|
343551
|
4.3 |
MEDIUM
|
phpopenchat
|
phpopenchat
|
Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or HTML via (1) the chatter parameter to regulars.php or (2) the chatter, chatter1,…
|
NVD-CWE-Other
|
CVE-2005-0863
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343552
|
5.0 |
MEDIUM
|
phpsysinfo
|
phpsysinfo
|
phpSysInfo 2.3 allows remote attackers to obtain sensitive information via a direct request to (1) class.OpenBSD.inc.php, (2) class.NetBSD.inc.php, (3) class.FreeBSD.inc.php, (4) class.Darwin.inc.php…
|
NVD-CWE-Other
|
CVE-2005-0869
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343553
|
4.3 |
MEDIUM
|
phpsysinfo
|
phpsysinfo
|
Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) sensor_program param…
|
NVD-CWE-Other
|
CVE-2005-0870
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343554
|
5.0 |
MEDIUM
|
phpbb_group
|
phpbb
|
calendar_scheduler.php in Topic Calendar 1.0.1 module for phpBB, when running on a Microsoft IIS server, allows remote attackers to obtain sensitive information via invalid parameters, which reveal t…
|
NVD-CWE-Other
|
CVE-2005-0871
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343555
|
4.3 |
MEDIUM
|
phpbb_group
|
phpbb
|
Cross-site scripting (XSS) vulnerability in calendar_scheduler.php in the Topic Calendar 1.0.1 module for phpBB allows remote attackers to inject arbitrary web script or HTML via the start parameter.
|
NVD-CWE-Other
|
CVE-2005-0872
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343556
|
5.0 |
MEDIUM
|
dnsmasq
|
dnsmasq
|
Off-by-one buffer overflow in Dnsmasq before 2.21 may allow attackers to execute arbitrary code via the DHCP lease file.
|
NVD-CWE-Other
|
CVE-2005-0876
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343557
|
4.3 |
MEDIUM
|
mercuryboard
|
mercuryboard_message_board
|
Cross-site scripting (XSS) vulnerability in MercuryBoard before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the title field of a PM (private message).
|
NVD-CWE-Other
|
CVE-2005-0878
|
2017-07-11 10:32 |
2005-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343558
|
7.5 |
HIGH
|
vortex_portal
|
vortex_portal
|
PHP remote file include vulnerability in (1) content.php and (2) index.php for Vortex Portal allows remote attackers to execute arbitrary PHP code via a URL in the act parameter.
|
NVD-CWE-Other
|
CVE-2005-0879
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343559
|
5.0 |
MEDIUM
|
vortex_portal
|
vortex_portal
|
content.php in Vortex Portal allows remote attackers to obtain sensitive information via an invalid act parameter, which leaks the full pathname in a PHP error message.
|
NVD-CWE-Other
|
CVE-2005-0880
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343560
|
4.3 |
MEDIUM
|
interspire
|
articlelive
|
Cross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers to inject arbitrary web script or HTML via the Articleld parameter.
|
NVD-CWE-Other
|
CVE-2005-0881
|
2017-07-11 10:32 |
2005-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343561
|
7.5 |
HIGH
|
birdblog
|
birdblog
|
SQL injection vulnerability in admincore.php in BirdBlog before 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) userid or (2) userpw parameters.
|
NVD-CWE-Other
|
CVE-2005-0882
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343562
|
4.3 |
MEDIUM
|
digitalhive
|
digitalhive
|
Multiple cross-site scripting (XSS) vulnerabilities in base.php for DigitalHive 2.0 allow remote attackers to inject arbitrary web script or HTML via (1) the mt parameter to the membres.php page or (…
|
NVD-CWE-Other
|
CVE-2005-0883
|
2017-07-11 10:32 |
2005-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343563
|
7.5 |
HIGH
|
digitalhive
|
digitalhive
|
DigitalHive 2.0 allows remote attackers to re-install the product by directly accessing the install script.
|
NVD-CWE-Other
|
CVE-2005-0884
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343564
|
7.5 |
HIGH
|
michael_dean
|
double_choco_latte
|
Eval injection vulnerability in Double Choco Latte before 0.9.4.3 allows remote attackers to execute arbitrary PHP code via the menuAction variable in (1) functions.inc.php or (2) main.php, which cau…
|
NVD-CWE-Other
|
CVE-2005-0887
|
2017-07-11 10:32 |
2005-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343565
|
4.3 |
MEDIUM
|
michael_dean
|
double_choco_latte
|
Multiple cross-site scripting (XSS) vulnerabilities in functions.inc.php for Double Choco Latte 0.9.4.3 allow remote attackers to inject arbitrary web script or HTML via the (1) class or (2) method n…
|
NVD-CWE-Other
|
CVE-2005-0888
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343566
|
2.1 |
LOW
|
microsoft
|
windows_xp
|
Remote Desktop in Windows XP SP1 does not verify the "Force shutdown from a remote system" setting, which allows remote attackers to shut down the system by executing TSShutdn.exe.
|
CWE-20
Improper Input Validation
|
CVE-2005-0904
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343567
|
7.5 |
HIGH
|
smarty
|
smarty
|
Unknown vulnerability in the regex_replace modifier (modifier.regex_replace.php) in Smarty before 2.6.8 allows attackers to execute arbitrary PHP code.
|
NVD-CWE-Other
|
CVE-2005-0913
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343568
|
4.3 |
MEDIUM
|
adventia
|
adventia_chat adventia_server_pro
|
Adventia Chat 3.1 and Server Pro 3.0 allows remote attackers to inject arbitrary web script or HTML into the chat space, which leaves other users vulnerable to cross-site scripting (XSS) attacks.
|
NVD-CWE-Other
|
CVE-2005-0919
|
2017-07-11 10:32 |
2005-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343569
|
4.3 |
MEDIUM
|
adventia
|
e-data
|
Cross-site scripting (XSS) vulnerability in Adventia E-Data 2.0 allows remote attackers to inject arbitrary web script or HTML via a query keyword.
|
NVD-CWE-Other
|
CVE-2005-0924
|
2017-07-11 10:32 |
2005-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343570
|
4.3 |
MEDIUM
|
asp_press
|
acs_blog
|
Cross-site scripting (XSS) vulnerability in ACS Blog 1.1.1 allows remote attackers to inject arbitrary web script or HTML via onmouseover or onload events in (1) img, (2) link, or (3) mail tags.
|
NVD-CWE-Other
|
CVE-2005-0945
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343571
|
7.5 |
HIGH
|
coinsoft_technologies
|
phpcoin
|
Directory traversal vulnerability in auxpage.php in phpCoin 1.2.1b and earlier allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the page parameter.
|
NVD-CWE-Other
|
CVE-2005-0947
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343572
|
7.5 |
HIGH
|
iatek
|
portalapp
|
SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parameter.
|
NVD-CWE-Other
|
CVE-2005-0948
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343573
|
4.3 |
MEDIUM
|
iatek
|
portalapp
|
Multiple cross-site scripting (XSS) vulnerabilities in content.asp in Iatek PortalApp allow remote attackers to inject arbitrary web script or HTML via the (1) contenttype or (2) keywords parameter.
|
NVD-CWE-Other
|
CVE-2005-0949
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343574
|
5.0 |
MEDIUM
|
faststone
|
4in1_browser
|
Directory traversal vulnerability in FastStone 4in1 Browser 1.2 allows remote attackers to read arbitrary files via a (1) ... (triple dot) or (2) ..\ (dot dot backslash) in the URL.
|
NVD-CWE-Other
|
CVE-2005-0950
|
2017-07-11 10:32 |
2005-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343575
|
7.5 |
HIGH
|
bay_technical_associates
|
rpc3_telnet
|
Bay Technical Associates RPC-3 Telnet Host 3.05 allows remote attackers to bypass authentication by pressing the escape and enter keys at the username prompt.
|
NVD-CWE-Other
|
CVE-2005-0957
|
2017-07-11 10:32 |
2005-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343576
|
7.5 |
HIGH
|
lighthouse_development
|
squirrelcart
|
SQL injection vulnerability in index.php for Lighthouse Squirrelcart allows remote attackers to execute arbitrary SQL commands via the (1) crn parameter in a show action or (2) rn parameter in a show…
|
NVD-CWE-Other
|
CVE-2005-0962
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343577
|
2.1 |
LOW
|
toshiba
|
acpi_flash_bios
|
An error in the Toshiba ACPI BIOS 1.6 causes the BIOS to only examine the first slot in the Master Boot Record (MBR) table for an active partition, which prevents the system from booting even though …
|
NVD-CWE-Other
|
CVE-2005-0963
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343578
|
4.6 |
MEDIUM
|
kerio
|
personal_firewall
|
Unknown vulnerability in Kerio Personal Firewall 4.1.2 and earlier allows local users to bypass firewall rules via a malicious process that impersonates a legitimate process that has fewer restrictio…
|
NVD-CWE-Other
|
CVE-2005-0964
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343579
|
2.1 |
LOW
|
apple opendarwin
|
mac_os_x mac_os_x_server darwin_kernel
|
Integer signedness error in the parse_machfile function in the mach-o loader (mach_loader.c) for the Darwin Kernel as used in Mac OS X 10.3.7, and other versions before 10.3.9, allows local users to …
|
NVD-CWE-Other
|
CVE-2005-0975
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343580
|
5.0 |
MEDIUM
|
ivt
|
bluesoleil
|
Directory traversal vulnerability in the Object Push service in IVT BlueSoleil 1.4 allows remote attackers to upload arbitrary files via a .. (dot dot) in a PUSH command.
|
NVD-CWE-Other
|
CVE-2005-0978
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343581
|
7.5 |
HIGH
|
netmanage
|
rumba
|
Multiple buffer overflows in RUMBA 7.3 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted values in a profile file, as demonstrated using …
|
NVD-CWE-Other
|
CVE-2005-0979
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343582
|
4.3 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin before 2.6.2-rc1 allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter.
|
NVD-CWE-Other
|
CVE-2005-0992
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343583
|
4.3 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the bid parameter to the EmailStats op in banners.pgp, (2) th…
|
NVD-CWE-Other
|
CVE-2005-1000
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343584
|
5.0 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
PHP-Nuke 7.6 allows remote attackers to obtain sensitive information via direct requests to (1) the Surveys module with the file parameter set to comments or (2) 3D-Fantasy/theme.php, which leaks the…
|
NVD-CWE-Other
|
CVE-2005-1001
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343585
|
7.5 |
HIGH
|
profitcode
|
payprocart
|
Directory traversal vulnerability in index.php for ProfitCode PayProCart 3.0 allows remote attackers to include arbitrary PHP files via .. (dot dot) sequences in the modID parameter.
|
NVD-CWE-Other
|
CVE-2005-1003
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343586
|
4.3 |
MEDIUM
|
profitcode
|
payprocart
|
Cross-site scripting (XSS) vulnerability in usrdetails.php in ProfitCode PayProCart 3.0 allows remote attackers to inject arbitrary web script or HTML via the sgnuptype parameter.
|
NVD-CWE-Other
|
CVE-2005-1004
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343587
|
7.5 |
HIGH
|
profitcode
|
payprocart
|
ProfitCode PayProCart 3.0 allows remote attackers to bypass authentication and gain administrative privileges to the admin control panel, as demonstrated via a direct request to adminshop/index.php w…
|
NVD-CWE-Other
|
CVE-2005-1005
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343588
|
5.0 |
MEDIUM
|
stalker
|
communigate_pro
|
Unknown vulnerability in the LIST functionality in CommuniGate Pro before 4.3c3 allows remote attackers to cause a denial of service (server crash) via certain multipart messages.
|
NVD-CWE-Other
|
CVE-2005-1007
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343589
|
10.0 |
HIGH
|
bakbone
|
netvault
|
Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a modified computer name and length that leads to a heap-based buffer overflow, or (…
|
NVD-CWE-Other
|
CVE-2005-1009
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343590
|
4.3 |
MEDIUM
|
comersus_open_technologies
|
comersus_cart
|
Cross-site scripting (XSS) vulnerability in Comersus Cart 6 allows remote attackers to inject arbitrary web script or HTML via the account username.
|
NVD-CWE-Other
|
CVE-2005-1010
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343591
|
4.3 |
MEDIUM
|
iatek
|
siteenable
|
Cross-site scripting (XSS) vulnerability in Iatek SiteEnable allows remote attackers to inject arbitrary web script or HTML via (1) the contenttype parameter to content.asp, (2) the title, or (3) the…
|
NVD-CWE-Other
|
CVE-2005-1012
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343592
|
5.0 |
MEDIUM
|
mailenable
|
mailenable_enterprise mailenable_professional
|
The SMTP service in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to cause a denial of service (server crash) via an EHLO command with a Unicode str…
|
NVD-CWE-Other
|
CVE-2005-1013
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343593
|
7.5 |
HIGH
|
mailenable
|
mailenable_enterprise mailenable_professional
|
Buffer overflow in the IMAP service for MailEnable Enterprise 1.04 and earlier and Professional 1.54 allows remote attackers to execute arbitrary code via a long AUTHENTICATE command.
|
NVD-CWE-Other
|
CVE-2005-1014
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343594
|
4.3 |
MEDIUM
|
maxwebportal
|
maxwebportal
|
Cross-site scripting (XSS) vulnerability in links_add_form.asp for MaxWebPortal 1.33 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript URL in a banner URL.
|
NVD-CWE-Other
|
CVE-2005-1016
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343595
|
7.5 |
HIGH
|
maxwebportal
|
maxwebportal
|
SQL injection vulnerability in the Update_Events function in events_functions.asp in MaxWebPortal 1.33 and earlier allows remote attackers to execute arbitrary SQL commands via the EVENT_ID parameter…
|
CWE-89
SQL Injection
|
CVE-2005-1017
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343596
|
7.2 |
HIGH
|
aeon
|
aeon
|
Buffer overflow in the getConfig function in Aeon 0.2a and earlier allows local users to gain privileges via a long HOME environment variable.
|
NVD-CWE-Other
|
CVE-2005-1019
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343597
|
4.3 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) min parameter to the Search module, (2) the catego…
|
NVD-CWE-Other
|
CVE-2005-1023
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343598
|
5.0 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) my_headlines, (2) userinfo, or (3) search, which reveals the path in a PHP error…
|
NVD-CWE-Other
|
CVE-2005-1024
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343599
|
4.3 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x through 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in the Your_Account module…
|
NVD-CWE-Other
|
CVE-2005-1027
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343600
|
7.5 |
HIGH
|
active_web_softwares
|
active_auction_house
|
Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to default.asp, (4) ite…
|
NVD-CWE-Other
|
CVE-2005-1029
|
2017-07-11 10:32 |
2005-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|