|
344751
|
5.0 |
MEDIUM
|
php_arena
|
pafaq
|
paFAQ 1.0 Beta 4 allows remote attackers to obtain sensitive information via a direct request to admin/backup.php, which contains a backup of the database including usernames and passwords.
|
NVD-CWE-Other
|
CVE-2005-2013
|
2016-10-18 12:24 |
2005-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344752
|
4.6 |
MEDIUM
|
php_arena
|
pafaq
|
The "upload a language pack" feature in paFAQ 1.0 Beta 4 allows remote authenticated administrators to execute arbitrary PHP commands by uploading a malicious language pack.
|
NVD-CWE-Other
|
CVE-2005-2014
|
2016-10-18 12:24 |
2005-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344753
|
7.5 |
HIGH
|
mercuryboard
|
mercuryboard_message_board
|
SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.
|
NVD-CWE-Other
|
CVE-2005-2028
|
2016-10-18 12:24 |
2005-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344754
|
5.0 |
MEDIUM
|
ultimate_php_board
|
ultimate_php_board
|
Ultimate PHP Board (UPB) 1.9.6 GOLD uses weak encryption for passwords in the users.dat file, which allows attackers to easily decrypt the passwords and gain privileges, possibly after exploiting CVE…
|
NVD-CWE-Other
|
CVE-2005-2030
|
2016-10-18 12:24 |
2005-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344755
|
5.0 |
MEDIUM
|
blue-collar_productions
|
i-gallery
|
Directory traversal vulnerability in folderview.asp for Blue-Collar Productions i-Gallery 3.3 allows remote attackers to read arbitrary files and directories via the folder parameter.
|
CWE-22
Path Traversal
|
CVE-2005-2033
|
2016-10-18 12:24 |
2005-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344756
|
4.3 |
MEDIUM
|
blue-collar_productions
|
i-gallery
|
Cross-site scripting (XSS) vulnerability in folderview.asp for BlueCollar iGallery 3.3 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.
|
NVD-CWE-Other
|
CVE-2005-2034
|
2016-10-18 12:24 |
2005-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344757
|
7.5 |
HIGH
|
duware
|
duportal_pro
|
Multiple SQL injection vulnerabilities in DUware DUportal PRO 3.4.3 allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to default.asp, (2) iData parameter to deta…
|
NVD-CWE-Other
|
CVE-2005-2045
|
2016-10-18 12:24 |
2005-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344758
|
7.5 |
HIGH
|
duware
|
duamazon_pro
|
Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iSub parameter to sub.asp…
|
NVD-CWE-Other
|
CVE-2005-2046
|
2016-10-18 12:24 |
2005-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344759
|
7.5 |
HIGH
|
duware
|
dupaypal_pro
|
Multiple SQL injection vulnerabilities in DUware DUpaypal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iPro parameter to detail.asp, (3)…
|
NVD-CWE-Other
|
CVE-2005-2047
|
2016-10-18 12:24 |
2005-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344760
|
7.5 |
HIGH
|
duware
|
duclassmate
|
Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState parameter to default.asp or (2) iPro parameter to edit.asp.
|
NVD-CWE-Other
|
CVE-2005-2049
|
2016-10-18 12:24 |
2005-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344761
|
7.5 |
HIGH
|
symantec_veritas
|
backup_exec
|
Buffer overflow in the VERITAS Backup Exec Web Administration Console (BEWAC) 9.0 4367 through 10.0 rev. 5484 allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-2051
|
2016-10-18 12:24 |
2005-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344762
|
5.1 |
MEDIUM
|
realnetworks
|
realone_player realplayer
|
Heap-based buffer overflow in vidplin.dll in RealPlayer 10 and 10.5 (6.0.12.1040 through 1069), RealOne Player v1 and v2, RealPlayer 8 and RealPlayer Enterprise allows remote attackers to execute arb…
|
NVD-CWE-Other
|
CVE-2005-2052
|
2016-10-18 12:24 |
2005-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344763
|
5.0 |
MEDIUM
|
salims_softhouse
|
jaf_cms
|
Just another flat file (JAF) CMS before 3.0 Final allows remote attackers to obtain sensitive information via (1) an * (asterisk) in the id parameter, (2) a blank id parameter, or (3) an * (asterisk)…
|
NVD-CWE-Other
|
CVE-2005-2053
|
2016-10-18 12:24 |
2005-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344764
|
6.8 |
MEDIUM
|
ubbcentral
|
ubb.threads
|
Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or HTML via the (1) Searchpage parameter to dosearch…
|
NVD-CWE-Other
|
CVE-2005-2057
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344765
|
7.5 |
HIGH
|
ubbcentral
|
ubb.threads
|
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.p…
|
NVD-CWE-Other
|
CVE-2005-2058
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344766
|
5.0 |
MEDIUM
|
ubbcentral
|
ubb.threads
|
Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to spoof web conten…
|
NVD-CWE-Other
|
CVE-2005-2060
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344767
|
5.0 |
MEDIUM
|
ubbcentral
|
ubb.threads
|
Infopop UBB.Threads before 6.5.2 Beta allows remote attackers to include arbitrary files via the language parameter in a cookie followed by a null (%00) byte.
|
NVD-CWE-Other
|
CVE-2005-2061
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344768
|
4.3 |
MEDIUM
|
active_web_softwares
|
activebuyandsell
|
Multiple cross-site scripting (XSS) vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to sendpassword.asp or (2) Keywor…
|
NVD-CWE-Other
|
CVE-2005-2063
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344769
|
5.0 |
MEDIUM
|
asp-nuke
|
asp-nuke
|
Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to forgot_password.asp, or the (2) FirstName, …
|
NVD-CWE-Other
|
CVE-2005-2064
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344770
|
5.0 |
MEDIUM
|
asp-nuke
|
asp-nuke
|
HTTP response splitting vulnerability in language_select.asp in ASP Nuke 0.80 allows remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the LangCode paramete…
|
NVD-CWE-Other
|
CVE-2005-2065
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344771
|
7.5 |
HIGH
|
asp-nuke
|
asp-nuke
|
SQL injection vulnerability in comment_post.asp in ASP Nuke 0.80 allows remote attackers to execute arbitrary SQL statements via the TaskID parameter.
|
NVD-CWE-Other
|
CVE-2005-2066
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344772
|
7.5 |
HIGH
|
asp-nuke
|
asp-nuke
|
SQL injection vulnerability in article.asp in unknown versions of aspnuke allows remote attackers to execute arbitrary SQL commands via the articleid parameter.
|
NVD-CWE-Other
|
CVE-2005-2067
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344773
|
4.6 |
MEDIUM
|
sun
|
solaris
|
traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malformed -s argument with …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2005-2071
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344774
|
5.0 |
MEDIUM
|
cgi-club
|
imtrset
|
im_trbbs.cgi in imTRSET 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the df parameter.
|
NVD-CWE-Other
|
CVE-2005-2082
|
2016-10-18 12:24 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344775
|
4.3 |
MEDIUM
|
telligent_systems
|
community_server_forums
|
Cross-site scripting (XSS) vulnerability in SearchResults.aspx in Community Forum allows remote attackers to inject arbitrary web script or HTML via the q parameter.
|
NVD-CWE-Other
|
CVE-2005-2084
|
2016-10-18 12:24 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344776
|
5.0 |
MEDIUM
|
infradig_systems
|
inframail_advantage
|
Buffer overflow in Inframail Advantage Server Edition 6.0 through 6.7 allows remote attackers to cause a denial of service (process crash) via a long (1) SMTP FROM field or possibly (2) FTP NLST comm…
|
NVD-CWE-Other
|
CVE-2005-2085
|
2016-10-18 12:24 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344777
|
7.5 |
HIGH
|
phpbb_group
|
phpbb
|
PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.
|
NVD-CWE-Other
|
CVE-2005-2086
|
2016-10-18 12:24 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344778
|
5.0 |
MEDIUM
|
drupal
|
drupal
|
Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.
|
NVD-CWE-Other
|
CVE-2005-2106
|
2016-10-18 12:24 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344779
|
5.0 |
MEDIUM
|
phpcms
|
phpcms
|
Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x before 1.2.1pl2 allows remote attackers to read or include arbitrary files, as demonstrated using a .. (dot dot) in the la…
|
NVD-CWE-Other
|
CVE-2005-1840
|
2016-10-18 12:23 |
2005-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344780
|
10.0 |
HIGH
|
ekg
|
ekg
|
Certain contributed scripts for ekg Gadu Gadu client 1.5 and earlier create temporary files insecurely, with unknown impact and attack vectors, a different vulnerability than CVE-2005-1916.
|
NVD-CWE-Other
|
CVE-2005-1850
|
2016-10-18 12:23 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344781
|
10.0 |
HIGH
|
ekg
|
ekg
|
A certain contributed script for ekg Gadu Gadu client 1.5 and earlier allows attackers to execute shell commands via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2005-1851
|
2016-10-18 12:23 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344782
|
5.0 |
MEDIUM
|
popper
|
popper
|
PHP remote file inclusion vulnerability in childwindow.inc.php in Popper 1.41-r2 and earlier allows remote attackers to execute arbitrary PHP code via the form parameter.
|
NVD-CWE-Other
|
CVE-2005-1870
|
2016-10-18 12:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344783
|
7.5 |
HIGH
|
drupal
|
drupal
|
Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain privileges, due to an "input check" that "is not impl…
|
NVD-CWE-Other
|
CVE-2005-1871
|
2016-10-18 12:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344784
|
7.5 |
HIGH
|
ibm
|
websphere_application_server
|
Buffer overflow in the administrative console in IBM WebSphere Application Server 5.x, when the global security option is enabled, allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-1872
|
2016-10-18 12:23 |
2005-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344785
|
7.5 |
HIGH
|
exhibit_engine
|
exhibit_engine
|
Multiple SQL injection vulnerabilities in list.php in Exhibit Engine (EE) 1.22 allow remote attackers to execute arbitrary SQL commands via the (1) search_row, (2) sort_row, (3) order or (4) perpage …
|
NVD-CWE-Other
|
CVE-2005-1875
|
2016-10-18 12:23 |
2005-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344786
|
5.0 |
MEDIUM
|
rakkarsoft
|
raknet
|
Rakkarsoft RakNet network library 2.33 and earlier, when released before 30 May 2005, and as used in multiple products including nFusion Elite Warriors: Vietnam, allows remote attackers to cause a de…
|
NVD-CWE-Other
|
CVE-2005-1899
|
2016-10-18 12:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344787
|
7.2 |
HIGH
|
kaspersky_lab
|
kaspersky_anti-virus kaspersky_anti-virus_personal
|
The klif.sys driver in Kaspersky Labs Anti-Virus 5.0.227, 5.0.228, and 5.0.335 on Windows 2000 allows local users to gain privileges by modifying certain critical code addresses that are later access…
|
NVD-CWE-Other
|
CVE-2005-1905
|
2016-10-18 12:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344788
|
5.0 |
MEDIUM
|
goodtech_systems
|
goodtech_smtp_server
|
GoodTech SMTP Server 5.14 allows remote attackers to cause a denial of service (application crash) via a RCPT TO command with an invalid argument, as demonstrated using an "A" character.
|
NVD-CWE-Other
|
CVE-2005-1931
|
2016-10-18 12:23 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344789
|
7.5 |
HIGH
|
-
|
-
|
Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.…
|
NVD-CWE-Other
|
CVE-2005-1943
|
2016-10-18 12:23 |
2005-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344790
|
2.1 |
LOW
|
xmysqladmin
|
xmysqladmin
|
xmysqladmin 1.0 and earlier allows local users to delete arbitrary files via a symlink attack on a database backup file in /tmp.
|
NVD-CWE-Other
|
CVE-2005-1944
|
2016-10-18 12:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344791
|
4.3 |
MEDIUM
|
invision_power_services
|
invision_community_blog
|
Cross-site scripting (XSS) vulnerability in the convert_highlite_words function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encod…
|
NVD-CWE-Other
|
CVE-2005-1945
|
2016-10-18 12:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344792
|
7.5 |
HIGH
|
invision_power_services
|
invision_community_blog
|
Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomme…
|
NVD-CWE-Other
|
CVE-2005-1946
|
2016-10-18 12:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344793
|
7.5 |
HIGH
|
invision_power_services
|
invision_gallery
|
Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rati…
|
NVD-CWE-Other
|
CVE-2005-1948
|
2016-10-18 12:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344794
|
7.5 |
HIGH
|
darryl_burgdorf
|
webhints
|
hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.
|
NVD-CWE-Other
|
CVE-2005-1950
|
2016-10-18 12:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344795
|
5.0 |
MEDIUM
|
oscommerce
|
oscommerce
|
Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences …
|
NVD-CWE-Other
|
CVE-2005-1951
|
2016-10-18 12:23 |
2005-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344796
|
7.5 |
HIGH
|
pico_server
|
pico_server
|
Directory traversal vulnerability in Pico Server (pServ) 3.3 allows remote attackers to read arbitrary files and execute arbitrary commands via a /./ (slash dot slash) before each .. (dot dot) sequen…
|
NVD-CWE-Other
|
CVE-2005-1952
|
2016-10-18 12:23 |
2005-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344797
|
7.5 |
HIGH
|
pico_server
|
pico_server
|
Heap-based buffer overflow in the CGI extension for Pico Server (pServ) 3.3 allows remote attackers to execute arbitrary code via a long HTTP request.
|
NVD-CWE-Other
|
CVE-2005-1953
|
2016-10-18 12:23 |
2005-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344798
|
5.0 |
MEDIUM
|
singapore
|
singapore
|
singapore 0.9.11 allows remote attackers to obtain sensitive information via a direct request to (1) admin.class.php, (2) any .tpl.php file in templates/admin_default/, or (3) any .tpl.php file in te…
|
NVD-CWE-Other
|
CVE-2005-1954
|
2016-10-18 12:23 |
2005-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344799
|
4.3 |
MEDIUM
|
singapore
|
singapore
|
Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.11 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter.
|
NVD-CWE-Other
|
CVE-2005-1955
|
2016-10-18 12:23 |
2005-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344800
|
5.0 |
MEDIUM
|
file_upload_manager
|
file_upload_manager
|
File Upload Manager allows remote attackers to upload arbitrary files by modifying the test variable to contain a value of '~~~~~~' (six tildes), which bypasses the file extension checks.
|
NVD-CWE-Other
|
CVE-2005-1956
|
2016-10-18 12:23 |
2005-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|