|
352151
|
7.5 |
HIGH
|
ubbcentral
|
ubb.threads
|
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.p…
|
NVD-CWE-Other
|
CVE-2005-2058
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352152
|
5.0 |
MEDIUM
|
ubbcentral
|
ubb.threads
|
Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to spoof web conten…
|
NVD-CWE-Other
|
CVE-2005-2060
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352153
|
5.0 |
MEDIUM
|
ubbcentral
|
ubb.threads
|
Infopop UBB.Threads before 6.5.2 Beta allows remote attackers to include arbitrary files via the language parameter in a cookie followed by a null (%00) byte.
|
NVD-CWE-Other
|
CVE-2005-2061
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352154
|
4.3 |
MEDIUM
|
active_web_softwares
|
activebuyandsell
|
Multiple cross-site scripting (XSS) vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to sendpassword.asp or (2) Keywor…
|
NVD-CWE-Other
|
CVE-2005-2063
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352155
|
5.0 |
MEDIUM
|
asp-nuke
|
asp-nuke
|
Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to forgot_password.asp, or the (2) FirstName, …
|
NVD-CWE-Other
|
CVE-2005-2064
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352156
|
5.0 |
MEDIUM
|
asp-nuke
|
asp-nuke
|
HTTP response splitting vulnerability in language_select.asp in ASP Nuke 0.80 allows remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the LangCode paramete…
|
NVD-CWE-Other
|
CVE-2005-2065
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352157
|
7.5 |
HIGH
|
asp-nuke
|
asp-nuke
|
SQL injection vulnerability in comment_post.asp in ASP Nuke 0.80 allows remote attackers to execute arbitrary SQL statements via the TaskID parameter.
|
NVD-CWE-Other
|
CVE-2005-2066
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352158
|
7.5 |
HIGH
|
asp-nuke
|
asp-nuke
|
SQL injection vulnerability in article.asp in unknown versions of aspnuke allows remote attackers to execute arbitrary SQL commands via the articleid parameter.
|
NVD-CWE-Other
|
CVE-2005-2067
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352159
|
4.6 |
MEDIUM
|
sun
|
solaris
|
traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malformed -s argument with …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2005-2071
|
2016-10-18 12:24 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352160
|
5.0 |
MEDIUM
|
cgi-club
|
imtrset
|
im_trbbs.cgi in imTRSET 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the df parameter.
|
NVD-CWE-Other
|
CVE-2005-2082
|
2016-10-18 12:24 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352161
|
4.3 |
MEDIUM
|
telligent_systems
|
community_server_forums
|
Cross-site scripting (XSS) vulnerability in SearchResults.aspx in Community Forum allows remote attackers to inject arbitrary web script or HTML via the q parameter.
|
NVD-CWE-Other
|
CVE-2005-2084
|
2016-10-18 12:24 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352162
|
5.0 |
MEDIUM
|
infradig_systems
|
inframail_advantage
|
Buffer overflow in Inframail Advantage Server Edition 6.0 through 6.7 allows remote attackers to cause a denial of service (process crash) via a long (1) SMTP FROM field or possibly (2) FTP NLST comm…
|
NVD-CWE-Other
|
CVE-2005-2085
|
2016-10-18 12:24 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352163
|
7.5 |
HIGH
|
phpbb_group
|
phpbb
|
PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.
|
NVD-CWE-Other
|
CVE-2005-2086
|
2016-10-18 12:24 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352164
|
5.0 |
MEDIUM
|
drupal
|
drupal
|
Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.
|
NVD-CWE-Other
|
CVE-2005-2106
|
2016-10-18 12:24 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352165
|
5.0 |
MEDIUM
|
phpcms
|
phpcms
|
Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x before 1.2.1pl2 allows remote attackers to read or include arbitrary files, as demonstrated using a .. (dot dot) in the la…
|
NVD-CWE-Other
|
CVE-2005-1840
|
2016-10-18 12:23 |
2005-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352166
|
10.0 |
HIGH
|
ekg
|
ekg
|
Certain contributed scripts for ekg Gadu Gadu client 1.5 and earlier create temporary files insecurely, with unknown impact and attack vectors, a different vulnerability than CVE-2005-1916.
|
NVD-CWE-Other
|
CVE-2005-1850
|
2016-10-18 12:23 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352167
|
10.0 |
HIGH
|
ekg
|
ekg
|
A certain contributed script for ekg Gadu Gadu client 1.5 and earlier allows attackers to execute shell commands via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2005-1851
|
2016-10-18 12:23 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352168
|
5.0 |
MEDIUM
|
popper
|
popper
|
PHP remote file inclusion vulnerability in childwindow.inc.php in Popper 1.41-r2 and earlier allows remote attackers to execute arbitrary PHP code via the form parameter.
|
NVD-CWE-Other
|
CVE-2005-1870
|
2016-10-18 12:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352169
|
7.5 |
HIGH
|
drupal
|
drupal
|
Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain privileges, due to an "input check" that "is not impl…
|
NVD-CWE-Other
|
CVE-2005-1871
|
2016-10-18 12:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352170
|
7.5 |
HIGH
|
ibm
|
websphere_application_server
|
Buffer overflow in the administrative console in IBM WebSphere Application Server 5.x, when the global security option is enabled, allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-1872
|
2016-10-18 12:23 |
2005-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352171
|
7.5 |
HIGH
|
exhibit_engine
|
exhibit_engine
|
Multiple SQL injection vulnerabilities in list.php in Exhibit Engine (EE) 1.22 allow remote attackers to execute arbitrary SQL commands via the (1) search_row, (2) sort_row, (3) order or (4) perpage …
|
NVD-CWE-Other
|
CVE-2005-1875
|
2016-10-18 12:23 |
2005-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352172
|
5.0 |
MEDIUM
|
rakkarsoft
|
raknet
|
Rakkarsoft RakNet network library 2.33 and earlier, when released before 30 May 2005, and as used in multiple products including nFusion Elite Warriors: Vietnam, allows remote attackers to cause a de…
|
NVD-CWE-Other
|
CVE-2005-1899
|
2016-10-18 12:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352173
|
7.2 |
HIGH
|
kaspersky_lab
|
kaspersky_anti-virus kaspersky_anti-virus_personal
|
The klif.sys driver in Kaspersky Labs Anti-Virus 5.0.227, 5.0.228, and 5.0.335 on Windows 2000 allows local users to gain privileges by modifying certain critical code addresses that are later access…
|
NVD-CWE-Other
|
CVE-2005-1905
|
2016-10-18 12:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352174
|
5.0 |
MEDIUM
|
goodtech_systems
|
goodtech_smtp_server
|
GoodTech SMTP Server 5.14 allows remote attackers to cause a denial of service (application crash) via a RCPT TO command with an invalid argument, as demonstrated using an "A" character.
|
NVD-CWE-Other
|
CVE-2005-1931
|
2016-10-18 12:23 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352175
|
7.5 |
HIGH
|
-
|
-
|
Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.…
|
NVD-CWE-Other
|
CVE-2005-1943
|
2016-10-18 12:23 |
2005-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352176
|
2.1 |
LOW
|
xmysqladmin
|
xmysqladmin
|
xmysqladmin 1.0 and earlier allows local users to delete arbitrary files via a symlink attack on a database backup file in /tmp.
|
NVD-CWE-Other
|
CVE-2005-1944
|
2016-10-18 12:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352177
|
4.3 |
MEDIUM
|
invision_power_services
|
invision_community_blog
|
Cross-site scripting (XSS) vulnerability in the convert_highlite_words function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encod…
|
NVD-CWE-Other
|
CVE-2005-1945
|
2016-10-18 12:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352178
|
7.5 |
HIGH
|
invision_power_services
|
invision_community_blog
|
Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomme…
|
NVD-CWE-Other
|
CVE-2005-1946
|
2016-10-18 12:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352179
|
7.5 |
HIGH
|
invision_power_services
|
invision_gallery
|
Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rati…
|
NVD-CWE-Other
|
CVE-2005-1948
|
2016-10-18 12:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352180
|
7.5 |
HIGH
|
darryl_burgdorf
|
webhints
|
hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.
|
NVD-CWE-Other
|
CVE-2005-1950
|
2016-10-18 12:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352181
|
5.0 |
MEDIUM
|
oscommerce
|
oscommerce
|
Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences …
|
NVD-CWE-Other
|
CVE-2005-1951
|
2016-10-18 12:23 |
2005-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352182
|
7.5 |
HIGH
|
pico_server
|
pico_server
|
Directory traversal vulnerability in Pico Server (pServ) 3.3 allows remote attackers to read arbitrary files and execute arbitrary commands via a /./ (slash dot slash) before each .. (dot dot) sequen…
|
NVD-CWE-Other
|
CVE-2005-1952
|
2016-10-18 12:23 |
2005-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352183
|
7.5 |
HIGH
|
pico_server
|
pico_server
|
Heap-based buffer overflow in the CGI extension for Pico Server (pServ) 3.3 allows remote attackers to execute arbitrary code via a long HTTP request.
|
NVD-CWE-Other
|
CVE-2005-1953
|
2016-10-18 12:23 |
2005-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352184
|
5.0 |
MEDIUM
|
singapore
|
singapore
|
singapore 0.9.11 allows remote attackers to obtain sensitive information via a direct request to (1) admin.class.php, (2) any .tpl.php file in templates/admin_default/, or (3) any .tpl.php file in te…
|
NVD-CWE-Other
|
CVE-2005-1954
|
2016-10-18 12:23 |
2005-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352185
|
4.3 |
MEDIUM
|
singapore
|
singapore
|
Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.11 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter.
|
NVD-CWE-Other
|
CVE-2005-1955
|
2016-10-18 12:23 |
2005-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352186
|
5.0 |
MEDIUM
|
file_upload_manager
|
file_upload_manager
|
File Upload Manager allows remote attackers to upload arbitrary files by modifying the test variable to contain a value of '~~~~~~' (six tildes), which bypasses the file extension checks.
|
NVD-CWE-Other
|
CVE-2005-1956
|
2016-10-18 12:23 |
2005-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352187
|
7.5 |
HIGH
|
adam_mmedici
|
file_upload_manager
|
mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitra…
|
CWE-287
Improper Authentication
|
CVE-2005-1957
|
2016-10-18 12:23 |
2005-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352188
|
7.5 |
HIGH
|
e107
|
e107
|
The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the etrace_host parameter.
|
NVD-CWE-Other
|
CVE-2005-1966
|
2016-10-18 12:23 |
2005-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352189
|
5.1 |
MEDIUM
|
sun
|
j2se
|
Java Web Start in Java 2 Platform Standard Edition (J2SE) 5.0 and 5.0 Update 1 allows applications to assign permissions to themselves and gain privileges.
|
NVD-CWE-Other
|
CVE-2005-1973
|
2016-10-18 12:23 |
2005-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352190
|
5.1 |
MEDIUM
|
sun
|
j2se
|
Unspecified vulnerability in Java 2 Platform, Standard Edition (J2SE) 5.0 and 5.0 Update 1 and J2SE 1.4.2 up to 1.4.2_07, as used in multiple products and platforms including (1) HP-UX and (2) APC Po…
|
NVD-CWE-noinfo
|
CVE-2005-1974
|
2016-10-18 12:23 |
2005-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352191
|
5.0 |
MEDIUM
|
mcgallery
|
mcgallery
|
show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, via a modified host parameter.
|
NVD-CWE-Other
|
CVE-2005-1997
|
2016-10-18 12:23 |
2005-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352192
|
5.0 |
MEDIUM
|
mcgallery
|
mcgallery
|
Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
|
NVD-CWE-Other
|
CVE-2005-1998
|
2016-10-18 12:23 |
2005-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352193
|
4.3 |
MEDIUM
|
php_arena
|
pafiledb
|
Multiple cross-site scripting (XSS) vulnerabilities in pafiledb.php in paFileDB 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sortby or (2) filelist parameters to the …
|
NVD-CWE-Other
|
CVE-2005-1999
|
2016-10-18 12:23 |
2005-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352194
|
7.5 |
HIGH
|
php_arena
|
pafiledb
|
Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in the team login for…
|
NVD-CWE-Other
|
CVE-2005-2000
|
2016-10-18 12:23 |
2005-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352195
|
5.0 |
MEDIUM
|
php_arena
|
pafiledb
|
Directory traversal vulnerability in pafiledb.php in paFileDB 3.1 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the action parameter.
|
NVD-CWE-Other
|
CVE-2005-2001
|
2016-10-18 12:23 |
2005-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352196
|
7.5 |
HIGH
|
mambo
|
mambo
|
SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_rating parameter.
|
NVD-CWE-Other
|
CVE-2005-2002
|
2016-10-18 12:23 |
2005-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352197
|
5.0 |
MEDIUM
|
ultimate_php_board
|
ultimate_php_board
|
Ultimate PHP Board (UPB) 1.9.6 GOLD allows remote attackers to obtain sensitive information via an invalid (zero) id parameter to (1) viewtopic.php, (2) profile.php, or (3) newpost.php, which reveals…
|
NVD-CWE-Other
|
CVE-2005-2003
|
2016-10-18 12:23 |
2005-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352198
|
5.0 |
MEDIUM
|
ultimate_php_board
|
ultimate_php_board
|
Multiple cross-site scripting vulnerabilities in Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ref parameter to login.php, …
|
NVD-CWE-Other
|
CVE-2005-2004
|
2016-10-18 12:23 |
2005-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352199
|
5.0 |
MEDIUM
|
ultimate_php_board
|
ultimate_php_board
|
Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier stores the users.dat file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information o…
|
NVD-CWE-Other
|
CVE-2005-2005
|
2016-10-18 12:23 |
2005-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352200
|
7.5 |
HIGH
|
black_cactus
|
warrior_kings warrior_kings_battles
|
Format string vulnerability in Warrior Kings: Battles 1.23 and earlier and Warrior Kings 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a nickname.
|
NVD-CWE-Other
|
CVE-2005-1702
|
2016-10-18 12:22 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|