|
344701
|
5.0 |
MEDIUM
|
codemasters
|
toca_race_driver
|
Format string vulnerability in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash) via format string specifiers in a (1) nickname or (2) chat message.
|
NVD-CWE-Other
|
CVE-2005-2375
|
2016-10-18 12:26 |
2005-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344702
|
5.0 |
MEDIUM
|
codemasters
|
toca_race_driver
|
Buffer overflow in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash) via a long (1) nickname or (2) chat message.
|
NVD-CWE-Other
|
CVE-2005-2376
|
2016-10-18 12:26 |
2005-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344703
|
4.3 |
MEDIUM
|
oracle
|
reports
|
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Reports 9.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) debug parameter to showenv, (2) test parameter to…
|
NVD-CWE-Other
|
CVE-2005-2379
|
2016-10-18 12:26 |
2005-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344704
|
5.0 |
MEDIUM
|
php_surveyor
|
php_surveyor
|
Multiple cross-site scripting vulnerabilities in PHP Surveyor 0.98 allow remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) start, and (3) id parameters to browse.php, or th…
|
NVD-CWE-Other
|
CVE-2005-2380
|
2016-10-18 12:26 |
2005-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344705
|
5.0 |
MEDIUM
|
php_surveyor
|
php_surveyor
|
PHP Surveyor 0.98 allows remote attackers to obtain sensitive information via a direct request to (1) question.php, (2) survey.php, or (3) group.php in the root directory, a direct request to (4) dat…
|
NVD-CWE-Other
|
CVE-2005-2381
|
2016-10-18 12:26 |
2005-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344706
|
7.2 |
HIGH
|
oray
|
peanuthull
|
Oray PeanutHull 3.0.1.0 and earlier does not properly drop SYSTEM privileges when launched from the system tray, which allows local users to gain privileges by accessing the Help functionality.
|
NVD-CWE-Other
|
CVE-2005-2382
|
2016-10-18 12:26 |
2005-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344707
|
7.5 |
HIGH
|
phpnews
|
phpnews
|
SQL injection vulnerability in auth.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the user parameter in an HTTP POST request.
|
NVD-CWE-Other
|
CVE-2005-2383
|
2016-10-18 12:26 |
2005-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344708
|
6.4 |
MEDIUM
|
proftpd_project
|
proftpd
|
Multiple format string vulnerabilities in ProFTPD before 1.3.0rc2 allow attackers to cause a denial of service or obtain sensitive information via (1) certain inputs to the shutdown message from ftps…
|
NVD-CWE-Other
|
CVE-2005-2390
|
2016-10-18 12:26 |
2005-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344709
|
7.5 |
HIGH
|
php_surveyor
|
php_surveyor
|
PHP Surveyor 0.98 allows remote attackers to trigger SQL errors via missing parameters to (1) browse.php, (2) export.php, (3) conditions.php, or (4) spss.php.
|
NVD-CWE-Other
|
CVE-2005-2399
|
2016-10-18 12:26 |
2005-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344710
|
4.3 |
MEDIUM
|
beehive_forum
|
beehive_forum
|
Cross-site scripting (XSS) vulnerability in index.php in Beehive Forum allows remote attackers to inject arbitrary web script or HTML via the webtag parameter.
|
NVD-CWE-Other
|
CVE-2005-2422
|
2016-10-18 12:26 |
2005-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344711
|
4.3 |
MEDIUM
|
wordpress
|
wordpress
|
Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.
|
NVD-CWE-Other
|
CVE-2005-2107
|
2016-10-18 12:25 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344712
|
7.5 |
HIGH
|
wordpress
|
wordpress
|
SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variab…
|
NVD-CWE-Other
|
CVE-2005-2108
|
2016-10-18 12:25 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344713
|
5.0 |
MEDIUM
|
wordpress
|
wordpress
|
wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.
|
NVD-CWE-Other
|
CVE-2005-2109
|
2016-10-18 12:25 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344714
|
7.5 |
HIGH
|
community_link_pro_web_editor
|
community_link_pro_web_editor
|
login.cgi in Community Link Pro Web Editor allows remote attackers to execute arbitrary commands via the file parameter.
|
NVD-CWE-Other
|
CVE-2005-2111
|
2016-10-18 12:25 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344715
|
4.3 |
MEDIUM
|
xoops
|
xoops
|
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter to edit.php or (2) cid parame…
|
NVD-CWE-Other
|
CVE-2005-2112
|
2016-10-18 12:25 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344716
|
7.5 |
HIGH
|
xoops
|
xoops
|
SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted …
|
NVD-CWE-Other
|
CVE-2005-2113
|
2016-10-18 12:25 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344717
|
5.0 |
MEDIUM
|
raven_software
|
soldier_of_fortune_2
|
Soldier of Fortune II 1.02x and 1.03 allows remote attackers to cause a denial of service (server crash) via a large ID value in the ignore command, which is used as an array index and causes an out-…
|
NVD-CWE-Other
|
CVE-2005-2115
|
2016-10-18 12:25 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344718
|
2.1 |
LOW
|
sco
|
unixware
|
RPC portmapper (rpcbind) in SCO UnixWare 7.1.1 m5, 7.1.3 mp5, and 7.1.4 mp2 allows remote attackers or local users to cause a denial of service (lack of response) via multiple invalid portmap request…
|
NVD-CWE-Other
|
CVE-2005-2132
|
2016-10-18 12:25 |
2005-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344719
|
7.5 |
HIGH
|
jboss
|
jbpm
|
A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vulnerability that was originally identified by CVE-2003-0845.
|
NVD-CWE-Other
|
CVE-2005-2158
|
2016-10-18 12:25 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344720
|
5.0 |
MEDIUM
|
planetdns
|
planetfileserver
|
mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request.
|
NVD-CWE-Other
|
CVE-2005-2159
|
2016-10-18 12:25 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344721
|
4.3 |
MEDIUM
|
phpbb_group
|
phpbb
|
Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote attackers to inject arbitrary web script or HTML via nested [url] tags.
|
NVD-CWE-Other
|
CVE-2005-2161
|
2016-10-18 12:25 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344722
|
5.0 |
MEDIUM
|
levcgi.com
|
myguestbook
|
PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter.
|
NVD-CWE-Other
|
CVE-2005-2162
|
2016-10-18 12:25 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344723
|
4.3 |
MEDIUM
|
autoindex
|
php_script
|
Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
|
NVD-CWE-Other
|
CVE-2005-2163
|
2016-10-18 12:25 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344724
|
7.5 |
HIGH
|
covide_groupware-crm
|
covide
|
SQL injection vulnerability in Covide Groupware-CRM allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2005-2164
|
2016-10-18 12:25 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344725
|
7.5 |
HIGH
|
probe.cgi
|
probe.cgi
|
probe.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the olddat parameter. NOTE: it is unclear which product or vendor this program is associated with, if any.
|
NVD-CWE-Other
|
CVE-2005-2178
|
2016-10-18 12:25 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344726
|
5.0 |
MEDIUM
|
jaws
|
jaws
|
PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter.
|
NVD-CWE-Other
|
CVE-2005-2179
|
2016-10-18 12:25 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344727
|
2.1 |
LOW
|
gnu
|
gnats
|
gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local u…
|
NVD-CWE-Other
|
CVE-2005-2180
|
2016-10-18 12:25 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344728
|
7.5 |
HIGH
|
phpxmail
|
phpxmail
|
class.xmail.php in PhpXmail 0.7 through 1.1 does not properly handle large passwords, which prevents an error message from being returned and allows remote attackers to bypass authentication and gain…
|
NVD-CWE-Other
|
CVE-2005-2183
|
2016-10-18 12:25 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344729
|
7.5 |
HIGH
|
emc
|
eroom
|
eRoom 6.x does not properly restrict files that can be attached, which allows remote attackers to execute arbitrary commands via a .lnk file.
|
NVD-CWE-Other
|
CVE-2005-2184
|
2016-10-18 12:25 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344730
|
7.5 |
HIGH
|
emc
|
eroom
|
eRoom does not set an expiration for Cookies, which allows remote attackers to capture cookies and conduct replay attacks.
|
NVD-CWE-Other
|
CVE-2005-2185
|
2016-10-18 12:25 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344731
|
1.9 |
LOW
|
mcafee
|
intrushield_security_management_system
|
Multiple cross-site scripting (XSS) vulnerabilities in McAfee IntruShield Security Management System allow remote authenticated users to inject arbitrary web script or HTML via the (1) thirdMenuName …
|
NVD-CWE-Other
|
CVE-2005-2186
|
2016-10-18 12:25 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344732
|
4.6 |
MEDIUM
|
mcafee
|
intrushield_security_management_system
|
McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true, as demonstrated using …
|
NVD-CWE-Other
|
CVE-2005-2187
|
2016-10-18 12:25 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344733
|
7.5 |
HIGH
|
mcafee
|
intrushield_security_management_system
|
McAfee IntruShield Security Management System obtains the user ID from the URL, which allows remote attackers to guess the Manager account and possibly gain privileges via a brute force attack.
|
NVD-CWE-Other
|
CVE-2005-2188
|
2016-10-18 12:25 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344734
|
5.0 |
MEDIUM
|
lantronix
|
securelinx
|
Lantronix SecureLinx console server running firmware 2.0 and 3.0 stores /etc/ssh under the web document root with insufficient access control, which allows remote attackers to obtain sensitive inform…
|
NVD-CWE-Other
|
CVE-2005-2189
|
2016-10-18 12:25 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344735
|
7.5 |
HIGH
|
comersus_open_technologies
|
comersus_cart
|
Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or (…
|
NVD-CWE-Other
|
CVE-2005-2190
|
2016-10-18 12:25 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344736
|
4.3 |
MEDIUM
|
comersus_open_technologies
|
comersus_cart
|
Multiple cross-site scripting (XSS) vulnerabilities in Comersus shopping cart allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to comersus_backoffice_listAssig…
|
NVD-CWE-Other
|
CVE-2005-2191
|
2016-10-18 12:25 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344737
|
5.0 |
MEDIUM
|
alexander_palmo
|
simple_php_blog
|
SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.
|
NVD-CWE-Other
|
CVE-2005-2192
|
2016-10-18 12:25 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344738
|
7.5 |
HIGH
|
punbb
|
punbb
|
SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote attackers to execute arbitrary SQL statements via the temp array, which is not ini…
|
NVD-CWE-Other
|
CVE-2005-2193
|
2016-10-18 12:25 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344739
|
5.0 |
MEDIUM
|
apple
|
darwin_streaming_server
|
Apple Darwin Streaming Server 5.5 and earlier allows remote attackers to cause a denial of service (application crash) via a URL with a filename containing a .cgi extension and an MS-DOS device name …
|
NVD-CWE-Other
|
CVE-2005-2195
|
2016-10-18 12:25 |
2005-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344740
|
7.5 |
HIGH
|
id_board
|
id_board
|
SQL injection vulnerability in sql.cls.php in Id Board 1.1.3 allows remote attackers to modify SQL queries, as demonstrated using the f parameter to index.php.
|
NVD-CWE-Other
|
CVE-2005-2197
|
2016-10-18 12:25 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344741
|
7.2 |
HIGH
|
softiacom
|
wmailserver
|
Softiacom wMailserver 1.0 stores passwords in plaintext in the Darsite\MAILSRV\Admin key, which allows local users to gain administrator privileges.
|
NVD-CWE-Other
|
CVE-2005-2227
|
2016-10-18 12:25 |
2005-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344742
|
7.5 |
HIGH
|
blog_torrent
|
blog_torrent
|
Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain …
|
NVD-CWE-Other
|
CVE-2005-2229
|
2016-10-18 12:25 |
2005-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344743
|
10.0 |
HIGH
|
phpslash
|
phpslash
|
The saveProfile function in PhpSlash 0.8.0 allows remote attackers to modify arbitrary profiles and gain privileges by modifying the author_id parameter.
|
NVD-CWE-Other
|
CVE-2005-2257
|
2016-10-18 12:25 |
2005-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344744
|
7.2 |
HIGH
|
mailenable
|
mailenable_professional
|
Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrary code via the status command with a long mailbox name.
|
NVD-CWE-Other
|
CVE-2005-2278
|
2016-10-18 12:25 |
2005-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344745
|
5.0 |
MEDIUM
|
softiacom
|
wmailserver
|
SoftiaCom wMailServer 1.0 and 2.0 allows remote attackers to cause a denial of service (application crash) via a large TCP packet with a leading space, possibly triggering a buffer overflow.
|
NVD-CWE-Other
|
CVE-2005-2287
|
2016-10-18 12:25 |
2005-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344746
|
5.0 |
MEDIUM
|
yaws
|
webserver
|
Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null).
|
NVD-CWE-Other
|
CVE-2005-2008
|
2016-10-18 12:24 |
2005-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344747
|
7.5 |
HIGH
|
ublog
|
reload
|
Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter t…
|
NVD-CWE-Other
|
CVE-2005-2009
|
2016-10-18 12:24 |
2005-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344748
|
4.3 |
MEDIUM
|
uapplication
|
ublog_reload
|
Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the btitle parameter.
|
NVD-CWE-Other
|
CVE-2005-2010
|
2016-10-18 12:24 |
2005-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344749
|
4.3 |
MEDIUM
|
php_arena
|
pafaq
|
Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the id parameter in a Question action.
|
NVD-CWE-Other
|
CVE-2005-2011
|
2016-10-18 12:24 |
2005-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344750
|
7.5 |
HIGH
|
php_arena
|
pafaq
|
Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) id parameters.
|
NVD-CWE-Other
|
CVE-2005-2012
|
2016-10-18 12:24 |
2005-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|