275301
|
5.0 |
MEDIUM
|
raysoft
|
video_cam_server
|
Directory traversal vulnerability in Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to read arbitrary files via ".." (dot dot) sequences in an HTTP request.
|
NVD-CWE-Other
|
CVE-2005-1421
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275302
|
7.5 |
HIGH
|
-
|
-
|
Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to conduct administrator operations and cause a denial of service (server or camera shutdown) via a direct request to admin.html.
|
NVD-CWE-Other
|
CVE-2005-1422
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275303
|
6.4 |
MEDIUM
|
software602
|
602lan_suite
|
Directory traversal vulnerability in the mail program in 602LAN SUITE 2004.0.05.0413 allows remote attackers to cause a denial of service and determine the presence of arbitrary files via .. sequence…
|
NVD-CWE-Other
|
CVE-2005-1423
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275304
|
7.5 |
HIGH
|
abczone.it
|
wwwguestbook
|
SQL injection vulnerability in login.asp in WWWguestbook 1.1 allows remote attackers to execute arbitrary SQL commands via the password parameter.
|
NVD-CWE-Other
|
CVE-2005-1429
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275305
|
4.6 |
MEDIUM
|
hp
|
openview_event_correlation_services
|
Multiple unknown vulnjerabilities HP OpenView Event Correlation Services (OV ECS) 3.32 and 3.33 allow attackers to cause a denial of service or execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-1433
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275306
|
7.5 |
HIGH
|
hp
|
openview_network_node_manager
|
Multiple unknown vulnerabilities in OpenView Network Node Manager (OV NNM) 6.2, 6.4, 7.01, and 7.50 allow attackers to cause a denial of service or execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-1434
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275307
|
7.5 |
HIGH
|
open_webmail
|
open_webmail
|
Open WebMail (OWM) before 2.51 20050430 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename.
|
NVD-CWE-Other
|
CVE-2005-1435
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275308
|
7.5 |
HIGH
|
osticket
|
osticket
|
Multiple SQL injection vulnerabilities in osTicket allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to admin.php or (2) cat parameter to view.php.
|
NVD-CWE-Other
|
CVE-2005-1437
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275309
|
7.5 |
HIGH
|
osticket
|
osticket
|
PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir parameter.
|
NVD-CWE-Other
|
CVE-2005-1438
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275310
|
7.5 |
HIGH
|
osticket
|
osticket
|
Directory traversal vulnerability in attachments.php in osTicket allows remote attackers to read arbitrary files via .. sequences in the file parameter.
|
NVD-CWE-Other
|
CVE-2005-1439
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275311
|
6.8 |
MEDIUM
|
codetosell
|
viart_shop_enterprise
|
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nick…
|
NVD-CWE-Other
|
CVE-2005-1440
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275312
|
6.8 |
MEDIUM
|
-
|
-
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php for Invision Power Board (IPB) 2.0.3 and 2.1 Alpha 2 allows remote attackers to inject arbitrary web script or HTML via the (1) act, (…
|
NVD-CWE-Other
|
CVE-2005-1443
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275313
|
6.8 |
MEDIUM
|
sitepanel
|
sitepanel
|
Multiple cross-site scripting (XSS) vulnerabilities in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to inject arbitrary web script or HTML via (1) the v, show, or sec_name paramet…
|
NVD-CWE-Other
|
CVE-2005-1444
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275314
|
6.4 |
MEDIUM
|
sitepanel
|
sitepanel
|
Multiple directory traversal vulnerabilities in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to (1) delete arbitrary files via the id parameter in a rmattach action to 5.php, or (…
|
NVD-CWE-Other
|
CVE-2005-1445
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275315
|
7.5 |
HIGH
|
sitepanel
|
sitepanel
|
SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to upload and execute arbitrary files such as PHP scripts via an attachment to a trouble ticket.
|
NVD-CWE-Other
|
CVE-2005-1446
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275316
|
7.5 |
HIGH
|
sitepanel
|
sitepanel
|
PHP remote file inclusion vulnerability in main.php in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to execute arbitrary PHP code via the p parameter.
|
NVD-CWE-Other
|
CVE-2005-1447
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275317
|
6.8 |
MEDIUM
|
s9y
|
serendipity
|
Cross-site scripting (XSS) vulnerability in the BBCode plugin for Serendipity before 0.8 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-1448
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275318
|
10.0 |
HIGH
|
s9y
|
serendipity
|
Unknown vulnerability in serendipity_config_local.inc.php for Serendipity before 0.8 has unknown impact.
|
NVD-CWE-Other
|
CVE-2005-1449
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275319
|
7.5 |
HIGH
|
s9y
|
serendipity
|
Unknown vulnerability in "the function used to validate path-names for uploading media" in Serendipity before 0.8 has unknown impact.
|
NVD-CWE-Other
|
CVE-2005-1450
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275320
|
7.5 |
HIGH
|
s9y
|
serendipity
|
The media manager in Serendipity before 0.8 allows remote attackers to upload and execute arbitrary (1) .php or (2) .shtml files.
|
NVD-CWE-Other
|
CVE-2005-1451
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275321
|
10.0 |
HIGH
|
s9y
|
serendipity
|
Serendipity before 0.8 allows Chief users to "hide plugins installed by other users."
|
NVD-CWE-Other
|
CVE-2005-1452
|
2008-09-6 05:49 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275322
|
2.1 |
LOW
|
apple
|
mac_os_x
|
Certain system calls in Apple Mac OS X 10.4.1 do not properly enforce the permissions of certain directories without the POSIX read bit set, but with the execute bits set for group or other, which al…
|
NVD-CWE-Other
|
CVE-2005-1472
|
2008-09-6 05:49 |
2005-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275323
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
SecurityAgent in Apple Mac OS X 10.4.1 allows attackers with physical access to bypass the locked screensaver and launch background applications by opening a URL from a text input field.
|
NVD-CWE-Other
|
CVE-2005-1473
|
2008-09-6 05:49 |
2005-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275324
|
7.5 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Dashboard in Apple Mac OS X 10.4.1 allows remote attackers to install widgets via Safari without prompting the user, a different vulnerability than CVE-2005-1933.
|
NVD-CWE-Other
|
CVE-2005-1474
|
2008-09-6 05:49 |
2005-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275325
|
7.5 |
HIGH
|
gnu
|
mailutils
|
Buffer overflow in the header_get_field_name function in header.c for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via a crafted e-ma…
|
NVD-CWE-Other
|
CVE-2005-1520
|
2008-09-6 05:49 |
2005-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275326
|
7.5 |
HIGH
|
gnu
|
mailutils
|
Integer overflow in the fetch_io function of the imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via a partial message …
|
NVD-CWE-Other
|
CVE-2005-1521
|
2008-09-6 05:49 |
2005-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275327
|
5.0 |
MEDIUM
|
gnu
|
mailutils
|
The imap4d server for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows authenticated remote users to cause a denial of service (CPU consumption) via a large range value in the FETC…
|
NVD-CWE-Other
|
CVE-2005-1522
|
2008-09-6 05:49 |
2005-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275328
|
7.5 |
HIGH
|
gnu
|
mailutils
|
Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via format string specifiers in the comm…
|
NVD-CWE-Other
|
CVE-2005-1523
|
2008-09-6 05:49 |
2005-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275329
|
5.0 |
MEDIUM
|
battleaxe_software
|
bttlxeforum
|
forum.asp in bttlxeForum 2.0 allows remote attackers to obtain full path information via a certain hex-encoded argument to the page parameter, possibly due to a SQL injection vulnerability.
|
NVD-CWE-Other
|
CVE-2005-1570
|
2008-09-6 05:49 |
2005-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275330
|
5.0 |
MEDIUM
|
wenig_and_spitzer-williams
|
showoff_digital_media_software
|
Multiple directory traversal vulnerabilities in ShowOff! 1.5.4 allow remote attackers to read arbitrary files via ".." sequences in arguments to the (1) ShowAlbum, (2) ShowVideo, or (3) ShowGraphic s…
|
NVD-CWE-Other
|
CVE-2005-1571
|
2008-09-6 05:49 |
2005-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275331
|
5.0 |
MEDIUM
|
wenig_and_spitzer-williams
|
showoff_digital_media_software
|
ShowOff! 1.5.4 allows remote attackers to cause a denial of service (server crash) via a malformed request to port 8083.
|
NVD-CWE-Other
|
CVE-2005-1572
|
2008-09-6 05:49 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275332
|
5.0 |
MEDIUM
|
mozilla
|
firefox
|
The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows allows remote attackers to hide the real file types of downloaded files via the Content-Type HTTP header and a filename containi…
|
NVD-CWE-Other
|
CVE-2005-1575
|
2008-09-6 05:49 |
2005-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275333
|
2.6 |
LOW
|
mozilla
|
firefox
|
The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selec…
|
NVD-CWE-Other
|
CVE-2005-1576
|
2008-09-6 05:49 |
2005-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275334
|
7.5 |
HIGH
|
apg_technology
|
classmaster
|
APG Technology ClassMaster does not properly restrict access to sensitive folders, which allows remote attackers to access folders via a network share.
|
NVD-CWE-Other
|
CVE-2005-1577
|
2008-09-6 05:49 |
2005-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275335
|
2.1 |
LOW
|
guidance_software
|
encase
|
EnCase Forensic Edition 4.18a does not support Device Configuration Overlays (DCO), which allows attackers to hide information without detection.
|
NVD-CWE-Other
|
CVE-2005-1578
|
2008-09-6 05:49 |
2005-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275336
|
7.5 |
HIGH
|
boastmachine
|
boastmachine
|
users.ini.php in BoastMachine 3.0 does not properly restrict the types of files that can be uploaded, which allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-1580
|
2008-09-6 05:49 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275337
|
4.3 |
MEDIUM
|
eric_fichot
|
bug_report
|
Cross-site scripting (XSS) vulnerability in Bug Report 1.0 allows remote attackers to inject arbitrary web script or HTML via various fields to bug_report.php, which are not filtered or quoted when p…
|
NVD-CWE-Other
|
CVE-2005-1581
|
2008-09-6 05:49 |
2005-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275338
|
4.3 |
MEDIUM
|
1two
|
1two_news
|
Cross-site scripting (XSS) vulnerability in index.php for 1Two News 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) nom, (2) email, (3) siteweb, or (4) commentaire vari…
|
NVD-CWE-Other
|
CVE-2005-1582
|
2008-09-6 05:49 |
2005-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275339
|
5.0 |
MEDIUM
|
1two
|
1two_news
|
1Two News 1.0 allows remote attackers to (1) delete images for new stories via a direct request to admin/delete.php or (2) upload arbitrary images via a direct request to admin/upload.php.
|
NVD-CWE-Other
|
CVE-2005-1583
|
2008-09-6 05:49 |
2005-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275340
|
4.3 |
MEDIUM
|
open_solution
|
quick.forum
|
Cross-site scripting (XSS) vulnerability in index.php for Quick.Forum 2.1.6 allows remote attackers to inject arbitrary web script or HTML via the topic field in a NewTopic action.
|
NVD-CWE-Other
|
CVE-2005-1584
|
2008-09-6 05:49 |
2005-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275341
|
7.5 |
HIGH
|
open_solution
|
quick.forum
|
Multiple SQL injection vulnerabilities in Quick.Forum 2.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) iCategory or (2) page parameter to index.php, or (3) iCategory paramet…
|
NVD-CWE-Other
|
CVE-2005-1585
|
2008-09-6 05:49 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275342
|
5.0 |
MEDIUM
|
open_solution
|
quick.forum
|
Quick.Forum 2.1.6 stores potentially sensitive information such as usernames, banned IP addresses, censored words, and backups under the web document root, which allows remote attackers to obtain tha…
|
NVD-CWE-Other
|
CVE-2005-1586
|
2008-09-6 05:49 |
2005-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275343
|
4.3 |
MEDIUM
|
open_solution
|
quick.cart
|
Cross-site scripting (XSS) vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to inject arbitrary web script or HTML via the sWord parameter.
|
NVD-CWE-Other
|
CVE-2005-1587
|
2008-09-6 05:49 |
2005-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275344
|
4.6 |
MEDIUM
|
altiris
|
client_service deployment_solution
|
The Altiris Client Service for Windows (ACLIENT.EXE) 6.0.88 allows local users to disable password protection and access the administrative interface by finding and showing the "Altiris Client Servic…
|
NVD-CWE-Other
|
CVE-2005-1590
|
2008-09-6 05:49 |
2005-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275345
|
7.5 |
HIGH
|
birdblog
|
birdblog
|
Multiple "javascript vulerabilities in BB code" in BirdBlog before 1.3.1 allow remote attackers to inject arbitrary Javascript.
|
NVD-CWE-Other
|
CVE-2005-1592
|
2008-09-6 05:49 |
2005-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275346
|
6.8 |
MEDIUM
|
codethat
|
shoppingcart
|
Cross-site scripting (XSS) vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
|
NVD-CWE-Other
|
CVE-2005-1593
|
2008-09-6 05:49 |
2005-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275347
|
7.5 |
HIGH
|
codethat
|
shoppingcart
|
SQL injection vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2005-1594
|
2008-09-6 05:49 |
2005-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275348
|
5.0 |
MEDIUM
|
codethat
|
shoppingcart
|
CodeThat ShoppingCart 1.3.1 stores config.ini under the web root, which allows remote attackers to obtain sensitive information via a direct request.
|
NVD-CWE-Other
|
CVE-2005-1595
|
2008-09-6 05:49 |
2005-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275349
|
6.8 |
MEDIUM
|
remote_cart
|
remote_cart
|
Cross-site scripting (XSS) vulnerability in shop.cgi in Remote Cart allows remote attackers to inject arbitrary web script or HTML via the (1) merchant or (2) demo parameters.
|
NVD-CWE-Other
|
CVE-2005-1607
|
2008-09-6 05:49 |
2005-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275350
|
5.0 |
MEDIUM
|
adobe
|
acrobat_reader
|
Stack-based buffer overflow in the UnixAppOpenFilePerform function in Adobe Reader 5.0.9 and 5.0.10 for Unix allows remote attackers to execute arbitrary code via a PDF document with a long /Filespec…
|
NVD-CWE-Other
|
CVE-2005-1625
|
2008-09-6 05:49 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|