|
344651
|
5.0 |
MEDIUM
|
comdev
|
comdev_ecommerce
|
Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the download parameter.
|
NVD-CWE-Other
|
CVE-2005-2543
|
2016-10-18 12:28 |
2005-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344652
|
5.0 |
MEDIUM
|
arab_portal
|
arab_portal
|
Arab Portal 2.0 allows remote attackers to obtain sensitive information via a long (1) username or (2) password, which reveals the path in an error message when the undefined "errmsg" function is cal…
|
NVD-CWE-Other
|
CVE-2005-2546
|
2016-10-18 12:28 |
2005-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344653
|
7.5 |
HIGH
|
hp
|
proliant_dl585
|
Unknown vulnerability in HP ProLiant DL585 servers running Integrated Lights Out (ILO) firmware before 1.81 allows attackers to access server controls when the server is "powered down."
|
NVD-CWE-Other
|
CVE-2005-2552
|
2016-10-18 12:28 |
2005-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344654
|
7.5 |
HIGH
|
mantis
|
mantis
|
core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal databases by modifying the g_db_type variable and monitoring th…
|
NVD-CWE-Other
|
CVE-2005-2556
|
2016-10-18 12:28 |
2005-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344655
|
4.3 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in index.cfm in CFBB 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
NVD-CWE-Other
|
CVE-2005-2560
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344656
|
7.5 |
HIGH
|
myfaq
|
myfaq
|
Multiple SQL injection vulnerabilities in MYFAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the Theme parameter to (1) affichagefaq.php3, (2) choixsoustheme.php3, (3) consultatio…
|
NVD-CWE-Other
|
CVE-2005-2561
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344657
|
4.3 |
MEDIUM
|
gravity_board_x_development_team
|
gravity_board_x
|
Multiple cross-site scripting (XSS) vulnerabilities in Gravity Board X (GBX) 1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the board_id parameter to deletethread.php or (2…
|
NVD-CWE-Other
|
CVE-2005-2563
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344658
|
7.5 |
HIGH
|
openbb
|
openbb
|
Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) allow remote attackers to execute arbitrary SQL commands via the (1) FID parameter to board.php or (2) UID parameter to member.p…
|
NVD-CWE-Other
|
CVE-2005-2566
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344659
|
7.5 |
HIGH
|
syscp_team
|
syscp
|
PHP remote file inclusion vulnerability in SysCP 1.2.10 and earlier allows remote attackers to execute arbitrary PHP code via the language parameter.
|
NVD-CWE-Other
|
CVE-2005-2567
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344660
|
7.5 |
HIGH
|
syscp_team
|
syscp
|
Eval injection vulnerability in the template engine for SysCP 1.2.10 and earlier allows remote attackers to execute arbitrary PHP code via a string containing the code within "{" and "}" (curly brack…
|
NVD-CWE-Other
|
CVE-2005-2568
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344661
|
4.3 |
MEDIUM
|
funkboard
|
funkboard
|
Multiple cross-site scripting (XSS) vulnerabilities in FunkBoard 0.66CF, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the fbusername or fbpassword …
|
NVD-CWE-Other
|
CVE-2005-2569
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344662
|
5.0 |
MEDIUM
|
funkboard
|
funkboard
|
FunkBoard 0.66CF, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to forums.php, which reveals the path in an error message.
|
NVD-CWE-Other
|
CVE-2005-2570
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344663
|
6.4 |
MEDIUM
|
funkboard
|
funkboard
|
FunkBoard 0.66CF, and possibly earlier versions, does not properly restrict access to the (1) admin/mysql_install.php and (2) admin/pg_install.php scripts, which allows attackers to obtain the databa…
|
NVD-CWE-Other
|
CVE-2005-2571
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344664
|
5.0 |
MEDIUM
|
calogic
|
calogic
|
CaLogic 1.22, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to (1) doclsqlres.php, (2) clmcpreload.php, (3) viewhistlog.php, (4) mcconfig…
|
NVD-CWE-Other
|
CVE-2005-2576
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344665
|
5.0 |
MEDIUM
|
wyse
|
winterm
|
Wyse Winterm 1125SE running firmware 4.2.09f or 4.4.061f allows remote attackers to cause a denial of service (device crash) via a packet with a zero in the IP option length field.
|
NVD-CWE-Other
|
CVE-2005-2577
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344666
|
7.2 |
HIGH
|
nortel
|
contivity
|
Nortel Contivity VPN Client V05_01.030, when configuring a certificate to be used as authentication, does not properly drop system privileges, which allows local users to gain privileges by opening a…
|
NVD-CWE-Other
|
CVE-2005-2579
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344667
|
7.2 |
HIGH
|
nortel
|
contivity
|
Patch released by vendor.
|
NVD-CWE-Other
|
CVE-2005-2579
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344668
|
7.5 |
HIGH
|
mybulletinboard
|
mybulletinboard
|
Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 with Security Patch allow remote attackers to execute arbitrary SQL commands via the Username field in (1) index.php or (2) m…
|
NVD-CWE-Other
|
CVE-2005-2580
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344669
|
5.0 |
MEDIUM
|
grandstream
|
budgetone_101 budgetone_102
|
Grandstream BudgeTone 101 and 102 running firmware 1.0.6.7 and possibly earlier versions, allows remote attackers to cause a denial of service (device hang or reboot) via a large UDP packet to port 5…
|
NVD-CWE-Other
|
CVE-2005-2581
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344670
|
3.6 |
LOW
|
kaspersky_lab
|
kaspersky_anti-virus
|
Kaspersky Anti-Virus for Unix/Linux File Servers 5.0-5 uses world-writable permissions for the (1) log and (2) license directory, which allows local users to delete log files, append to arbitrary fil…
|
NVD-CWE-Other
|
CVE-2005-2582
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344671
|
7.5 |
HIGH
|
mentor
|
adslfr4ii
|
Mentor ADSL-FR4II router running firmware 2.00.0111 has an undocumented web server running on TCP port 5678, which allows local users to gain access.
|
NVD-CWE-Other
|
CVE-2005-2583
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344672
|
7.2 |
HIGH
|
-
|
-
|
The web administration interface in Mentor ADSL-FR4II router running firmware 2.00.0111 does not set a default password, which allows local users to gain access.
|
NVD-CWE-Other
|
CVE-2005-2584
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344673
|
5.0 |
MEDIUM
|
mentor
|
adslfr4ii
|
Mentor ADSL-FR4II router running firmware 2.00.0111 allows remote attackers to cause a denial of service (active TCP connections state table consumption) via a large number of connections, such as a …
|
NVD-CWE-Other
|
CVE-2005-2585
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344674
|
2.1 |
LOW
|
mentor
|
adslfr4ii
|
Mentor ADSL-FR4II router running firmware 2.00.0111 stores the web administration password in cleartext in the backup configuration file, which allows local users to obtain sensitive information.
|
NVD-CWE-Other
|
CVE-2005-2586
|
2016-10-18 12:28 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344675
|
5.0 |
MEDIUM
|
ecw-shop
|
ecw-shop
|
index.php in ECW-Shop 6.0.2 allows remote attackers to obtain sensitive information via the (1) min or (2) max parameter with a "'" (single quote), which reveals the path in an error message, possibl…
|
NVD-CWE-Other
|
CVE-2005-2621
|
2016-10-18 12:28 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344676
|
4.3 |
MEDIUM
|
ecw-shop
|
ecw-shop
|
Cross-site scripting (XSS) vulnerability in index.php in ECW-Shop 6.0.2 allows remote attackers to inject arbitrary web script or HTML via the (1) max or (2) ctg parameter.
|
NVD-CWE-Other
|
CVE-2005-2622
|
2016-10-18 12:28 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344677
|
5.0 |
MEDIUM
|
gforge
|
gforge
|
The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail address, which allows remote attackers to send a large numb…
|
NVD-CWE-Other
|
CVE-2005-2431
|
2016-10-18 12:27 |
2005-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344678
|
5.8 |
MEDIUM
|
kayako
|
liveresponse
|
Multiple cross-site scripting (XSS) vulnerabilities in Kayako liveResponse 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter or (2) name field when ente…
|
NVD-CWE-Other
|
CVE-2005-2460
|
2016-10-18 12:27 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344679
|
6.4 |
MEDIUM
|
kayako
|
liveresponse
|
Multiple SQL injection vulnerabilities in the calendar feature in Kayako liveResponse 2.x allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) date parameter.
|
NVD-CWE-Other
|
CVE-2005-2461
|
2016-10-18 12:27 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344680
|
2.1 |
LOW
|
kayako
|
liveresponse
|
Kayako liveResponse 2.x, when logging in a user, records the password in plaintext in the URL, which allows local users and possibly remote attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-2462
|
2016-10-18 12:27 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344681
|
6.4 |
MEDIUM
|
kayako
|
liveresponse
|
Kayako liveResponse 2.x allows remote attackers to obtain sensitive information via a direct request to addressbook.php and other include scripts, which reveals the path in an error message.
|
NVD-CWE-Other
|
CVE-2005-2463
|
2016-10-18 12:27 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344682
|
7.5 |
HIGH
|
pcxp_toppe_cms
|
pcxp_toppe_cms
|
login.php in PCXP/TOPPE CMS allows remote attackers to bypass authentication and gain privileges by modifying the cookie to match the target userid.
|
NVD-CWE-Other
|
CVE-2005-2464
|
2016-10-18 12:27 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344683
|
5.8 |
MEDIUM
|
pc-experience toppe
|
pc-experience toppe_cms
|
Cross-site scripting (XSS) vulnerability in pm.php in PCXP/TOPPE CMS allows remote attackers to inject arbitrary web script or HTML via the msg variable.
|
NVD-CWE-Other
|
CVE-2005-2465
|
2016-10-18 12:27 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344684
|
5.8 |
MEDIUM
|
mysql
|
eventum
|
Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to view.php, (2) release …
|
NVD-CWE-Other
|
CVE-2005-2467
|
2016-10-18 12:27 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344685
|
6.4 |
MEDIUM
|
mysql
|
eventum
|
Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorrectPassword or (2) userExist function in class.aut…
|
NVD-CWE-Other
|
CVE-2005-2468
|
2016-10-18 12:27 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344686
|
5.0 |
MEDIUM
|
macromedia
|
coldfusion_fusebox
|
ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server path in an error message, as demonstrated using the "…
|
NVD-CWE-Other
|
CVE-2005-2481
|
2016-10-18 12:27 |
2005-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344687
|
4.3 |
MEDIUM
|
phpcounter
|
phpcounter
|
Cross-site scripting (XSS) vulnerability in PHPCounter 7.2 allows remote attackers to inject arbitrary web script or HTML via the EpochPrefix parameter.
|
NVD-CWE-Other
|
CVE-2005-2288
|
2016-10-18 12:26 |
2005-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344688
|
5.0 |
MEDIUM
|
phpcounter
|
phpcounter
|
PHPCounter 7.2 allows remote attackers to obtain sensitive information via a direct request to prelims.php, which reveals the path in an error message.
|
NVD-CWE-Other
|
CVE-2005-2289
|
2016-10-18 12:26 |
2005-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344689
|
10.0 |
HIGH
|
-
|
-
|
wps_shop.cgi in WPS Web Portal System 0.7.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and (2) cat variables.
|
NVD-CWE-Other
|
CVE-2005-2290
|
2016-10-18 12:26 |
2005-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344690
|
4.6 |
MEDIUM
|
oracle
|
jdeveloper
|
Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which allows local users to gain sensitive information.
|
NVD-CWE-Other
|
CVE-2005-2291
|
2016-10-18 12:26 |
2005-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344691
|
5.0 |
MEDIUM
|
yabb
|
yabb
|
YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.
|
NVD-CWE-Other
|
CVE-2005-2296
|
2016-10-18 12:26 |
2005-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344692
|
4.6 |
MEDIUM
|
sybase
|
easerver
|
Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter.
|
NVD-CWE-Other
|
CVE-2005-2297
|
2016-10-18 12:26 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344693
|
5.0 |
MEDIUM
|
softwin
|
bitdefender_engine
|
BitDefender Engine 1.6.1 and earlier does not properly scan all attachments, which allows remote attackers to bypass virus scanning via begin and end commands in the body of the e-mail, which BitDefe…
|
NVD-CWE-Other
|
CVE-2005-2298
|
2016-10-18 12:26 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344694
|
4.3 |
MEDIUM
|
-
|
-
|
Multiple cross-site scripting (XSS) vulnerabilities in Simple Message Board Version 2.0 Beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) FID parameter to forum.cfm, (2…
|
NVD-CWE-Other
|
CVE-2005-2299
|
2016-10-18 12:26 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344695
|
2.1 |
LOW
|
skype_technologies
|
skype
|
Skype 1.1.0.20 and earlier allows local users to overwrite arbitrary files via a symlink attack on the skype_profile.jpg temporary file.
|
NVD-CWE-Other
|
CVE-2005-2300
|
2016-10-18 12:26 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344696
|
5.0 |
MEDIUM
|
powerdns
|
powerdns
|
PowerDNS before 2.9.18, when running with an LDAP backend, does not properly escape LDAP queries, which allows remote attackers to cause a denial of service (failure to answer ldap questions) and pos…
|
NVD-CWE-Other
|
CVE-2005-2301
|
2016-10-18 12:26 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344697
|
2.1 |
LOW
|
powerdns
|
powerdns
|
PowerDNS before 2.9.18, when allowing recursion to a restricted range of IP addresses, does not properly handle questions from clients that are denied recursion, which could cause a "blank out" of an…
|
NVD-CWE-Other
|
CVE-2005-2302
|
2016-10-18 12:26 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344698
|
4.3 |
MEDIUM
|
xoops
|
xoops
|
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.12 JP and earlier, XOOPS 2.0.13.1 and earlier, and 2.2.x up to 2.2.3 RC1 allow remote attackers to inject arbitrary web script or HTML…
|
NVD-CWE-Other
|
CVE-2005-2338
|
2016-10-18 12:26 |
2005-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344699
|
7.5 |
HIGH
|
novell
|
groupwise
|
Buffer overflow in Novell GroupWise 6.5 Client allows remote attackers to execute arbitrary code via a GWVW02xx.INI language file with a long entry, as demonstrated using a long ES02TKS.VEW value in …
|
NVD-CWE-Other
|
CVE-2005-2346
|
2016-10-18 12:26 |
2005-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344700
|
7.2 |
HIGH
|
oracle
|
forms
|
Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicio…
|
NVD-CWE-Other
|
CVE-2005-2372
|
2016-10-18 12:26 |
2005-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|