|
345901
|
5.0 |
MEDIUM
|
phpalbum.net
|
phpalbum
|
Directory traversal vulnerability in main.php in PHPAlbum 0.2.3 and earlier allows remote attackers to read arbitrary files via the (1) cmd and (2) var1 parameters.
|
NVD-CWE-Other
|
CVE-2005-3948
|
2008-10-3 13:41 |
2005-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345902
|
7.5 |
HIGH
|
bedeng_psp
|
bedeng_psp
|
SQL injection vulnerability in Bedeng PSP 1.1 allows remote attackers to execute arbitrary SQL commands via the cwhere parameter to (1) index.php and (2) download.php, or (3) ckode parameter to baca.…
|
NVD-CWE-Other
|
CVE-2005-3953
|
2008-10-3 13:41 |
2005-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345903
|
7.5 |
HIGH
|
dmanews
|
dmanews
|
Multiple SQL injection vulnerabilities in index.php in DMANews 0.904 and 0.910 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a comments action and the (2) sorto…
|
NVD-CWE-Other
|
CVE-2005-3956
|
2008-10-3 13:41 |
2005-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345904
|
7.5 |
HIGH
|
iisprotect
|
iisprotect
|
iisPROTECT 2.1 and 2.2 allows remote attackers to bypass authentication via an HTTP request containing URL-encoded characters.
|
NVD-CWE-Other
|
CVE-2003-0317
|
2008-10-3 13:20 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345905
|
7.2 |
HIGH
|
phpnettoolpack
|
phpnettoolpack
|
PHPNetToolpack 0.1 relies on its environment's PATH to find and execute the traceroute program, which could allow local users to gain privileges by inserting a Trojan horse program into the search pa…
|
NVD-CWE-Other
|
CVE-2002-0470
|
2008-09-24 13:13 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345906
|
10.0 |
HIGH
|
phpnettoolpack
|
phpnettoolpack
|
PHPNetToolpack 0.1 allows remote attackers to execute arbitrary code via shell metacharacters in the a_query variable.
|
NVD-CWE-Other
|
CVE-2002-0471
|
2008-09-24 13:13 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345907
|
10.0 |
HIGH
|
sun
|
solaris_answerbook2
|
The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters.
|
NVD-CWE-Other
|
CVE-2000-0697
|
2008-09-24 13:07 |
2000-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345908
|
5.0 |
MEDIUM
|
-
|
-
|
Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to obtain the full path of the application via an invalid mode parameter to community.html, which leaks the path in an error …
|
NVD-CWE-Other
|
CVE-2005-4373
|
2008-09-20 13:43 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345909
|
4.3 |
MEDIUM
|
libertas_solutions
|
libertas_enterprise_cms
|
Cross-site scripting (XSS) vulnerability in search/index.php in Libertas Enterprise CMS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page_search parameter.
|
NVD-CWE-Other
|
CVE-2005-4399
|
2008-09-20 13:43 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345910
|
4.3 |
MEDIUM
|
liferay
|
liferay_portal_enterprise
|
Cross-site scripting (XSS) vulnerability in downloads/portal_ent in Liferay Portal Enterprise 3.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) _77_struts_a…
|
NVD-CWE-Other
|
CVE-2005-4400
|
2008-09-20 13:43 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345911
|
4.3 |
MEDIUM
|
lutece
|
lutece
|
Cross-site scripting (XSS) vulnerability in Lutece 1.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the query parameter.
|
NVD-CWE-Other
|
CVE-2005-4401
|
2008-09-20 13:43 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345912
|
7.5 |
HIGH
|
qcm
|
marwel
|
SQL injection vulnerability in index.php in Marwel 2.7 and earlier allows remote attackers to execute arbitrary SQL commands via the show parameter.
|
NVD-CWE-Other
|
CVE-2005-4403
|
2008-09-20 13:43 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345913
|
7.5 |
HIGH
|
tmc_visionpool
|
mercury_cms
|
SQL injection vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.
|
NVD-CWE-Other
|
CVE-2005-4406
|
2008-09-20 13:43 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345914
|
4.3 |
MEDIUM
|
tmc_visionpool
|
mercury_cms
|
Cross-site scripting (XSS) vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) content and (2) criteria parameters.
|
NVD-CWE-Other
|
CVE-2005-4407
|
2008-09-20 13:43 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345915
|
7.5 |
HIGH
|
pc_media
|
miraserver
|
Multiple SQL injection vulnerabilities in Miraserver 1.0 RC4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) id parameter to newsitem…
|
NVD-CWE-Other
|
CVE-2005-4408
|
2008-09-20 13:43 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345916
|
4.3 |
MEDIUM
|
mmbase
|
mmbase
|
Cross-site scripting (XSS) vulnerability in MMBase 1.7.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.
|
NVD-CWE-Other
|
CVE-2005-4409
|
2008-09-20 13:43 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345917
|
4.3 |
MEDIUM
|
nqcontent
|
nqcontent
|
Cross-site scripting (XSS) vulnerability in NQcontent 3 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the text parameter.
|
NVD-CWE-Other
|
CVE-2005-4410
|
2008-09-20 13:43 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345918
|
7.5 |
HIGH
|
cs-cart
|
cs-cart
|
SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php.
|
NVD-CWE-Other
|
CVE-2005-4429
|
2008-09-20 13:43 |
2005-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345919
|
7.5 |
HIGH
|
-
|
-
|
SQL injection vulnerability in LogicBill 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) __mode and (2) __id parameters to helpdesk.php.
|
NVD-CWE-Other
|
CVE-2005-4430
|
2008-09-20 13:43 |
2005-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345920
|
7.5 |
HIGH
|
wowbb
|
wowbb
|
SQL injection vulnerability in WowBB 1.65 allows remote attackers to execute arbitrary SQL commands via the q parameter to search.php. NOTE: the view_user.php/sort_by vector is already covered by CVE…
|
NVD-CWE-Other
|
CVE-2005-4431
|
2008-09-20 13:43 |
2005-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345921
|
6.8 |
MEDIUM
|
alkacon
|
opencms
|
Cross-site scripting (XSS) vulnerability in OpenCms 6.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.
|
NVD-CWE-Other
|
CVE-2005-4475
|
2008-09-20 13:43 |
2005-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345922
|
6.8 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in papaya CMS 4.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the bab[searchfor] parameter.
|
NVD-CWE-Other
|
CVE-2005-4477
|
2008-09-20 13:43 |
2005-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345923
|
6.8 |
MEDIUM
|
plexcor
|
plexcor_cms
|
Cross-site scripting (XSS) vulnerability in Plexcor CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.
|
NVD-CWE-Other
|
CVE-2005-4480
|
2008-09-20 13:43 |
2005-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345924
|
4.3 |
MEDIUM
|
text-e
|
text-e_cms
|
Cross-site scripting (XSS) vulnerability in Text-e 1.6.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.
|
NVD-CWE-Other
|
CVE-2005-4498
|
2008-09-20 13:43 |
2005-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345925
|
4.3 |
MEDIUM
|
waxtrapp
|
waxtrapp
|
Cross-site scripting (XSS) vulnerability in WAXTRAPP 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.
|
NVD-CWE-Other
|
CVE-2005-4512
|
2008-09-20 13:43 |
2005-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345926
|
4.3 |
MEDIUM
|
ooapp
|
ooapp_guestbook
|
Cross-site scripting (XSS) vulnerability in home.php in OoApp Guestbook 2.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
NVD-CWE-Other
|
CVE-2005-4598
|
2008-09-20 13:43 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345927
|
7.5 |
HIGH
|
phpoutsourcing
|
zorum
|
SQL injection vulnerability in index.php in phpoutsourcing Zorum Forum 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the rollid parameter in the showhtmllist method.
|
NVD-CWE-Other
|
CVE-2005-4619
|
2008-09-20 13:43 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345928
|
4.3 |
MEDIUM
|
jelsoft
|
vbulletin
|
Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which th…
|
NVD-CWE-Other
|
CVE-2005-4621
|
2008-09-20 13:43 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345929
|
7.5 |
HIGH
|
help_desk_point_software
|
helpdeskpoint
|
SQL injection vulnerability in index.php in HelpDeskPoint 2.38 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.
|
NVD-CWE-Other
|
CVE-2005-4628
|
2008-09-20 13:43 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345930
|
7.5 |
HIGH
|
smbcms
|
smbcms
|
SQL injection vulnerability in SMBCMS 2.1 allows remote attackers to execute arbitrary SQL commands via unspecified search parameters.
|
NVD-CWE-Other
|
CVE-2005-4629
|
2008-09-20 13:43 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345931
|
7.5 |
HIGH
|
ryan_lath
|
zina
|
SQL injection vulnerability in index.php in Zina 0.12.07 and earlier allows remote attackers to execute arbitrary SQL commands via the p parameter.
|
NVD-CWE-Other
|
CVE-2005-4631
|
2008-09-20 13:43 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345932
|
7.5 |
HIGH
|
vote_pro
|
vote_pro
|
SQL injection vulnerability in poll_frame.php in Vote! Pro 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the poll_id parameter.
|
CWE-89
SQL Injection
|
CVE-2005-4632
|
2008-09-20 13:43 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345933
|
7.5 |
HIGH
|
activecampaign
|
supporttrio
|
SQL injection vulnerability in index.php in ActiveCampaign SupportTrio 1.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the provenance of this information …
|
NVD-CWE-Other
|
CVE-2005-4634
|
2008-09-20 13:43 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345934
|
7.5 |
HIGH
|
class-1
|
poll_software
|
SQL injection vulnerability in index.php in class-1 Poll Software 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) pollid or (2) previouspoll parameters.
|
NVD-CWE-Other
|
CVE-2005-4640
|
2008-09-20 13:43 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345935
|
7.5 |
HIGH
|
eazycms
|
eazycms
|
SQL injection vulnerability in home.php in eazyCMS 2.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.
|
NVD-CWE-Other
|
CVE-2005-4641
|
2008-09-20 13:43 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345936
|
6.4 |
MEDIUM
|
alstrasoft
|
epay
|
SQL injection vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the pmodule parameter.
|
NVD-CWE-Other
|
CVE-2005-4651
|
2008-09-20 13:43 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345937
|
7.5 |
HIGH
|
sysbotz
|
systems_panel
|
Multiple SQL injection vulnerabilities in Sysbotz Systems Panel 1.0.6 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the cid parameter in knowledgebase/index.php, (2) th…
|
NVD-CWE-Other
|
CVE-2005-4719
|
2008-09-20 13:43 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345938
|
5.0 |
MEDIUM
|
nelogic_technologies
|
nephp_publisher
|
Multiple SQL injection vulnerabilities in index.php in NeLogic Nephp Publisher 4.5.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) nnet_catid parameters.
|
NVD-CWE-Other
|
CVE-2005-4743
|
2008-09-20 13:43 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345939
|
5.0 |
MEDIUM
|
sergids
|
top_music_module
|
Multiple SQL injection vulnerabilities in SergiDs Top Music module 3.0 PR3 and earlier for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the (1) idartist, (2) idsong, and (3) …
|
NVD-CWE-Other
|
CVE-2005-4781
|
2008-09-20 13:43 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345940
|
4.3 |
MEDIUM
|
locazo
|
locazolist_classifieds
|
Cross-site scripting (XSS) vulnerability in searchdb.asp in LocazoList 1.03c and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.
|
NVD-CWE-Other
|
CVE-2005-4205
|
2008-09-20 13:42 |
2005-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345941
|
7.5 |
HIGH
|
php_web_scripts
|
link_up_gold
|
SQL injection vulnerability in poll.php in Link Up Gold 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the number parameter.
|
NVD-CWE-Other
|
CVE-2005-4230
|
2008-09-20 13:42 |
2005-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345942
|
7.5 |
HIGH
|
php_web_scripts
|
ad_manager_pro
|
SQL injection vulnerability in advertiser_statistic.php in Ad Manager Pro 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ad_number parameter.
|
NVD-CWE-Other
|
CVE-2005-4233
|
2008-09-20 13:42 |
2005-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345943
|
7.5 |
HIGH
|
vcd-db
|
vcd-db
|
SQL injection vulnerability in search.php in VCD-db 0.98 and earlier allows remote attackers to execute arbitrary SQL commands via the by parameter.
|
NVD-CWE-Other
|
CVE-2005-4240
|
2008-09-20 13:42 |
2005-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345944
|
4.3 |
MEDIUM
|
edatcat
|
edatcat_shopping_cart_system
|
Cross-site scripting (XSS) vulnerability in EDCstore.pl in eDatCat 0.3 allows remote attackers to inject arbitrary web script or HTML via the user_action parameter.
|
NVD-CWE-Other
|
CVE-2005-4289
|
2008-09-20 13:42 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345945
|
7.5 |
HIGH
|
indexcor
|
ezdatabase
|
SQL injection vulnerability in index.php for ezDatabase 2.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the db_id parameter.
|
NVD-CWE-Other
|
CVE-2005-4303
|
2008-09-20 13:42 |
2005-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345946
|
5.0 |
MEDIUM
|
indexcor
|
ezdatabase
|
index.php in ezDatabase 2.1.2 and earlier allows remote attackers to obtain sensitive information via an invalid cat_id parameter, which leaks the full pathname in an error message. NOTE: these deta…
|
NVD-CWE-Other
|
CVE-2005-4304
|
2008-09-20 13:42 |
2005-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345947
|
7.5 |
HIGH
|
scriptscenter
|
ezupload_pro
|
index.php in ezUpload Pro 2.2 and earlier allows remote attackers to include files via the mode parameter.
|
NVD-CWE-Other
|
CVE-2005-4308
|
2008-09-20 13:42 |
2005-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345948
|
4.3 |
MEDIUM
|
binary-concepts
|
binary_board_system
|
Multiple cross-site scripting (XSS) vulnerabilities in Binary Board System (BBS) 0.2.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) inreplyto, (2) article, an…
|
NVD-CWE-Other
|
CVE-2005-4333
|
2008-09-20 13:42 |
2005-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345949
|
7.8 |
HIGH
|
courseforum
|
projectforum
|
ProjectForum 4.7.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted pageid parameter to admin/versions.html.
|
NVD-CWE-Other
|
CVE-2005-4335
|
2008-09-20 13:42 |
2005-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345950
|
6.4 |
MEDIUM
|
fad_solutions
|
drzes_hms
|
Multiple SQL injection vulnerabilities in DRZES HMS 3.2 allow remote attackers to execute arbitrary SQL commands via the (1) plan_id parameter to (a) domains.php, (b) viewusage.php, (c) pop_accounts.…
|
NVD-CWE-Other
|
CVE-2005-4366
|
2008-09-20 13:42 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|