273751
|
10.0 |
HIGH
|
f-secure wrq
|
f-secure_ssh_server wrq_reflection_for_secure_it_windows_server
|
WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) processes access and deny lists in a case-sensitive manner, when previous versions were case-insensitive, which…
|
NVD-CWE-Other
|
CVE-2005-2771
|
2008-09-6 05:52 |
2005-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273752
|
7.5 |
HIGH
|
linksys
|
wrt54g
|
Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote attackers to execute arbitrary code via a long HTTP POST request.
|
NVD-CWE-Other
|
CVE-2005-2799
|
2008-09-6 05:52 |
2005-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273753
|
7.2 |
HIGH
|
frox
|
frox
|
frox 0.7.18, when running setuid root, does not properly drop privileges when reading a configuration file, which allows local users to read portions of arbitrary files via the -f command line option.
|
NVD-CWE-Other
|
CVE-2005-2807
|
2008-09-6 05:52 |
2005-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273754
|
7.5 |
HIGH
|
frox
|
frox
|
frox 0.7.16 and 0.7.17 does not properly parse certain Deny ACLs, which might allow attackers to bypass intended restrictions and access blocked hosts.
|
NVD-CWE-Other
|
CVE-2005-2808
|
2008-09-6 05:52 |
2005-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273755
|
2.1 |
LOW
|
silc
|
secure_internet_live_conferencing
|
silc daemon (silcd.c) in Secure Internet Live Conferencing (SILC) 1.0 and earlier allows local users to overwrite arbitrary files via a symlink attack on the silcd.[PID].stats temporary file.
|
NVD-CWE-Other
|
CVE-2005-2809
|
2008-09-6 05:52 |
2005-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273756
|
4.6 |
MEDIUM
|
net-snmp
|
net-snmp
|
Untrusted search path vulnerability in Net-SNMP 5.2.1.2 and earlier, on Gentoo Linux, installs certain Perl modules with an insecure DT_RPATH, which could allow local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-2811
|
2008-09-6 05:52 |
2005-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273757
|
7.5 |
HIGH
|
man2web
|
man2web
|
man2web allows remote attackers to execute arbitrary commands via -P arguments.
|
NVD-CWE-Other
|
CVE-2005-2812
|
2008-09-6 05:52 |
2005-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273758
|
4.3 |
MEDIUM
|
phorum
|
phorum
|
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 5.0.17a and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to register.php or (2) a…
|
NVD-CWE-Other
|
CVE-2005-2836
|
2008-09-6 05:52 |
2005-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273759
|
4.3 |
MEDIUM
|
maxdev
|
md-pro
|
Multiple cross-site scripting (XSS) vulnerabilities in MAXdev MD-Pro 1.0.72 allow remote attackers to inject arbitrary web script or HTML via (1) dl-search.php or (2) wl-search.php.
|
NVD-CWE-Other
|
CVE-2005-2839
|
2008-09-6 05:52 |
2005-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273760
|
5.0 |
MEDIUM
|
whitsoft_development
|
slimftpd
|
SlimFTPd 3.17 allows remote attackers to cause a denial of service (crash) via certain (1) USER and (2) PASS commands, possibly due to a buffer overflow or off-by-one error.
|
NVD-CWE-Other
|
CVE-2005-2850
|
2008-09-6 05:52 |
2005-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273761
|
2.1 |
LOW
|
smb4k
|
smb4k
|
smb4k 0.4 and other versions before 0.6.3 allows local users to read sensitive files via a symlink attack on the (1) smb4k.tmp or (2) sudoers temporary files.
|
NVD-CWE-Other
|
CVE-2005-2851
|
2008-09-6 05:52 |
2005-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273762
|
5.0 |
MEDIUM
|
novell
|
netware
|
Unknown vulnerability in CIFS.NLM in Novell Netware 6.5 SP2 and SP3, 5.1, and 6.0 allows remote attackers to cause a denial of service (ABEND) via an incorrect password length, as exploited by the "w…
|
NVD-CWE-Other
|
CVE-2005-2852
|
2008-09-6 05:52 |
2005-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273763
|
4.3 |
MEDIUM
|
guppy
|
guppy
|
Multiple cross-site scripting (XSS) vulnerabilities in GuppY 4.5.3a and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the pg parameter to printfaq.php, or the (2) Refe…
|
NVD-CWE-Other
|
CVE-2005-2853
|
2008-09-6 05:52 |
2005-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273764
|
5.0 |
MEDIUM
|
thesitewizard.com
|
chfeedback.pl_feedback_form_perl_script
|
CRLF injection vulnerability in thesitewizard.com chfeedback.pl Feedback Form Perl Script 2.0.1 allows remote attackers to use the script as a mail relay (spam proxy) via CRLF sequences in the (1) na…
|
NVD-CWE-Other
|
CVE-2005-2854
|
2008-09-6 05:52 |
2005-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273765
|
7.5 |
HIGH
|
softstack
|
free_smtp_server
|
Free SMTP Server 2.2 allows remote attackers to use the server as an open mail relay (spam proxy).
|
NVD-CWE-Other
|
CVE-2005-2857
|
2008-09-6 05:52 |
2005-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273766
|
4.6 |
MEDIUM
|
savant
|
savant_webserver
|
Savant Web Server stores user credentials in plaintext in the Savant\Users registry key, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-2859
|
2008-09-6 05:52 |
2005-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273767
|
4.3 |
MEDIUM
|
n-stalker
|
n-stealth
|
Cross-site scripting (XSS) vulnerability in N-Stealth Commercial Edition before 5.8.0.38 and Free Edition before 5.8.1.03 allows remote attackers to inject arbitrary web script or HTML via the Server…
|
NVD-CWE-Other
|
CVE-2005-2861
|
2008-09-6 05:52 |
2005-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273768
|
4.6 |
MEDIUM
|
-
|
-
|
Mercora IMRadio 4.0.0.0 stores usernames and passwords in plaintext in the MercoraClient\Profiles registry key, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-2866
|
2008-09-6 05:52 |
2005-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273769
|
7.5 |
HIGH
|
bluewhalecrm
|
bluewhalecrm
|
SQL injection vulnerability in BlueWhaleCRM allows remote attackers to execute arbitrary SQL commands via the Account ID field.
|
NVD-CWE-Other
|
CVE-2005-2867
|
2008-09-6 05:52 |
2005-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273770
|
4.3 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php…
|
NVD-CWE-Other
|
CVE-2005-2869
|
2008-09-6 05:52 |
2005-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273771
|
7.5 |
HIGH
|
sun
|
solaris
|
Unknown vulnerability in the net-svc script on Solaris 10 allows remote authenticated users to execute arbitrary code on a DHCP client via certain DHCP responses.
|
NVD-CWE-Other
|
CVE-2005-2870
|
2008-09-6 05:52 |
2005-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273772
|
7.5 |
HIGH
|
py2play
|
py2play
|
Py2Play allows remote attackers to execute arbitrary Python code via pickled objects, which Py2Play unpickles and executes.
|
NVD-CWE-Other
|
CVE-2005-2875
|
2008-09-6 05:52 |
2005-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273773
|
5.0 |
MEDIUM
|
linksys
|
wrt54g
|
Linksys WRT54G router allows remote attackers to cause a denial of service (CPU consumption and server hang) via an HTTP POST request with a negative Content-Length value.
|
NVD-CWE-Other
|
CVE-2005-2912
|
2008-09-6 05:52 |
2005-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273774
|
7.5 |
HIGH
|
linksys
|
wrt54g
|
ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions, does not use an authentication initialization function, which allows remote a…
|
NVD-CWE-Other
|
CVE-2005-2914
|
2008-09-6 05:52 |
2005-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273775
|
5.0 |
MEDIUM
|
linksys
|
wrt54g
|
ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions, uses weak encryption (XOR encoding with a fixed byte mask) for configuration …
|
NVD-CWE-Other
|
CVE-2005-2915
|
2008-09-6 05:52 |
2005-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273776
|
5.0 |
MEDIUM
|
linksys
|
wrt54g
|
Linksys WRT54G 3.01.03, 3.03.6, 4.00.7, and possibly other versions before 4.20.7, does not verify user authentication until after an HTTP POST request has been processed, which allows remote attacke…
|
NVD-CWE-Other
|
CVE-2005-2916
|
2008-09-6 05:52 |
2005-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273777
|
5.0 |
MEDIUM
|
microsoft
|
frontpage
|
Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page.
|
NVD-CWE-Other
|
CVE-2005-2143
|
2008-09-6 05:51 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273778
|
2.1 |
LOW
|
prevx
|
prevx_pro_2005
|
Prevx Pro 2005 1.0 allows local users to bypass file protection and modify files by using MapViewOfFile to perform memory mapping on the file.
|
NVD-CWE-Other
|
CVE-2005-2144
|
2008-09-6 05:51 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273779
|
4.6 |
MEDIUM
|
prevx
|
prevx_pro_2005
|
The kernel driver in Prevx Pro 2005 1.0 does not verify the source of certain messages, which allows local users to bypass protection by sending certain messages to the driver, as demonstrated by sen…
|
NVD-CWE-Other
|
CVE-2005-2145
|
2008-09-6 05:51 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273780
|
4.6 |
MEDIUM
|
ssh
|
tectia_server
|
SSH Tectia Server 4.3.1 and earlier, and SSH Secure Shell for Windows Servers, uses insecure permissions when generating the Secure Shell host identification key, which allows local users to access t…
|
NVD-CWE-Other
|
CVE-2005-2146
|
2008-09-6 05:51 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273781
|
6.4 |
MEDIUM
|
edgewall_software
|
trac
|
Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts.
|
NVD-CWE-Other
|
CVE-2005-2147
|
2008-09-6 05:51 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273782
|
5.0 |
MEDIUM
|
double_precision_incorporated
|
courier_mail_server
|
spf.c in Courier Mail Server does not properly handle DNS failures when looking up Sender Policy Framework (SPF) records, which could allow attackers to cause memory corruption.
|
NVD-CWE-Other
|
CVE-2005-2151
|
2008-09-6 05:51 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273783
|
7.5 |
HIGH
|
geeklog
|
geeklog
|
SQL injection vulnerability in Geeklog before 1.3.11 allows remote attackers to execute arbitrary SQL commands via user comments for an article.
|
NVD-CWE-Other
|
CVE-2005-2152
|
2008-09-6 05:51 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273784
|
7.5 |
HIGH
|
osticket
|
osticket_sts
|
SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable.
|
NVD-CWE-Other
|
CVE-2005-2153
|
2008-09-6 05:51 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273785
|
7.5 |
HIGH
|
osticket
|
osticket_sts
|
PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and possibly execute arbitrary local files via the inc pa…
|
NVD-CWE-Other
|
CVE-2005-2154
|
2008-09-6 05:51 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273786
|
7.5 |
HIGH
|
phpnews
|
phpnews
|
SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter.
|
NVD-CWE-Other
|
CVE-2005-2156
|
2008-09-6 05:51 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273787
|
7.5 |
HIGH
|
globalnotescript
|
globalnotescript
|
read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters.
|
NVD-CWE-Other
|
CVE-2005-2165
|
2008-09-6 05:51 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273788
|
5.0 |
MEDIUM
|
kaf_oseo
|
quick_and_dirty_phpsource_printer
|
Directory traversal vulnerability in source.php in Quick & Dirty PHPSource Printer 1.1 and earlier allows remote attackers to read arbitrary files via ".../...//" sequences in the file parameter, whi…
|
NVD-CWE-Other
|
CVE-2005-2169
|
2008-09-6 05:51 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273789
|
5.0 |
MEDIUM
|
mozilla
|
bugzilla
|
The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to…
|
NVD-CWE-Other
|
CVE-2005-2173
|
2008-09-6 05:51 |
2005-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273790
|
2.6 |
LOW
|
mozilla
|
bugzilla
|
Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access info…
|
NVD-CWE-Other
|
CVE-2005-2174
|
2008-09-6 05:51 |
2005-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273791
|
5.0 |
MEDIUM
|
ibm
|
lotus_notes
|
The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based att…
|
NVD-CWE-Other
|
CVE-2005-2175
|
2008-09-6 05:51 |
2005-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273792
|
2.1 |
LOW
|
apple
|
airport_card
|
The Apple AirPort card uses a default WEP key when not connected to a known or trusted network, which can cause it to automatically connect to a malicious network.
|
NVD-CWE-Other
|
CVE-2005-2196
|
2008-09-6 05:51 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273793
|
7.5 |
HIGH
|
spid
|
spid
|
PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary code via the lang_path parameter.
|
NVD-CWE-Other
|
CVE-2005-2198
|
2008-09-6 05:51 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273794
|
7.5 |
HIGH
|
skrypty
|
ppa_gallery
|
PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via the config[ppa_root_path] variable.
|
NVD-CWE-Other
|
CVE-2005-2199
|
2008-09-6 05:51 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273795
|
7.5 |
HIGH
|
xerox
|
workcentre_2128 workcentre_2636 workcentre_3545
|
Multiple unknown vulnerabilities in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to bypass authentication.
|
NVD-CWE-Other
|
CVE-2005-2200
|
2008-09-6 05:51 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273796
|
6.4 |
MEDIUM
|
xerox
|
workcentre_2128 workcentre_2636 workcentre_3545
|
Unknown vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to cause a denial of service or acc…
|
NVD-CWE-Other
|
CVE-2005-2201
|
2008-09-6 05:51 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273797
|
4.3 |
MEDIUM
|
xerox
|
workcentre_2128 workcentre_2636 workcentre_3545
|
Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to injec…
|
NVD-CWE-Other
|
CVE-2005-2202
|
2008-09-6 05:51 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273798
|
7.5 |
HIGH
|
phpwishlist
|
phpwishlist
|
login.php in phpWishlist before 0.1.15 allows remote attackers to bypass authentication via a direct request to admin.php.
|
NVD-CWE-Other
|
CVE-2005-2203
|
2008-09-6 05:51 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273799
|
7.5 |
HIGH
|
pngren
|
pngren
|
The ReadLog function in kaiseki.cgi in pngren allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.
|
NVD-CWE-Other
|
CVE-2005-2205
|
2008-09-6 05:51 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273800
|
7.5 |
HIGH
|
elemental_software
|
cartwiz
|
Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp,…
|
NVD-CWE-Other
|
CVE-2005-2206
|
2008-09-6 05:51 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|