|
345851
|
4.6 |
MEDIUM
|
openoffice
|
openoffice
|
OpenOffice.org 2.0 and earlier, when hyperlinks has been disabled, does not prevent the user from clicking the WWW-browser button in the Hyperlink dialog, which makes it easier for attackers to trick…
|
NVD-CWE-Other
|
CVE-2005-4636
|
2009-11-12 14:51 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345852
|
7.2 |
HIGH
|
dec
|
dec_openvms
|
Vulnerability in Monitor utility (SYS$SHARE:SPISHR.EXE) in VMS 5.0 through 5.4-2 allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-1999-1395
|
2009-10-31 13:02 |
1992-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345853
|
7.6 |
HIGH
|
apple
|
mac_os_x
|
Mac OS X 10.3.9 and earlier allows users to install, create, and execute setuid/setgid scripts, contrary to the intended design, which may allow attackers to conduct unauthorized activities with esca…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2005-0970
|
2009-10-14 13:00 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345854
|
10.0 |
HIGH
|
sips
|
sips
|
Unspecified vulnerability in Haakon Nilsen simple, integrated publishing system (SIPS) before 0.2.4 has an unknown impact and attack vectors, related to a "grave security fault."
|
NVD-CWE-noinfo
|
CVE-2000-1241
|
2009-10-14 13:00 |
2000-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345855
|
7.5 |
HIGH
|
netgear
|
fm114p
|
NETGEAR FM114P allows remote attackers to bypass access restrictions for web sites via a URL that uses the IP address instead of the hostname.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2002-1877
|
2009-10-14 13:00 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345856
|
5.0 |
MEDIUM
|
post_affiliate_pro
|
post_affiliate_pro
|
merchants/index.php in Post Affiliate Pro 2.0.4 and earlier, with magic_quotes_gpc disabled, allows remote attackers to include arbitrary local files via the md parameter, possibly due to a directory…
|
NVD-CWE-Other
|
CVE-2005-3910
|
2009-10-9 13:33 |
2005-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345857
|
7.5 |
HIGH
|
babe_logger
|
babe_logger
|
SQL injection vulnerability in Babe Logger 2 allows remote attackers to execute arbitrary SQL commands via the (1) gal parameter to index.php or (2) id parameter to comments.php.
|
NVD-CWE-Other
|
CVE-2005-3920
|
2009-10-9 13:33 |
2005-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345858
|
7.5 |
HIGH
|
socketkb
|
socketkb
|
PHP file include vulnerability in SocketKB 1.1.0 and earlier allows remote attackers to include arbitrary local files via the __f parameter.
|
NVD-CWE-Other
|
CVE-2005-3936
|
2009-10-9 13:33 |
2005-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345859
|
7.5 |
HIGH
|
softbiz
|
b2b_trading_marketplace_script
|
SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffe…
|
NVD-CWE-Other
|
CVE-2005-3937
|
2009-10-9 13:33 |
2005-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345860
|
5.0 |
MEDIUM
|
sun
|
java_plug-in
|
The Java Plug-in 1.4.2_03 and 1.4.2_04 controls, and the 1.4.2_03 and 1.4.2_04 <applet> redirector controls, allow remote attackers to cause a denial of service (Internet Explorer crash) by creating …
|
CWE-16
Configuration
|
CVE-2005-4845
|
2009-08-28 13:00 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345861
|
7.5 |
HIGH
|
gnu
|
mailman
|
Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or (2) the Pipermail index summaries.
|
NVD-CWE-Other
|
CVE-2002-0388
|
2009-07-22 06:00 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345862
|
7.5 |
HIGH
|
wowbb
|
wowbb_web_forum
|
Multiple SQL injection vulnerabilities in WowBB Forum 1.61 allow remote attackers to execute arbitrary SQL commands via the (1) sort_by or (2) page parameters to view_user.php, or the (3) forum_id pa…
|
NVD-CWE-Other
|
CVE-2004-2181
|
2009-06-25 13:25 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345863
|
5.0 |
MEDIUM
|
abe_timmerman
|
zml.cgi
|
Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
|
NVD-CWE-Other
|
CVE-2001-1209
|
2009-04-30 13:08 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345864
|
7.5 |
HIGH
|
virtual_programming
|
vp-asp
|
SQL injection vulnerability in shopadmin.asp in VP-ASP 4.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password fields.
|
NVD-CWE-Other
|
CVE-2002-1919
|
2009-04-11 13:14 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345865
|
2.1 |
LOW
|
easyscripts
|
easynews
|
easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtain the passwords and gain access.
|
NVD-CWE-Other
|
CVE-2001-1527
|
2009-04-3 13:11 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345866
|
10.0 |
HIGH
|
newsscript.co.uk
|
newsscript
|
newsscript.pl for NewsScript allows remote attackers to gain privileges by setting the mode parameter to admin.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2005-0735
|
2009-04-3 13:00 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345867
|
2.6 |
LOW
|
php_heaven
|
phpmychat
|
Multiple directory traversal vulnerabilities in admin.php3 in PHPMyChat 0.14.5 allow remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the (1) sheet and (2…
|
CWE-22
Path Traversal
|
CVE-2004-2717
|
2009-04-3 13:00 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345868
|
7.5 |
HIGH
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 2.2.0rc3 and earlier allows remote attackers to execute arbitrary commands by inserting them into (1) the strCopyTableOK argument in tbl_copy.php, or (2) the strRenameTableOK argument in t…
|
NVD-CWE-Other
|
CVE-2001-1060
|
2009-04-3 13:00 |
2001-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345869
|
7.5 |
HIGH
|
darren_reed
|
ipfilter
|
IPFilter 3.1.1 through 3.4.28 allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server, which generates a response that co…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2002-1978
|
2009-04-3 13:00 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345870
|
7.5 |
HIGH
|
watchguard
|
legacy_rssa soho vclass
|
WatchGuard SOHO products running firmware 5.1.6 and earlier, and Vclass/RSSA using 3.2 SP1 and earlier, allows remote attackers to bypass firewall rules by sending a PASV command string as the argume…
|
CWE-20
Improper Input Validation
|
CVE-2002-1979
|
2009-04-3 13:00 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345871
|
7.5 |
HIGH
|
zipgenius
|
zipgenius
|
Multiple stack-based buffer overflows in ZipGenius 5.5.1.468 and 6.0.2.1041, and other versions before 6.0.2.1050, allow remote attackers to execute arbitrary code via (1) a ZIP archive that contains…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2005-3317
|
2009-03-25 13:00 |
2005-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345872
|
6.8 |
MEDIUM
|
openbsd
|
openssh
|
sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after a root login attempt with the correct password, but leaves the connection open after an attempt wi…
|
CWE-16
Configuration
|
CVE-2004-2760
|
2009-01-29 14:37 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345873
|
5.0 |
MEDIUM
|
netscape
|
navigator
|
Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
|
CWE-200
Information Exposure
|
CVE-2003-1560
|
2009-01-29 14:28 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345874
|
4.3 |
MEDIUM
|
opera
|
opera
|
Opera, probably before 7.50, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer …
|
NVD-CWE-noinfo CWE-200
Information Exposure
|
CVE-2003-1561
|
2009-01-29 14:28 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345875
|
10.0 |
HIGH
|
bsdi caldera redhat
|
bsd_os openlinux linux
|
Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-1999-0002
|
2009-01-26 14:00 |
1998-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345876
|
2.6 |
LOW
|
clam_anti-virus
|
clamav
|
The Quantum archive decompressor in Clam AntiVirus (ClamAV) before 0.86.1 allows remote attackers to cause a denial of service (application crash) via a crafted Quantum archive.
|
NVD-CWE-Other
|
CVE-2005-2056
|
2008-11-15 14:48 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345877
|
5.0 |
MEDIUM
|
ipswitch
|
ipswitch_collaboration_suite
|
The IMAP daemon (IMAPD32.EXE) in Ipswitch Collaboration Suite (ICS) allows remote attackers to cause a denial of service (CPU consumption) via an LSUB command with a large number of null characters, …
|
NVD-CWE-Other
|
CVE-2005-1249
|
2008-11-15 14:46 |
2005-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345878
|
5.0 |
MEDIUM
|
ipswitch
|
imail imail_server
|
Directory traversal vulnerability in the Web Calendaring server in Ipswitch Imail 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote attackers to read arbitrary files via "..\" …
|
NVD-CWE-Other
|
CVE-2005-1252
|
2008-11-15 14:46 |
2005-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345879
|
5.0 |
MEDIUM
|
ipswitch
|
imail
|
Stack-based buffer overflow in the IMAP server for Ipswitch IMail 8.12 and 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to cause a denial of service (c…
|
NVD-CWE-Other
|
CVE-2005-1254
|
2008-11-15 14:46 |
2005-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345880
|
10.0 |
HIGH
|
ipswitch
|
imail imail_server ipswitch_collaboration_suite
|
Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow remote attackers to e…
|
NVD-CWE-Other
|
CVE-2005-1255
|
2008-11-15 14:46 |
2005-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345881
|
10.0 |
HIGH
|
ipswitch
|
imail imail_server ipswitch_collaboration_suite
|
Stack-based buffer overflow in the IMAP daemon (IMAPD32.EXE) in IMail 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated user…
|
NVD-CWE-Other
|
CVE-2005-1256
|
2008-11-15 14:46 |
2005-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345882
|
7.2 |
HIGH
|
debian
|
ppxp
|
ppxp does not drop root privileges before opening log files, which allows local users to execute arbitrary commands.
|
NVD-CWE-Other
|
CVE-2005-0392
|
2008-11-15 14:43 |
2005-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345883
|
4.0 |
MEDIUM
|
cybozu
|
collaborex cybozu_ag cybozu_pocket garoon_1 mailwise
|
Directory traversal vulnerability in Cybozu Collaborex, AG before 1.2(1.5), AG Pocket before 5.2(0.8), Mailwise before 3.0(0.3), and Garoon 1 before 1.5(4.1) allows remote authenticated users to read…
|
NVD-CWE-Other
|
CVE-2006-4491
|
2008-11-11 15:28 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345884
|
5.0 |
MEDIUM
|
cybozu
|
cybozu_office
|
Unspecified vulnerability in Cybozu Office 6.5 Build 1.2 for Windows allows remote attackers to obtain sensitive information, including users and groups, via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-4492
|
2008-11-11 15:28 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345885
|
5.0 |
MEDIUM
|
hyper_estraier
|
hyper_estraier
|
estcmd in Hyper Estraier 1.0.1 on Windows systems allows remote attackers to read unauthorized files via a crafted search request for a filename that contains Unicode characters.
|
NVD-CWE-Other
|
CVE-2005-3421
|
2008-11-11 14:55 |
2005-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345886
|
4.3 |
MEDIUM
|
hiki
|
hiki
|
Cross-site scripting (XSS) vulnerability in Hiki 0.8.1 to 0.8.2 allows remote attackers to inject arbitrary web script or HTML via a page name in a Login link, a different vulnerability than CVE-2005…
|
NVD-CWE-Other
|
CVE-2005-2803
|
2008-11-11 14:53 |
2005-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345887
|
4.3 |
MEDIUM
|
hiki
|
hiki
|
Cross-site scripting (XSS) vulnerability in Hiki 0.8.0 to 0.8.2 allows remote attackers to inject arbitrary web script or HTML via "missing pages" in which the page name is not properly escaped, a di…
|
NVD-CWE-Other
|
CVE-2005-2336
|
2008-11-11 14:51 |
2005-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345888
|
7.2 |
HIGH
|
sendmail debian
|
sendmail debian_linux
|
The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privileges via (1) expn, (2) checksendmail, or (3) doubl…
|
NVD-CWE-Other
|
CVE-2003-0308
|
2008-11-11 14:29 |
2003-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345889
|
7.8 |
HIGH
|
eva-web
|
eva-web
|
An unspecified script in EVA-Web 2.1.2 and earlier, probably index.php, allows remote attackers to obtain the full path of the web server via invalid (1) perso or (2) aide parameters.
|
NVD-CWE-Other
|
CVE-2006-2690
|
2008-11-9 15:26 |
2006-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345890
|
7.5 |
HIGH
|
allaire
|
forums
|
Allaire Forums 2.0.4 and 2.0.5 and Forums! 3.0 and 3.1 allows remote authenticated users to spoof messages as other users by modifying the hidden form fields for the name and e-mail address.
|
NVD-CWE-Other
|
CVE-2002-0108
|
2008-11-4 14:23 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345891
|
7.5 |
HIGH
|
infopop
|
ultimate_bulletin_board
|
Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.2.0 Beta Release 1.0 allows remote attackers to execute arbitrary script and steal cookies via a message containing encod…
|
NVD-CWE-Other
|
CVE-2002-0118
|
2008-11-4 14:23 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345892
|
5.0 |
MEDIUM
|
netgear
|
rp114
|
Netgear RP114 Cable/DSL Web Safe Router Firmware 3.26, when configured to block traffic below port 1024, allows remote attackers to cause a denial of service (hang) via a port scan of the WAN port.
|
NVD-CWE-Other
|
CVE-2002-0127
|
2008-11-4 14:23 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345893
|
1.2 |
LOW
|
maelstrom
|
maelstrom_gpl
|
Maelstrom GPL 3.0.1 allows local users to overwrite arbitrary files of other Maelstrom users via a symlink attack on the /tmp/f file.
|
NVD-CWE-Other
|
CVE-2002-0141
|
2008-11-4 14:23 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345894
|
2.6 |
LOW
|
awstats
|
awstats
|
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the config parameter. NOTE: this might be the sam…
|
NVD-CWE-Other
|
CVE-2006-1945
|
2008-11-3 15:18 |
2006-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345895
|
6.4 |
MEDIUM
|
leadhound_network
|
leadhound_full leadhound_lite
|
Multiple SQL injection vulnerabilities in Leadhound Full and LITE 2.1, and probably the Network Version "Full Version", allow remote attackers to execute arbitrary SQL commands via the (1) banner par…
|
NVD-CWE-Other
|
CVE-2006-2062
|
2008-11-3 15:18 |
2006-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345896
|
6.8 |
MEDIUM
|
leadhound_network
|
leadhound_full leadhound_lite
|
Multiple cross-site scripting (XSS) vulnerabilities in Leadhound Full and LITE 2.1, and probably the Network Version "Full Version", allow remote attackers to inject arbitrary web script or HTML via …
|
NVD-CWE-Other
|
CVE-2006-2063
|
2008-11-3 15:18 |
2006-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345897
|
5.0 |
MEDIUM
|
ecotwo
|
shopsystem
|
Unspecified vulnerability in ecotwo Shopsystem 1.0-192 and earlier allows remote attackers to include arbitrary local files via (1) the lang parameter in news.php and (2) other unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-1684
|
2008-11-3 15:16 |
2006-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345898
|
5.0 |
MEDIUM
|
apt
|
apt-webshop-system
|
Unspecified vulnerability in modules.php in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to access unspecified files via a modified warp parameter.
|
NVD-CWE-Other
|
CVE-2006-1686
|
2008-11-3 15:16 |
2006-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345899
|
10.0 |
HIGH
|
hp
|
hp-ux
|
Buffer overflow in the DCE daemon (DCED) for the DCE endpoint mapper (epmap) on HP-UX 11 allows remote attackers to execute arbitrary code via a request with a small fragment length and a large amoun…
|
NVD-CWE-Other
|
CVE-2004-0716
|
2008-10-24 13:32 |
2004-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345900
|
7.5 |
HIGH
|
wsn_knowledge_base
|
wsn_knowledge_base
|
Multiple SQL injection vulnerabilities in WSN Knowledge Base 1.2.0 and earler allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) perpage, (3) ascdesc, and (4) orderlinks …
|
NVD-CWE-Other
|
CVE-2005-3939
|
2008-10-3 13:41 |
2005-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|