|
357701
|
7.5 |
HIGH
|
mybulletinboard
|
mybulletinboard
|
SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the awayday parameter.
|
NVD-CWE-Other
|
CVE-2005-3326
|
2008-09-6 05:54 |
2005-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357702
|
7.5 |
HIGH
|
belchior_foundry
|
vcard
|
PHP remote file include vulnerability in admin/define.inc.php in Belchior Foundry vCard 2.9 allows remote attackers to execute arbitrary PHP code via the match parameter.
|
NVD-CWE-Other
|
CVE-2005-3332
|
2008-09-6 05:54 |
2005-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357703
|
4.3 |
MEDIUM
|
mantis
|
mantis
|
Multiple cross-site scripting (XSS) vulnerabilities in Mantis before 0.19.3 allow remote attackers to inject arbitrary web script or HTML via (1) unknown vectors involving Javascript and (2) mantis/v…
|
NVD-CWE-Other
|
CVE-2005-3337
|
2008-09-6 05:54 |
2005-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357704
|
5.0 |
MEDIUM
|
mantis
|
mantis
|
Unspecified vulnerability in Mantis before 0.19.3, when using reminders, causes Mantis to display the real email addresses of users.
|
NVD-CWE-Other
|
CVE-2005-3338
|
2008-09-6 05:54 |
2005-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357705
|
7.2 |
HIGH
|
mantis
|
mantis
|
Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2005-3339
|
2008-09-6 05:54 |
2005-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357706
|
4.3 |
MEDIUM
|
comersus_open_technologies
|
comersus_backoffice_lite comersus_backoffice_plus
|
Cross-site scripting (XSS) vulnerability in Comersus BackOffice allows remote attackers to inject arbitrary web script or HTML via the error parameter to comersus_backoffice_supportError.asp. NOTE: …
|
NVD-CWE-Other
|
CVE-2005-3397
|
2008-09-6 05:54 |
2005-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357707
|
7.5 |
HIGH
|
subdreamer
|
subdreamer
|
Multiple SQL injection vulnerabilities in Subdreamer 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the loginusername parameter or (2) cookies to (a) subdreamer.php, (b) ipb2.…
|
NVD-CWE-Other
|
CVE-2005-3423
|
2008-09-6 05:54 |
2005-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357708
|
4.3 |
MEDIUM
|
gnu
|
gnump3d
|
Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2005-3424.
|
NVD-CWE-Other
|
CVE-2005-3425
|
2008-09-6 05:54 |
2005-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357709
|
5.0 |
MEDIUM
|
cisco
|
content_services_switch_11500
|
Cisco CSS 11500 Content Services Switch (CSS) with SSL termination services allows remote attackers to cause a denial of service (memory corruption and device reload) via a malformed client certifica…
|
NVD-CWE-Other
|
CVE-2005-3426
|
2008-09-6 05:54 |
2005-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357710
|
4.6 |
MEDIUM
|
sony
|
first4internet_xcp_content_management
|
The aries.sys driver in Sony First4Internet XCP DRM software hides any file, registry key, or process with a name that starts with "$sys$", which allows attackers to hide activities on a system that …
|
NVD-CWE-Other
|
CVE-2005-3474
|
2008-09-6 05:54 |
2005-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357711
|
4.3 |
MEDIUM
|
invision_power_services
|
invision_gallery
|
Multiple interpretation error in the image upload handling code in Invision Gallery 2.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML or script in an image whose ty…
|
NVD-CWE-Other
|
CVE-2005-3477
|
2008-09-6 05:54 |
2005-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357712
|
4.3 |
MEDIUM
|
ringtail
|
casebook
|
Cross-site scripting (XSS) vulnerability in login.asp in Ringtail CaseBook 6.1.0 allows remote attackers to inject arbitrary web script or HTML via the users parameter.
|
NVD-CWE-Other
|
CVE-2005-3479
|
2008-09-6 05:54 |
2005-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357713
|
5.0 |
MEDIUM
|
ringtail
|
casebook
|
login.asp in Ringtail CaseBook 6.1.0 displays different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.
|
NVD-CWE-Other
|
CVE-2005-3480
|
2008-09-6 05:54 |
2005-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357714
|
4.3 |
MEDIUM
|
ar-blog
|
ar-blog
|
Cross-site scripting (XSS) vulnerability in Ar-blog 5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a blog comment.
|
NVD-CWE-Other
|
CVE-2005-3494
|
2008-09-6 05:54 |
2005-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357715
|
7.5 |
HIGH
|
ar-blog
|
ar-blog
|
Ar-blog 5.2 and earlier allows remote attackers to bypass authentication by modifying cookies.
|
NVD-CWE-Other
|
CVE-2005-3495
|
2008-09-6 05:54 |
2005-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357716
|
7.5 |
HIGH
|
ketm
|
ketm
|
Buffer overflow in KETM 0.0.6 allows local users to execute arbitrary code via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-3535
|
2008-09-6 05:54 |
2005-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357717
|
7.5 |
HIGH
|
phpbb_group
|
phpbb
|
SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type.
|
NVD-CWE-Other
|
CVE-2005-3536
|
2008-09-6 05:54 |
2005-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357718
|
5.0 |
MEDIUM
|
phpbb_group
|
phpbb
|
A "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit private messages of other users, probably by modifying certain parameters or other inputs.
|
NVD-CWE-Other
|
CVE-2005-3537
|
2008-09-6 05:54 |
2005-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357719
|
7.5 |
HIGH
|
petris
|
petris
|
Buffer overflow in petris before 1.0.1 allows remote attackers to execute arbitrary code via unspecified attack vectors.
|
NVD-CWE-Other
|
CVE-2005-3540
|
2008-09-6 05:54 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357720
|
5.0 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
CRLF injection vulnerability in phpMyAdmin before 2.6.4-pl4 allows remote attackers to conduct HTTP response splitting attacks via unspecified scripts.
|
NVD-CWE-Other
|
CVE-2005-3621
|
2008-09-6 05:54 |
2005-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357721
|
5.0 |
MEDIUM
|
redhat
|
fedora_core
|
Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configurat…
|
NVD-CWE-Other
|
CVE-2005-3630
|
2008-09-6 05:54 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357722
|
7.5 |
HIGH
|
oracle
|
database_server database_server_lite oracle10g oracle8i oracle9i
|
Oracle Databases running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication by supplying a valid username.
|
NVD-CWE-Other
|
CVE-2005-3641
|
2008-09-6 05:54 |
2005-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357723
|
7.5 |
HIGH
|
ibm
|
informix_dynamic_database_server
|
IBM Informix Dynamic Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account by supplying an invalid u…
|
NVD-CWE-Other
|
CVE-2005-3642
|
2008-09-6 05:54 |
2005-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357724
|
7.5 |
HIGH
|
ibm
|
db2_universal_database
|
IBM DB2 Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account without supplying a password.
|
NVD-CWE-Other
|
CVE-2005-3643
|
2008-09-6 05:54 |
2005-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357725
|
10.0 |
HIGH
|
internet_key_exchange
|
internet_key_exchange
|
Multiple unspecified format string vulnerabilities in multiple unspecified implementations of Internet Key Exchange version 1 (IKEv1) have multiple unspecified attack vectors and impacts, as demonstr…
|
NVD-CWE-Other
|
CVE-2005-3666
|
2008-09-6 05:54 |
2005-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357726
|
5.0 |
MEDIUM
|
internet_key_exchange
|
internet_key_exchange
|
Multiple unspecified vulnerabilities in multiple unspecified implementations of Internet Key Exchange version 1 (IKEv1) have multiple unspecified attack vectors and impacts related to denial of servi…
|
NVD-CWE-Other
|
CVE-2005-3667
|
2008-09-6 05:54 |
2005-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357727
|
5.0 |
MEDIUM
|
internet_key_exchange
|
internet_key_exchange
|
Multiple buffer overflows in multiple unspecified implementations of Internet Key Exchange version 1 (IKEv1) have multiple unspecified attack vectors and impacts related to denial of service, as demo…
|
NVD-CWE-Other
|
CVE-2005-3668
|
2008-09-6 05:54 |
2005-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357728
|
4.6 |
MEDIUM
|
microsoft
|
antispyware
|
Unquoted Windows search path vulnerability in Microsoft AntiSpyware might allow local users to execute code via a malicious c:\program.exe file, which is run by AntiSpywareMain.exe when it attempts t…
|
NVD-CWE-Other
|
CVE-2005-2935
|
2008-09-6 05:53 |
2005-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357729
|
7.2 |
HIGH
|
vmware
|
workstation
|
Unquoted Windows search path vulnerability in VMWare Workstation 5.0.0 build-13124 might allow local users to gain privileges via a malicious "program.exe" file in the C: folder.
|
NVD-CWE-Other
|
CVE-2005-2939
|
2008-09-6 05:53 |
2005-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357730
|
7.2 |
HIGH
|
microsoft
|
antispyware
|
Unquoted Windows search path vulnerability in Microsoft Antispyware 1.0.509 (Beta 1) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, involving the prog…
|
NVD-CWE-Other
|
CVE-2005-2940
|
2008-09-6 05:53 |
2005-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357731
|
4.6 |
MEDIUM
|
brent_ely
|
gnome_workstation_command_center
|
The perform_file_save function in GNOME Workstation Command Center (gwcc) 0.9.6 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the gwcc_out.txt tempora…
|
NVD-CWE-Other
|
CVE-2005-2944
|
2008-09-6 05:53 |
2005-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357732
|
2.1 |
LOW
|
ntlmaps
|
ntlmaps
|
The post-installation script for ntlmaps before 0.9.9 sets world-readable permissions for the configuration file, which allows local users to obtain the username and password.
|
NVD-CWE-Other
|
CVE-2005-2962
|
2008-09-6 05:53 |
2005-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357733
|
7.5 |
HIGH
|
symantec_veritas
|
storage_exec storagecentral
|
Multiple heap-based and stack-based buffer overflows in certain DCOM server components in VERITAS Storage Exec Storage Exec 5.3 before Hotfix 9 and StorageCentral 5.2 before Hot Fix 2 allow remote at…
|
NVD-CWE-Other
|
CVE-2005-2996
|
2008-09-6 05:53 |
2005-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357734
|
5.0 |
MEDIUM
|
bugada_andrea
|
php_advanced_transfer_manager
|
Multiple directory traversal vulnerabilities in PHP Advanced Transfer Manager 1.30 allow remote attackers to read arbitrary files via ".." sequences in (1) the currentdir parameter to txt.php, or the…
|
NVD-CWE-Other
|
CVE-2005-2997
|
2008-09-6 05:53 |
2005-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357735
|
7.5 |
HIGH
|
bugada_andrea
|
php_advanced_transfer_manager
|
PHP Advanced Transfer Manager 1.30 has a default password for the administrator user, which allows remote attackers to upload and execute arbitrary PHP files.
|
NVD-CWE-Other
|
CVE-2005-2998
|
2008-09-6 05:53 |
2005-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357736
|
5.0 |
MEDIUM
|
bugada_andrea
|
php_advanced_transfer_manager
|
PHP Advanced Transfer Manager 1.30 allows remote attackers to obtain sensitive PHP configuration information via a direct request to test.php.
|
NVD-CWE-Other
|
CVE-2005-2999
|
2008-09-6 05:53 |
2005-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357737
|
4.3 |
MEDIUM
|
bugada_andrea
|
php_advanced_transfer_manager
|
Multiple cross-site scripting (XSS) vulnerabilities in viewers/txt.php in PHP Advanced Transfer Manager 1.30 allow remote attackers to inject arbitrary web script or HTML via the (1) font, (2) normal…
|
NVD-CWE-Other
|
CVE-2005-3000
|
2008-09-6 05:53 |
2005-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357738
|
7.5 |
HIGH
|
-
|
-
|
SQL injection vulnerability in index.php in NooTopList 1.0.0 release 17 allows remote attackers to execute arbitrary SQL commands via the (1) o or (2) sort parameters.
|
NVD-CWE-Other
|
CVE-2005-3003
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357739
|
7.5 |
HIGH
|
amar_sagoo
|
tofu
|
Tofu 0.2 allows remote attackers to execute arbitrary Python code via crafted pickled objects, which Tofu unpickles and executes.
|
NVD-CWE-Other
|
CVE-2005-3008
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357740
|
7.5 |
HIGH
|
cutephp
|
cutenews
|
Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers to execute arbitrary PHP code via the HTTP_CLIENT…
|
NVD-CWE-Other
|
CVE-2005-3010
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357741
|
2.1 |
LOW
|
simplecdr-x
|
simplecdr-x
|
The MasterDataCD::createImage function in masterdatacd.cpp for SimpleCDR-X 1.3.3 creates the .temp temporary directory with insecure permissions, which allows local users to read sensitive ISO images.
|
NVD-CWE-Other
|
CVE-2005-3012
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357742
|
4.3 |
MEDIUM
|
ensim
|
webppliance
|
Cross-site scripting (XSS) vulnerability in Ensim webplliance allows remote attackers to inject arbitrary web script or HTML via the Login (OCW_login_username) field.
|
NVD-CWE-Other
|
CVE-2005-3014
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357743
|
4.3 |
MEDIUM
|
ibm
|
lotus_domino lotus_domino_enterprise_server
|
Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) BaseTarget or (2) Src parameters.
|
NVD-CWE-Other
|
CVE-2005-3015
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357744
|
10.0 |
HIGH
|
francisco_burzi
|
php-nuke
|
Multiple unspecified vulnerabilities in the WYSIWYG editor in PHP-Nuke before 7.9 Final have unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2005-3016
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357745
|
4.3 |
MEDIUM
|
content2web
|
content2web
|
PHP file inclusion vulnerability in index.php in Content2Web 1.0.1 allows remote attackers to include arbitrary files via the show parameter, which can lead to resultant errors such as path disclosur…
|
NVD-CWE-Other
|
CVE-2005-3017
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357746
|
7.5 |
HIGH
|
cambridge_computer_corporation
|
vxftpsrv
|
Buffer overflow in vxFtpSrv 0.9.7 allows remote attackers to execute arbitrary code via a long USER name.
|
NVD-CWE-Other
|
CVE-2005-3031
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357747
|
7.5 |
HIGH
|
cambridge_computer_corporation
|
vxtftpsrv
|
Buffer overflow in vxTftpSrv 1.7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TFTP request with a long filename argument.
|
NVD-CWE-Other
|
CVE-2005-3032
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357748
|
7.5 |
HIGH
|
cambridge_computer_corporation
|
vxweb
|
Stack-based buffer overflow in vxWeb 1.1.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.
|
NVD-CWE-Other
|
CVE-2005-3033
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357749
|
7.5 |
HIGH
|
compuware
|
driverstudio
|
Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to bypass authentication via a null session.
|
NVD-CWE-Other
|
CVE-2005-3034
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357750
|
5.0 |
MEDIUM
|
compuware
|
driverstudio
|
Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to cause a denial of service (reboot) via a UDP packet sent directly to port 9110.
|
NVD-CWE-Other
|
CVE-2005-3035
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|