVE-2005-3752
|
2008-09-6 05:55 |
2005-11-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357679
|
7.8 |
HIGH
|
linux
|
linux_kernel
|
Linux kernel before after 2.6.12 and before 2.6.13.1 might allow attackers to cause a denial of service (Oops) via certain IPSec packets that cause alignment problems in standard multi-block cipher p…
|
NVD-CWE-Other
|
CVE-2005-3753
|
2008-09-6 05:55 |
2005-11-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357680
|
4.3 |
MEDIUM
|
exponent
|
exponent
|
Cross-site scripting (XSS) vulnerability in Exponent CMS 0.96.3 and later versions allows remote attackers to inject arbitrary web script or HTML via (1) Javascript in forms produced by the form gene…
|
NVD-CWE-Other
|
CVE-2005-3761
|
2008-09-6 05:55 |
2005-11-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357681
|
5.0 |
MEDIUM
|
exponent
|
exponent
|
Exponent CMS 0.96.3 and later versions includes the full installation path in the base parameter to thumb.php, which allows remote attackers to obtain sensitive information. NOTE: this might be resu…
|
NVD-CWE-Other
|
CVE-2005-3763
|
2008-09-6 05:55 |
2005-11-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357682
|
10.0 |
HIGH
|
exponent
|
exponent
|
The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files, with unknown impact from the preview icon, possibly invol…
|
NVD-CWE-Other
|
CVE-2005-3764
|
2008-09-6 05:55 |
2005-11-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357683
|
7.5 |
HIGH
|
exponent
|
exponent
|
Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-3765
|
2008-09-6 05:55 |
2005-11-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357684
|
5.0 |
MEDIUM
|
exponent
|
exponent
|
Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though certain permissions are specified, which allows attackers t…
|
NVD-CWE-Other
|
CVE-2005-3766
|
2008-09-6 05:55 |
2005-11-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357685
|
7.5 |
HIGH
|
php_download_manager
|
php_download_manager
|
SQL injection vulnerability in files.php in PHP Download Manager 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.
|
NVD-CWE-Other
|
CVE-2005-3769
|
2008-09-6 05:55 |
2005-11-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357686
|
5.0 |
MEDIUM
|
-
|
-
|
Unspecified vulnerability in MyBulletinBoard (MyBB) before 1.0 PR2 Rev 686 allows attackers to cause a denial of service via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-3778
|
2008-09-6 05:55 |
2005-11-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357687
|
2.1 |
LOW
|
apple
|
mac_os_x mac_os_x_server
|
Mac OS X 10.4.3 up to 10.4.6, when loginwindow uses the "Name and password" setting, and the "Show the Restart, Sleep, and Shut Down buttons" option is disabled, allows users with physical access to …
|
NVD-CWE-Other
|
CVE-2005-3782
|
2008-09-6 05:55 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357688
|
4.3 |
MEDIUM
|
easypagecms
|
easypagecms
|
Cross-site scripting (XSS) vulnerability in index.php in EasyPageCMS allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
|
NVD-CWE-Other
|
CVE-2005-3854
|
2008-09-6 05:55 |
2005-11-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357689
|
4.0 |
MEDIUM
|
krusader
|
krusader
|
The Popular URL capability (popularurls.cpp) in Krusader 1.60.0 and 1.70.0-beta1 saves passwords in cleartext in the krusaderrc file when the user enters URLs containing passwords in the panel URL fi…
|
NVD-CWE-Other
|
CVE-2005-3856
|
2008-09-6 05:55 |
2005-11-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357690
|
7.8 |
HIGH
|
macromedia
|
flash_communication_server
|
Macromedia Flash Communication Server MX 1.0 and 1.5 does not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated usin…
|
NVD-CWE-Other
|
CVE-2005-3901
|
2008-09-6 05:55 |
2005-11-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357691
|
4.3 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in PBLang 4.65 allows remote attackers to inject arbitrary web script or HTML via multiple fields in (1) UCP.php and (2) SendPm.php.
|
NVD-CWE-Other
|
CVE-2005-3919
|
2008-09-6 05:55 |
2005-11-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357692
|
10.0 |
HIGH
|
dotclear
|
dotclear
|
Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2005-3957
|
2008-09-6 05:55 |
2005-12-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357693
|
7.5 |
HIGH
|
tradesoft
|
tradesoft_cms
|
Multiple SQL injection vulnerabilities in Tradesoft CMS allow remote attackers to execute arbitrary SQL commands via unspecified attack vectors.
|
NVD-CWE-Other
|
CVE-2005-3987
|
2008-09-6 05:55 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357694
|
7.5 |
HIGH
|
wineggdropshell
|
wineggdropshell
|
Multiple buffer overflows in WinEggDropShell remote access trojan (RAT) 1.7 allow remote attackers to execute arbitrary code via (1) a long GET request to the HTTP server, or a long (2) USER or (3) P…
|
NVD-CWE-Other
|
CVE-2005-3992
|
2008-09-6 05:55 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357695
|
4.0 |
MEDIUM
|
esi_products
|
webeoc
|
WebEOC before 6.0.2 uses the same secret key for all installations, which allows attackers with the key to decrypt data from any WebEOC installation.
|
NVD-CWE-Other
|
CVE-2005-4002
|
2008-09-6 05:55 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357696
|
7.5 |
HIGH
|
-
|
-
|
Help Desk Reloaded Free Help Desk does not remove or protect install.php once installation is complete, which allows remote attackers to gain privileges via a direct request to install.php, then navi…
|
NVD-CWE-Other
|
CVE-2005-4025
|
2008-09-6 05:55 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357697
|
4.3 |
MEDIUM
|
amember
|
amember
|
Multiple cross-site scripting (XSS) vulnerabilities in aMember allow remote attackers to inject arbitrary web script or HTML via the (1) lamember_login parameter to sendpass.php and (2) login paramet…
|
NVD-CWE-Other
|
CVE-2005-4028
|
2008-09-6 05:55 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357698
|
5.0 |
MEDIUM
|
esi_products
|
webeoc
|
WebEOC before 6.0.2 allows remote attackers to obtain valid usernames via the HTML source of the WebEOC login webpage, which could be useful in other attacks such as locking out valid users via brute…
|
NVD-CWE-Other
|
CVE-2005-4029
|
2008-09-6 05:55 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357699
|
5.0 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform…
|
NVD-CWE-Other
|
CVE-2005-3299
|
2008-09-6 05:54 |
2005-10-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357700
|
2.6 |
LOW
|
siteturn
|
domain_manager_pro
|
Cross-site scripting (XSS) vulnerability in SiteTurn Domain Manager Pro allows remote attackers to inject arbitrary web script or HTML via the err parameter in the panel script.
|
NVD-CWE-Other
|
CVE-2005-3320
|
2008-09-6 05:54 |
2005-10-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|