|
344901
|
7.2 |
HIGH
|
kristofer_szymanski
|
cocktail
|
Cocktail 3.5.4 and possibly earlier in Mac OS X passes the administrative password on the command line to sudo in cleartext, which allows local users to gain sensitive information by running listing …
|
NVD-CWE-Other
|
CVE-2005-1387
|
2016-10-18 12:19 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344902
|
4.6 |
MEDIUM
|
esri
|
arcinfo_workstation
|
Multiple buffer overflows in ArcGIS for ESRI ArcInfo Workstation 9.0 allow local users to execute arbitrary code via long command line arguments to (1) asmaster, (2) asuser, (3) asutility, (4) se, or…
|
NVD-CWE-Other
|
CVE-2005-1393
|
2016-10-18 12:19 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344903
|
7.5 |
HIGH
|
rsa
|
securid_web_agent
|
Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-encoding data.
|
NVD-CWE-Other
|
CVE-2005-1471
|
2016-10-18 12:19 |
2005-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344904
|
7.5 |
HIGH
|
oracle
|
database_server
|
SQL injection vulnerability in the SYS.DBMS_CDC_IPUBLISH.CREATE_SCN_CHANGE_SET procedure in Oracle Database Server 10g allows remote attackers to execute arbitrary SQL commands via the CHANGE_SET_NAM…
|
NVD-CWE-Other
|
CVE-2005-1197
|
2016-10-18 12:18 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344905
|
5.0 |
MEDIUM
|
anaconda_partners
|
foundation_directory
|
Directory traversal vulnerability in apexec.pl for Anaconda Foundation Directory allows remote attackers to read arbitrary files via hex-encoded null characters (%00) in the middle of ".." sequences …
|
NVD-CWE-Other
|
CVE-2005-1198
|
2016-10-18 12:18 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344906
|
7.5 |
HIGH
|
infopop
|
ultimate_bulletin_board
|
SQL injection vulnerability in printthread.php in UBB.Threads allows remote attackers to execute arbitrary SQL commands via the main parameter.
|
NVD-CWE-Other
|
CVE-2005-1199
|
2016-10-18 12:18 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344907
|
6.8 |
MEDIUM
|
egroupware
|
egroupware
|
Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via the (1) ab_id, (2) page, (3) type, or (4) lang par…
|
NVD-CWE-Other
|
CVE-2005-1202
|
2016-10-18 12:18 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344908
|
7.5 |
HIGH
|
egroupware
|
egroupware
|
Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands via the (1) filter or (2) cats_app parameter.
|
NVD-CWE-Other
|
CVE-2005-1203
|
2016-10-18 12:18 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344909
|
5.0 |
MEDIUM
|
nelso_software
|
desktop_rover
|
Desktop Rover 3.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a crafted packet to TCP port 61427, which causes an invalid memory acces…
|
NVD-CWE-Other
|
CVE-2005-1204
|
2016-10-18 12:18 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344910
|
5.0 |
MEDIUM
|
magnus_lundvall
|
yawcam
|
Directory traversal vulnerability in Yawcam 0.2.5 allows remote attackers to read arbitrary files via "..\" (dot dot backslash) sequences in a GET request.
|
NVD-CWE-Other
|
CVE-2005-1230
|
2016-10-18 12:18 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344911
|
6.8 |
MEDIUM
|
woltlab
|
burning_board
|
Cross-site scripting (XSS) vulnerability in thread.php in WoltLab Burning Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the hilight parameter.
|
NVD-CWE-Other
|
CVE-2005-1285
|
2016-10-18 12:18 |
2005-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344912
|
1.2 |
LOW
|
softwin
|
bitdefender_antivirus
|
Unquoted Windows search path vulnerability in BitDefender 8 allows local users to prevent BitDefender from starting by creating a malicious C:\program.exe, possibly due to the lack of quoting of the …
|
NVD-CWE-Other
|
CVE-2005-1286
|
2016-10-18 12:18 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344913
|
7.5 |
HIGH
|
asp_press
|
acs_blog
|
inc_login_check.asp ACS Blog 0.8 through 1.1.3 allows remote attackers to gain administrator privileges via the "in" value in a cookie.
|
NVD-CWE-Other
|
CVE-2005-1288
|
2016-10-18 12:18 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344914
|
7.5 |
HIGH
|
e-cart
|
e-cart
|
index.cgi in E-Cart 2004 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and possibly (2) cat parameters.
|
NVD-CWE-Other
|
CVE-2005-1289
|
2016-10-18 12:18 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344915
|
4.3 |
MEDIUM
|
phpbb_group
|
phpbb
|
Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) u parameter to profile.php, (2) highlight par…
|
NVD-CWE-Other
|
CVE-2005-1290
|
2016-10-18 12:18 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344916
|
7.5 |
HIGH
|
storeportal
|
storeportal
|
Multiple SQL injection vulnerabilities in default.asp in StorePortal 2.63 allow remote attackers to execute arbitrary SQL commands via the (1) language, (2) bpic, (3) idcategory, (4) content, (5) key…
|
NVD-CWE-Other
|
CVE-2005-1293
|
2016-10-18 12:18 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344917
|
7.2 |
HIGH
|
nokia
|
affix
|
The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a socket call with a negative protocol value, which is used as an array index.
|
NVD-CWE-Other
|
CVE-2005-1294
|
2016-10-18 12:18 |
2005-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344918
|
7.5 |
HIGH
|
include.cgi
|
include.cgi
|
include.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.
|
NVD-CWE-Other
|
CVE-2005-1295
|
2016-10-18 12:18 |
2005-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344919
|
7.5 |
HIGH
|
include.cgi
|
include.cgi
|
include.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.
|
NVD-CWE-Other
|
CVE-2005-1296
|
2016-10-18 12:18 |
2005-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344920
|
6.8 |
MEDIUM
|
include.cgi
|
include.cgi
|
Cross-site scripting (XSS) vulnerability in the include.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.
|
NVD-CWE-Other
|
CVE-2005-1297
|
2016-10-18 12:18 |
2005-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344921
|
7.5 |
HIGH
|
inserter.cgi
|
inserter.cgi
|
The inserter.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.
|
NVD-CWE-Other
|
CVE-2005-1298
|
2016-10-18 12:18 |
2005-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344922
|
10.0 |
HIGH
|
-
|
-
|
The inserter.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.
|
NVD-CWE-Other
|
CVE-2005-1299
|
2016-10-18 12:18 |
2005-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344923
|
6.8 |
MEDIUM
|
inserter.cgi
|
inserter.cgi
|
Cross-site scripting (XSS) vulnerability in the inserter.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.
|
NVD-CWE-Other
|
CVE-2005-1300
|
2016-10-18 12:18 |
2005-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344924
|
2.6 |
LOW
|
nprotect
|
netizen
|
nProtect:Netizen 2005.3.17.1 does not properly verify that the update module is downloaded from an authorized site, which allows remote malicious web sites to write arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-1301
|
2016-10-18 12:18 |
2005-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344925
|
7.5 |
HIGH
|
swsoft
|
confixx
|
SQL injection vulnerability in Confixx 3.08 and earlier allows remote attackers to execute arbitrary SQL commands via the "change user" field.
|
NVD-CWE-Other
|
CVE-2005-1302
|
2016-10-18 12:18 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344926
|
7.5 |
HIGH
|
citat.pl
|
citat.pl
|
The citat.pl script allows remote attackers to read arbitrary files via a full pathname in the argument.
|
NVD-CWE-Other
|
CVE-2005-1303
|
2016-10-18 12:18 |
2005-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344927
|
7.5 |
HIGH
|
-
|
-
|
The citat.pl script allows remote attackers to execute arbitrary files via shell metacharacters in the argument.
|
NVD-CWE-Other
|
CVE-2005-1304
|
2016-10-18 12:18 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344928
|
5.0 |
MEDIUM
|
hyper.cgi
|
hyper.cgi
|
The hyper.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.
|
NVD-CWE-Other
|
CVE-2005-1305
|
2016-10-18 12:18 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344929
|
5.0 |
MEDIUM
|
matthieu_aubry
|
phpmyvisites
|
set_lang.php in phpMyVisites 1.3 allows remote attackers to read and include arbitrary files via the mylang parameter.
|
NVD-CWE-Other
|
CVE-2005-1325
|
2016-10-18 12:18 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344930
|
4.6 |
MEDIUM
|
rsnapshot
|
filesystem_snapshot_utility
|
The copy_symlink function in rsnapshot 1.2.0 and 1.1.x before 1.1.7 changes the ownership of files that a symlink points to rather than the symlink itself, which allows local users to obtain access t…
|
NVD-CWE-Other
|
CVE-2005-1064
|
2016-10-18 12:17 |
2005-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344931
|
7.5 |
HIGH
|
-
|
-
|
SQL injection vulnerability in banner.inc.php in JPortal Web Portal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the haslo parameter.
|
NVD-CWE-Other
|
CVE-2005-1071
|
2016-10-18 12:17 |
2005-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344932
|
4.3 |
MEDIUM
|
xampp
|
apache_distribution
|
Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x allow remote attackers to inject arbitrary web script or HTML via (1) cds.php, (2) Guestbook-EN.pl, or (3) phonebook.php.
|
NVD-CWE-Other
|
CVE-2005-1077
|
2016-10-18 12:17 |
2005-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344933
|
7.5 |
HIGH
|
xampp
|
apache_distribution
|
XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-1078
|
2016-10-18 12:17 |
2005-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344934
|
7.5 |
HIGH
|
-
|
-
|
SQL injection vulnerability in index.php for zOOm Media Gallery 2.1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
|
NVD-CWE-Other
|
CVE-2005-1079
|
2016-10-18 12:17 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344935
|
6.8 |
MEDIUM
|
wordpress
|
wordpress
|
Multiple cross-site scripting (XSS) vulnerabilities in template-functions-post.php in WordPress 1.5 and earlier allow remote attackers to execute arbitrary commands via the (1) content or (2) title o…
|
NVD-CWE-Other
|
CVE-2005-1102
|
2016-10-18 12:17 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344936
|
4.6 |
MEDIUM
|
sygate_technologies
|
security_agent
|
Sygate Security Agent (SSA) in Sygate Secure Enterprise 3.5 through 4.1 does not prevent the security policy from being updated by unprivileged users, which allows local users to modify the policy by…
|
NVD-CWE-Other
|
CVE-2005-1103
|
2016-10-18 12:17 |
2005-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344937
|
4.3 |
MEDIUM
|
centra
|
centra
|
Multiple cross-site scripting (XSS) vulnerabilities in Centra 7 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name fields.
|
NVD-CWE-Other
|
CVE-2005-1104
|
2016-10-18 12:17 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344938
|
5.0 |
MEDIUM
|
sun
|
javamail
|
Directory traversal vulnerability in the MimeBodyPart.getFileName method in JavaMail 1.3.2 allows remote attackers to write arbitrary files via a .. (dot dot) in the filename in the Content-Dispositi…
|
NVD-CWE-Other
|
CVE-2005-1105
|
2016-10-18 12:17 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344939
|
5.0 |
MEDIUM
|
apple
|
quicktime_pictureviewer
|
PictureViewer in QuickTime for Windows 6.5.2 allows remote attackers to cause a denial of service (application crash) via a GIF image with the maximum depth start value, possibly triggering an intege…
|
NVD-CWE-Other
|
CVE-2005-1106
|
2016-10-18 12:17 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344940
|
4.3 |
MEDIUM
|
phpbb_group smartor
|
phpbb photo_album
|
Multiple cross-site scripting (XSS) vulnerabilities in Photo Album 2.0.53 module for phpBB allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) album_cat.php or…
|
NVD-CWE-Other
|
CVE-2005-1115
|
2016-10-18 12:17 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344941
|
4.3 |
MEDIUM
|
phpbb_group
|
phpbb
|
Cross-site scripting (XSS) vulnerability in the Calendar module for phpBB allow remote attackers to inject arbitrary web script or HTML via the start parameter to calendar_scheduler.php.
|
NVD-CWE-Other
|
CVE-2005-1116
|
2016-10-18 12:17 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344942
|
7.5 |
HIGH
|
all4www
|
all4www-homepagecreator
|
PHP remote file inclusion vulnerability in index.php in All4WWW-Homepagecreator 1.0a allows remote attackers to execute arbitrary PHP code by modifying the site parameter to reference a URL on a remo…
|
NVD-CWE-Other
|
CVE-2005-1117
|
2016-10-18 12:17 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344943
|
5.0 |
MEDIUM
|
ibm
|
iseries_as_400
|
The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid user IDs on the server.
|
NVD-CWE-Other
|
CVE-2005-1133
|
2016-10-18 12:17 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344944
|
4.3 |
MEDIUM
|
alexander_palmo
|
simple_php_blog
|
Cross-site scripting (XSS) vulnerability in search.php for Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
|
NVD-CWE-Other
|
CVE-2005-1135
|
2016-10-18 12:17 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344945
|
5.0 |
MEDIUM
|
sphpblog
|
sphpblog
|
Simple PHP Blog (sphpBlog) 0.4.0 stores the (1) password.txt and (2) config.txt files under the web document root, which allows remote attackers to obtain sensitive information and crack passwords vi…
|
NVD-CWE-Other
|
CVE-2005-1136
|
2016-10-18 12:17 |
2005-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344946
|
5.0 |
MEDIUM
|
alexander_palmo
|
simple_php_blog
|
Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to obtain sensitive information via a direct request to sb_functions.php, which leaks the full pathname in a PHP error message.
|
NVD-CWE-Other
|
CVE-2005-1137
|
2016-10-18 12:17 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344947
|
7.5 |
HIGH
|
gocr
|
optical_character_recognition_utility
|
Heap-based buffer overflow in the readpgm function in pnm.c for GOCR 0.40, when it is not using netpbm, allows remote attackers to execute arbitrary code via a P3 format PNM file with more data than …
|
NVD-CWE-Other
|
CVE-2005-1142
|
2016-10-18 12:17 |
2005-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344948
|
2.1 |
LOW
|
dameware_development
|
dameware_nt_utilities miniremote_control
|
The DNTUS26 process in Dameware NT Utilities and the DWRCS process in MiniRemote Control 4.9 and earlier stores the username and password in cleartext in memory, which could allow attackers to obtain…
|
NVD-CWE-Other
|
CVE-2005-1166
|
2016-10-18 12:17 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344949
|
2.1 |
LOW
|
musicmatch
|
jukebox
|
Musicmatch 10.00.2047 and earlier store log files in the Program Files directory instead of the user profile, which may allow local users to obtain sensitive information.
|
NVD-CWE-Other
|
CVE-2005-1167
|
2016-10-18 12:17 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344950
|
5.0 |
MEDIUM
|
musicmatch
|
jukebox
|
DiagCollectionControl.dll in Musicmatch 10.00.2047 and earlier allows remote attackers to overwrite arbitrary files via the bstrSavePath argument.
|
NVD-CWE-Other
|
CVE-2005-1168
|
2016-10-18 12:17 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|