|
346951
|
4.3 |
MEDIUM
|
spey
|
spey
|
Format string vulnerability in Logger.cc for Spey 0.3.3 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a syslog call.
|
CWE-20
Improper Input Validation
|
CVE-2005-4846
|
2008-09-6 05:57 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346952
|
4.6 |
MEDIUM
|
appfluent_technology
|
database_ids
|
Buffer overflow in Appfluent Technology Database IDS 2.0 allows local users to execute arbitrary code via a long APPFLUENT_HOME environment variable.
|
NVD-CWE-Other
|
CVE-2005-4076
|
2008-09-6 05:56 |
2005-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346953
|
7.5 |
HIGH
|
realnetworks
|
realplayer
|
** UNVERIFIABLE, PRERELEASE ** NOTE: this issue describes a problem that can not be independently verified as of 20051208. Unspecified vulnerability in unspecified versions of Real Networks RealPla…
|
NVD-CWE-Other
|
CVE-2005-4126
|
2008-09-6 05:56 |
2005-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346954
|
7.5 |
HIGH
|
realnetworks
|
realplayer
|
** UNVERIFIABLE, PRERELEASE ** NOTE: this issue describes a problem that can not be independently verified as of 20051208. Unspecified vulnerability in unspecified versions of Real Networks RealPla…
|
NVD-CWE-Other
|
CVE-2005-4130
|
2008-09-6 05:56 |
2005-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346955
|
7.5 |
HIGH
|
adaptive_technology_resource_centre
|
atutor
|
registration.PHP in ATutor 1.5.1 pl2 allows remote attackers to execute arbitrary SQL commands via an e-mail address that ends in a NULL character, which bypasses the PHP regular expression check. NO…
|
NVD-CWE-Other
|
CVE-2005-4155
|
2008-09-6 05:56 |
2005-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346956
|
9.4 |
HIGH
|
mambo
|
mambo_open_source_4.5
|
Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrary files and possibly cause a denial of service via a query …
|
NVD-CWE-Other
|
CVE-2005-4156
|
2008-09-6 05:56 |
2005-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346957
|
4.3 |
MEDIUM
|
efiction_project
|
efiction
|
Cross-site scripting (XSS) vulnerability in eFiction 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the let parameter in a viewlist action to titles.php.
|
NVD-CWE-Other
|
CVE-2005-4167
|
2008-09-6 05:56 |
2005-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346958
|
7.5 |
HIGH
|
efiction_project
|
efiction
|
Multiple SQL injection vulnerabilities in eFiction 1.0, 1.1, and 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the let parameter in a viewlist action to titles.php and (2) the …
|
NVD-CWE-Other
|
CVE-2005-4168
|
2008-09-6 05:56 |
2005-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346959
|
7.5 |
HIGH
|
efiction_project
|
efiction
|
The "Upload new image" command in the "Manage Images" eFiction 1.1, when members are allowed to upload images, allows remote attackers to execute arbitrary PHP code by uploading a filename with a .ph…
|
NVD-CWE-Other
|
CVE-2005-4171
|
2008-09-6 05:56 |
2005-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346960
|
5.0 |
MEDIUM
|
efiction_project
|
efiction
|
eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information via a direct request to storyblock.php without arguments, which leaks the full pathname in the resulting PHP error m…
|
NVD-CWE-Other
|
CVE-2005-4172
|
2008-09-6 05:56 |
2005-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346961
|
5.0 |
MEDIUM
|
efiction_project
|
efiction
|
eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information by accessing phpinfo.php, which executes the PHP phpinfo function.
|
NVD-CWE-Other
|
CVE-2005-4173
|
2008-09-6 05:56 |
2005-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346962
|
7.5 |
HIGH
|
-
|
-
|
eFiction 1.0, 1.1, and 2.0, in unspecified environments, might allow remote attackers to conduct unauthorized operations by directly accessing (1) install.php or (2) upgrade.php. NOTE: it is unclear…
|
NVD-CWE-Other
|
CVE-2005-4174
|
2008-09-6 05:56 |
2005-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346963
|
4.3 |
MEDIUM
|
logisphere
|
logisphere
|
Cross-site scripting (XSS) vulnerability in LogiSphere 0.9.9j allows remote attackers to inject arbitrary Javascript via the msg command. NOTE: due to lack of appropriate details by the original rese…
|
NVD-CWE-Other
|
CVE-2005-4204
|
2008-09-6 05:56 |
2005-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346964
|
4.3 |
MEDIUM
|
asp-dev
|
xm_forum
|
Cross-site scripting (XSS) vulnerability in forum.asp in ASP-DEV XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via the forum_title parameter. NOTE: the provenance of th…
|
NVD-CWE-Other
|
CVE-2005-4256
|
2008-09-6 05:56 |
2005-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346965
|
7.8 |
HIGH
|
linksys
|
befw11s4 befw11s4_v3 befw11s4_v4 wrt54gs
|
Linksys WRT54GS and BEFW11S4 allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LA…
|
NVD-CWE-Other
|
CVE-2005-4257
|
2008-09-6 05:56 |
2005-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346966
|
7.5 |
HIGH
|
alt-n
|
mdaemon worldclient
|
WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to pe…
|
NVD-CWE-Other
|
CVE-2005-4266
|
2008-09-6 05:56 |
2005-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346967
|
7.8 |
HIGH
|
microsoft
|
ie windows_2003_server windows_xp
|
mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at…
|
NVD-CWE-Other
|
CVE-2005-4269
|
2008-09-6 05:56 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346968
|
7.8 |
HIGH
|
scientific_atlanta
|
dpx2100_cable_modem
|
Scientific Atlanta DPX2100 Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag s…
|
NVD-CWE-Other
|
CVE-2005-4275
|
2008-09-6 05:56 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346969
|
7.8 |
HIGH
|
westell
|
versalink
|
Westell Versalink 327W allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD). N…
|
NVD-CWE-Other
|
CVE-2005-4276
|
2008-09-6 05:56 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346970
|
7.8 |
HIGH
|
-
|
-
|
AppServ Open Project 2.5.3 allows remote attackers to cause a denial of service via a large HTTP request.
|
NVD-CWE-Other
|
CVE-2005-4296
|
2008-09-6 05:56 |
2005-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346971
|
7.5 |
HIGH
|
john_andersson
|
zixforum
|
SQL injection vulnerability in ZixForum 1.12 allows remote attackers to execute arbitrary SQL commands via the H_ID parameter to (1) zixforum/forum.asp, as used in (2) Headforums.asp and (3) Subject.…
|
NVD-CWE-Other
|
CVE-2005-4334
|
2008-09-6 05:56 |
2005-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346972
|
7.5 |
HIGH
|
blackboard
|
academic_suite
|
The login page in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to bypass authentication and gain privileg…
|
NVD-CWE-Other
|
CVE-2005-4337
|
2008-09-6 05:56 |
2005-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346973
|
10.0 |
HIGH
|
blackboard
|
academic_suite
|
announcement.pl in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to gain administrator privileges by setti…
|
NVD-CWE-Other
|
CVE-2005-4338
|
2008-09-6 05:56 |
2005-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346974
|
4.3 |
MEDIUM
|
blackboard
|
academic_suite
|
Cross-site scripting (XSS) vulnerability in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to inject arbitr…
|
NVD-CWE-Other
|
CVE-2005-4339
|
2008-09-6 05:56 |
2005-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346975
|
5.0 |
MEDIUM
|
blackboard
|
academic_suite
|
Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to list all available categories via a blank category_id par…
|
NVD-CWE-Other
|
CVE-2005-4341
|
2008-09-6 05:56 |
2005-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346976
|
4.3 |
MEDIUM
|
icms_content_management_systems
|
icms
|
Cross-site scripting (XSS) vulnerability in admin/Default.asp in iCMS allows remote attackers to inject arbitrary web script or HTML via the LoginMSG parameter. NOTE: the provenance of this issue is…
|
NVD-CWE-Other
|
CVE-2005-4396
|
2008-09-6 05:56 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346977
|
7.5 |
HIGH
|
icms_content_management_systems
|
icms
|
SQL injection vulnerability in RunScript.asp iCMS allows remote attackers to execute arbitrary SQL commands via the Event_ID parameter.
|
NVD-CWE-Other
|
CVE-2005-4397
|
2008-09-6 05:56 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346978
|
7.5 |
HIGH
|
media2_cms
|
media2_cms_shop
|
SQL injection vulnerability in default.asp in Media2 CMS Shop 18.x allows remote attackers to execute arbitrary SQL commands via the item parameter. NOTE: the provenance of this issue is unknown; th…
|
NVD-CWE-Other
|
CVE-2005-4404
|
2008-09-6 05:56 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346979
|
2.1 |
LOW
|
citrix
|
program_neighborhood_client
|
Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the…
|
NVD-CWE-Other
|
CVE-2005-4412
|
2008-09-6 05:56 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346980
|
4.3 |
MEDIUM
|
ibm
|
websphere_application_server
|
Multiple cross-site scripting (XSS) vulnerabilities in sample scripts in IBM WebSphere Application Server 6 allow remote attackers to inject arbitrary web script or HTML via the (1) E-mail address fi…
|
NVD-CWE-Other
|
CVE-2005-4413
|
2008-09-6 05:56 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346981
|
10.0 |
HIGH
|
open_lab
|
teamwork
|
Unspecified vulnerability in Teamwork 3 before alpha 1.7 has unknown impact and attack vectors, related to "a menu security bug."
|
NVD-CWE-Other
|
CVE-2005-4414
|
2008-09-6 05:56 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346982
|
4.3 |
MEDIUM
|
tml
|
tml
|
Cross-site scripting (XSS) vulnerability in index.php in TML CMS 0.5 allows remote attackers to inject arbitrary web script or HTML via the form parameter.
|
NVD-CWE-Other
|
CVE-2005-4415
|
2008-09-6 05:56 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346983
|
7.5 |
HIGH
|
tml
|
tml
|
SQL injection vulnerability in index.php in TML CMS 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2005-4416
|
2008-09-6 05:56 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346984
|
6.5 |
MEDIUM
|
toenda_software_development
|
toendacms
|
Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then acc…
|
NVD-CWE-Other
|
CVE-2005-4422
|
2008-09-6 05:56 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346985
|
6.5 |
MEDIUM
|
-
|
-
|
Unrestricted file upload vulnerability in PHPFM before 0.2.3 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension to an accessible directory, a…
|
NVD-CWE-Other
|
CVE-2005-4423
|
2008-09-6 05:56 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346986
|
7.2 |
HIGH
|
openldap
|
openldap
|
Untrusted search path vulnerability in OpenLDAP before 2.2.28-r3 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary buil…
|
NVD-CWE-Other
|
CVE-2005-4442
|
2008-09-6 05:56 |
2005-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346987
|
7.2 |
HIGH
|
gauche
|
gauche
|
Untrusted search path vulnerability in Gauche before 0.8.6-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build d…
|
NVD-CWE-Other
|
CVE-2005-4443
|
2008-09-6 05:56 |
2005-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346988
|
4.3 |
MEDIUM
|
aspbite
|
aspbite
|
Cross-site scripting (XSS) vulnerability in index.asp in ASPBite 8.x allows remote attackers to inject arbitrary web script or HTML via the strSearch parameter.
|
NVD-CWE-Other
|
CVE-2005-4446
|
2008-09-6 05:56 |
2005-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346989
|
7.5 |
HIGH
|
phpmyadmin
|
phpmyadmin
|
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to server_privileges.php, as demo…
|
NVD-CWE-Other
|
CVE-2005-4450
|
2008-09-6 05:56 |
2005-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346990
|
5.0 |
MEDIUM
|
livejournal
|
livejournal
|
cleanhtml.pl 1.129 in LiveJournal CVS before Dec 13 2005 allows remote attackers to inject scripting languages via the XSL namespace in XML, via vectors such as customview.cgi.
|
NVD-CWE-Other
|
CVE-2005-4455
|
2008-09-6 05:56 |
2005-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346991
|
7.8 |
HIGH
|
mailenable
|
mailenable_enterprise mailenable_professional
|
Multiple buffer overflows in MailEnable Professional 1.71 and Enterprise 1.1 before patch ME-10009 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via …
|
NVD-CWE-Other
|
CVE-2005-4456
|
2008-09-6 05:56 |
2005-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346992
|
7.5 |
HIGH
|
mailenable
|
mailenable_enterprise
|
MailEnable Enterprise 1.1 before patch ME-10009 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via several "..." (triple dot) sequences in a UID FETC…
|
NVD-CWE-Other
|
CVE-2005-4457
|
2008-09-6 05:56 |
2005-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346993
|
5.0 |
MEDIUM
|
-
|
-
|
cancel_account.php in WHM AutoPilot 2.5.30 and earlier allows remote attackers to cancel requests for arbitrary accounts via a modified c parameter.
|
NVD-CWE-Other
|
CVE-2005-3687
|
2008-09-6 05:55 |
2005-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346994
|
7.5 |
HIGH
|
uresk_links
|
uresk_links
|
Unspecified vulnerability in the administration interface in Uresk Links 2.0 Lite allows remote attackers to bypass authentication via unspecified vectors in index.php.
|
NVD-CWE-Other
|
CVE-2005-3697
|
2008-09-6 05:55 |
2005-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346995
|
7.5 |
HIGH
|
php_easy_download
|
php_easy_download
|
PHP Easy Download allows remote attackers to bypass authentication via edit.php.
|
NVD-CWE-Other
|
CVE-2005-3698
|
2008-09-6 05:55 |
2005-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346996
|
7.5 |
HIGH
|
revize_cms
|
revize_cms
|
SQL injection vulnerability in debug/query_results.jsp in Idetix Software Systems Revize CMS allows remote attackers to execute arbitrary SQL commands via the query parameter.
|
NVD-CWE-Other
|
CVE-2005-3727
|
2008-09-6 05:55 |
2005-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346997
|
5.0 |
MEDIUM
|
revize_cms
|
revize_cms
|
Idetix Software Systems Revize CMS stores conf/revize.xml under the web document root with insufficient access control, which allows remote attackers to obtain sensitive configuration information.
|
NVD-CWE-Other
|
CVE-2005-3728
|
2008-09-6 05:55 |
2005-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346998
|
5.0 |
MEDIUM
|
revize_cms
|
revize_cms
|
Idetix Software Systems Revize CMS allows remote attackers to obtain sensitive information via direct requests to files in the revize/debug directory, such as (1) apptables.html and (2) main.html.
|
NVD-CWE-Other
|
CVE-2005-3729
|
2008-09-6 05:55 |
2005-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346999
|
4.3 |
MEDIUM
|
revize_cms
|
revize_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in HTTPTranslatorServlet in Idetix Software Systems Revize CMS allow remote attackers to inject arbitrary web script or HTML via the (1) resourcety…
|
NVD-CWE-Other
|
CVE-2005-3730
|
2008-09-6 05:55 |
2005-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347000
|
10.0 |
HIGH
|
yassl
|
yassl
|
Unspecified vulnerability in yaSSL before 1.0.6 has unknown impact and attack vectors, related to "certificate chain processing."
|
NVD-CWE-Other
|
CVE-2005-3731
|
2008-09-6 05:55 |
2005-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|