|
345401
|
5.0 |
MEDIUM
|
mcgallery
|
mcgallery_pro
|
Directory traversal vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to read arbitrary files via the language parameter.
|
NVD-CWE-Other
|
CVE-2005-4250
|
2011-03-8 11:27 |
2005-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345402
|
7.5 |
HIGH
|
mcgallery
|
mcgallery_pro
|
Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and th…
|
NVD-CWE-Other
|
CVE-2005-4251
|
2011-03-8 11:27 |
2005-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345403
|
4.3 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters.
|
NVD-CWE-Other
|
CVE-2005-4252
|
2011-03-8 11:27 |
2005-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345404
|
7.5 |
HIGH
|
dreamlevels
|
dream_poll
|
SQL injection vulnerability in view_Results.php in DreamLevels DreamPoll 3.0 final allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2005-4254
|
2011-03-8 11:27 |
2005-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345405
|
4.3 |
MEDIUM
|
wikkawiki
|
wikkawiki
|
Cross-site scripting (XSS) vulnerability in TextSearch in WikkaWiki 1.1.6.0 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded phrase parameter.
|
NVD-CWE-Other
|
CVE-2005-4255
|
2011-03-8 11:27 |
2005-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345406
|
4.3 |
MEDIUM
|
envolution
|
envolution
|
Cross-site scripting (XSS) vulnerability in the News module in Envolution allows remote attackers to inject arbitrary web script or HTML via the (1) startrow and (2) catid parameter. NOTE: this issu…
|
NVD-CWE-Other
|
CVE-2005-4262
|
2011-03-8 11:27 |
2005-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345407
|
7.5 |
HIGH
|
triangle_solutions
|
php_support_tickets
|
Multiple SQL injection vulnerabilities in index.php in PHP Support Tickets 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields, and (3) id parame…
|
NVD-CWE-Other
|
CVE-2005-4264
|
2011-03-8 11:27 |
2005-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345408
|
7.2 |
HIGH
|
gentoo
|
qt-unixodbc
|
Untrusted search path vulnerability in Qt-UnixODBC before 3.3.4-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary bu…
|
NVD-CWE-Other
|
CVE-2005-4279
|
2011-03-8 11:27 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345409
|
7.2 |
HIGH
|
-
|
-
|
Untrusted search path vulnerability in CMake before 2.2.0-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build di…
|
NVD-CWE-Other
|
CVE-2005-4280
|
2011-03-8 11:27 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345410
|
4.3 |
MEDIUM
|
zaygo
|
hostingcart
|
Cross-site scripting (XSS) vulnerability in Zaygo HostingCart 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via certain search module parameters, possibly the root pa…
|
NVD-CWE-Other
|
CVE-2005-4281
|
2011-03-8 11:27 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345411
|
4.3 |
MEDIUM
|
zaygo
|
domaincart
|
Cross-site scripting (XSS) vulnerability in Zaygo DomainCart 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML, possibly via the root parameter to zaygo.cgi.
|
NVD-CWE-Other
|
CVE-2005-4282
|
2011-03-8 11:27 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345412
|
4.3 |
MEDIUM
|
nightmedia
|
the_city_shop
|
Cross-site scripting (XSS) vulnerability in The CITY Shop 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via parameters to the search module, possibly SKey to store.cg…
|
NVD-CWE-Other
|
CVE-2005-4283
|
2011-03-8 11:27 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345413
|
4.3 |
MEDIUM
|
static_store
|
staticstore
|
Cross-site scripting (XSS) vulnerability in StaticStore Search Engine 1.189A and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to search.cgi, possi…
|
NVD-CWE-Other
|
CVE-2005-4284
|
2011-03-8 11:27 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345414
|
4.3 |
MEDIUM
|
dick_copits
|
pdestore
|
Cross-site scripting (XSS) vulnerability in pdestore.cgi in Dick Copits PDEstore 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the search module parameter or …
|
NVD-CWE-Other
|
CVE-2005-4285
|
2011-03-8 11:27 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345415
|
7.5 |
HIGH
|
-
|
-
|
Unspecified vulnerability in PhpLogCon before 1.2.2 allows remote attackers to use arbitrary profiles via unknown vectors involving "'smart' values for userid and password," probably involving an SQL…
|
NVD-CWE-Other
|
CVE-2005-4286
|
2011-03-8 11:27 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345416
|
4.3 |
MEDIUM
|
soft4e
|
ecw-cart
|
Cross-site scripting (XSS) vulnerability in index.cgi in ECW-Cart 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) kword, (2) max, (3) min, (4) comp, and (5…
|
NVD-CWE-Other
|
CVE-2005-4290
|
2011-03-8 11:27 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345417
|
4.3 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in cart.cgi in ECTOOLS Onlineshop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) product, (2) category, and (3) ui…
|
NVD-CWE-Other
|
CVE-2005-4291
|
2011-03-8 11:27 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345418
|
4.3 |
MEDIUM
|
internet_express_products
|
commercesql
|
Cross-site scripting (XSS) vulnerability in CommerceSQL 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keywords …
|
NVD-CWE-Other
|
CVE-2005-4292
|
2011-03-8 11:27 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345419
|
4.3 |
MEDIUM
|
kryptronic
|
clickcartpro
|
Cross-site scripting (XSS) vulnerability in cp-app.cgi in ClickCartPro (CCP) 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the affl parameter.
|
NVD-CWE-Other
|
CVE-2005-4293
|
2011-03-8 11:27 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345420
|
4.3 |
MEDIUM
|
alkacon
|
opencms
|
Cross-site scripting (XSS) vulnerability in Alkacon OpenCms before 6.0.3 allows remote attackers to inject arbitrary web script or HTML via the username in the login page.
|
NVD-CWE-Other
|
CVE-2005-4294
|
2011-03-8 11:27 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345421
|
4.3 |
MEDIUM
|
xigla
|
absolute_image_gallery_xe
|
Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.x allows remote attackers to inject arbitrary web script or HTML via the text parameter. NOTE: the provenance of this informat…
|
NVD-CWE-Other
|
CVE-2005-4295
|
2011-03-8 11:27 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345422
|
4.3 |
MEDIUM
|
bbboard
|
bbboard
|
Cross-site scripting (XSS) vulnerability in bbBoard 2.56 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly via the "keys" paramete…
|
NVD-CWE-Other
|
CVE-2005-4297
|
2011-03-8 11:27 |
2005-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345423
|
4.3 |
MEDIUM
|
atlantpro.com
|
atlantforum
|
Cross-site scripting (XSS) vulnerability in atl.cgi in AtlantForum 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) sch_allsubct, (2) before, and (3) ct par…
|
NVD-CWE-Other
|
CVE-2005-4298
|
2011-03-8 11:27 |
2005-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345424
|
4.3 |
MEDIUM
|
atlantpro.com
|
atlant_pro
|
Cross-site scripting (XSS) vulnerability in atl.cgi in Atlant Pro 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) before and (2) ct parameters.
|
NVD-CWE-Other
|
CVE-2005-4299
|
2011-03-8 11:27 |
2005-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345425
|
4.3 |
MEDIUM
|
phpxplorer
|
phpxplorer
|
Cross-site scripting (XSS) vulnerability in phpXplorer 0.9.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the address bar field.
|
NVD-CWE-Other
|
CVE-2005-4301
|
2011-03-8 11:27 |
2005-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345426
|
5.0 |
MEDIUM
|
indexcor
|
ezdatabase
|
Directory traversal vulnerability in index.php in ezDatabase 2.1.2 and earlier allows remote attackers to include arbitrary local files via ".." sequences in the p parameter.
|
NVD-CWE-Other
|
CVE-2005-4302
|
2011-03-8 11:27 |
2005-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345427
|
4.3 |
MEDIUM
|
focalmedia.net
|
sitenet_bbs
|
Multiple cross-site scripting (XSS) vulnerabilities in SiteNet BBS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) pg, (2) tid, (3) cid, and (4) fid paramete…
|
NVD-CWE-Other
|
CVE-2005-4306
|
2011-03-8 11:27 |
2005-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345428
|
4.3 |
MEDIUM
|
jonathan_bravata
|
scarecrow
|
Cross-site scripting (XSS) vulnerability in ScareCrow 2.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the forum parameter to (1) forum.cgi and (2) post.cgi, or (3)…
|
NVD-CWE-Other
|
CVE-2005-4307
|
2011-03-8 11:27 |
2005-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345429
|
7.5 |
HIGH
|
ssh
|
tectia_server
|
SSH Tectia Server 5.0.0 (A, F, and T), when allowing host-based authentication only, allows users to log in with the wrong credentials.
|
NVD-CWE-Other
|
CVE-2005-4310
|
2011-03-8 11:27 |
2005-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345430
|
4.3 |
MEDIUM
|
dcscripts
|
dcforum dcforum\+
|
Cross-site scripting (XSS) vulnerability in DCForum 6.25 and earlier, and possibly DCForum+ 1.x, allows remote attackers to inject arbitrary web script or HTML via (1) the page parameter in dcboard.p…
|
NVD-CWE-Other
|
CVE-2005-4311
|
2011-03-8 11:27 |
2005-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345431
|
7.5 |
HIGH
|
-
|
-
|
SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds 5.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2005-4312
|
2011-03-8 11:27 |
2005-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345432
|
4.3 |
MEDIUM
|
ppcal_shopping_cart
|
ppcal_shopping_cart
|
Cross-site scripting (XSS) vulnerability in ppcal.cgi in PPCal Shopping Cart 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) stop and (2) user parameters.
|
NVD-CWE-Other
|
CVE-2005-4314
|
2011-03-8 11:27 |
2005-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345433
|
7.5 |
HIGH
|
sourcefire
|
snort
|
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to execute arbitrary code via a crafted UDP packet.
|
NVD-CWE-Other
|
CVE-2005-3252
|
2011-03-8 11:26 |
2005-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345434
|
7.5 |
HIGH
|
avaya proxim
|
wireless_ap-3 wireless_ap-4 wireless_ap-5 wireless_ap-6 wireless_ap-7 wireless_ap-8 ap-2000 ap-4000 ap-600 ap-700
|
Wireless Access Points (AP) for (1) Avaya AP-3 through AP-6 2.5 to 2.5.4, and AP-7/AP-8 2.5 and other versions before 3.1, and (2) Proxim AP-600 and AP-2000 before 2.5.5, and Proxim AP-700 and AP-400…
|
NVD-CWE-Other
|
CVE-2005-3253
|
2011-03-8 11:26 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345435
|
5.0 |
MEDIUM
|
squid
|
squid
|
The rfc1738_do_escape function in ftp.c for Squid 2.5 STABLE11 and earlier allows remote FTP servers to cause a denial of service (segmentation fault) via certain "odd" responses.
|
NVD-CWE-Other
|
CVE-2005-3258
|
2011-03-8 11:26 |
2005-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345436
|
4.3 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.…
|
NVD-CWE-Other
|
CVE-2005-3301
|
2011-03-8 11:26 |
2005-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345437
|
7.5 |
HIGH
|
clam_anti-virus
|
clamav
|
The FSG unpacker (fsg.c) in Clam AntiVirus (ClamAV) 0.80 through 0.87 allows remote attackers to cause "memory corruption" and execute arbitrary code via a crafted FSG 1.33 file.
|
NVD-CWE-Other
|
CVE-2005-3303
|
2011-03-8 11:26 |
2005-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345438
|
7.5 |
HIGH
|
novell
|
zenworks_patch_management_server
|
Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers to execute arbitrary SQL commands via the (1) Direction parameter to computers/d…
|
NVD-CWE-Other
|
CVE-2005-3315
|
2011-03-8 11:26 |
2005-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345439
|
7.5 |
HIGH
|
mantis
|
mantis
|
SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-3336
|
2011-03-8 11:26 |
2005-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345440
|
1.2 |
LOW
|
norman_ramsey
|
noweb
|
noweb 2.10c and earlier allows local users to overwrite arbitrary files via symlink attacks on temporary files in (1) lib/toascii.nw and (2) shell/roff.mm.
|
NVD-CWE-Other
|
CVE-2005-3342
|
2011-03-8 11:26 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345441
|
7.2 |
HIGH
|
trend_micro
|
pc-cillin_2005
|
The installation of Trend Micro PC-Cillin Internet Security 2005 12.00 build 1244, and probably previous versions, uses insecure default ACLs, which allows local users to cause a denial of service (d…
|
NVD-CWE-Other
|
CVE-2005-3360
|
2011-03-8 11:26 |
2005-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345442
|
4.6 |
MEDIUM
|
luca_deri
|
ntop
|
The startup script in packages/RedHat/ntop.init in ntop before 3.2, when ntop.conf is writable by users besides root, creates temporary files insecurely, which allows remote attackers to execute arbi…
|
NVD-CWE-Other
|
CVE-2005-3387
|
2011-03-8 11:26 |
2005-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345443
|
4.3 |
MEDIUM
|
snitz_communications
|
snitz_forums_2000
|
Cross-site scripting (XSS) vulnerability in post.asp in Snitz Forums 2000 3.4.05 allows remote attackers to inject arbitrary web script or HTML via the type parameter in a Topic method.
|
NVD-CWE-Other
|
CVE-2005-3411
|
2011-03-8 11:26 |
2005-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345444
|
4.3 |
MEDIUM
|
10-4_aps
|
asp_fast_forum
|
Cross-site scripting (XSS) vulnerability in error.asp in ASP Fast Forum allows remote attackers to inject arbitrary web script or HTML via the error parameter.
|
NVD-CWE-Other
|
CVE-2005-3422
|
2011-03-8 11:26 |
2005-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345445
|
4.3 |
MEDIUM
|
gnu
|
gnump3d
|
Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.5 allows remote attackers to inject arbitrary web script or HTML via 404 error pages, a different vulnerability than CVE-2005-3425.
|
NVD-CWE-Other
|
CVE-2005-3424
|
2011-03-8 11:26 |
2005-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345446
|
5.0 |
MEDIUM
|
f-secure
|
f-secure_anti-virus internet_gatekeeper
|
Directory traversal vulnerability in F-Secure Anti-Virus for Microsoft Exchange 6.40 and Internet Gatekeeper 6.40 to 6.42 allows limited remote attackers to bypass Web Console authentication and read…
|
NVD-CWE-Other
|
CVE-2005-3468
|
2011-03-8 11:26 |
2005-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345447
|
5.0 |
MEDIUM
|
-
|
-
|
Directory traversal vulnerability in the ruleset view for MailWatch for MailScanner 1.0.2 allows remote attackers to access arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-3471
|
2011-03-8 11:26 |
2005-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345448
|
5.0 |
MEDIUM
|
sun
|
java_system_communications_express
|
Unspecified vulnerability in Sun Java System Communications Express 2005Q1 and 2004Q2 allows local and remote attackers to read sensitive information from configuration files.
|
NVD-CWE-Other
|
CVE-2005-3472
|
2011-03-8 11:26 |
2005-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345449
|
5.0 |
MEDIUM
|
cisco
|
aironet_ap1131 aironet_ap1200 aironet_ap1240
|
Cisco 1200, 1131, and 1240 series Access Points, when operating in Lightweight Access Point Protocol (LWAPP) mode and controlled by 2000 and 4400 series Airespace WLAN controllers running 3.1.59.24, …
|
NVD-CWE-Other
|
CVE-2005-3482
|
2011-03-8 11:26 |
2005-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345450
|
5.0 |
MEDIUM
|
clam_anti-virus
|
clamav
|
The tnef_attachment function in tnef.c for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via a crafted value in a CA…
|
NVD-CWE-Other
|
CVE-2005-3500
|
2011-03-8 11:26 |
2005-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|