|
357751
|
4.6 |
MEDIUM
|
ttxn
|
file_transfer_anywhere
|
File Transfer Anywhere 3.01 stores sensitive password information in plaintext in the PASS value in the "File Transfer Anywhere" registry key, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-3036
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357752
|
4.3 |
MEDIUM
|
handy_address_book
|
handy_address_book_server
|
Cross-site scripting (XSS) vulnerability in Handy Address Book Server 1.1 allows remote attackers to inject arbitrary web script or HTML via the SEARCHTEXT parameter in a demos URL.
|
NVD-CWE-Other
|
CVE-2005-3037
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357753
|
5.0 |
MEDIUM
|
hosting_controller
|
hosting_controller
|
Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related to "the PHP vulnerability."
|
NVD-CWE-Other
|
CVE-2005-3038
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357754
|
7.5 |
HIGH
|
mall23
|
mall23
|
SQL injection vulnerability in infopage.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idPage parameter.
|
NVD-CWE-Other
|
CVE-2005-3039
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357755
|
5.0 |
MEDIUM
|
tac
|
vista
|
Directory traversal vulnerability in the web interface (ISALogin.dll) for TAC Vista 4.0, and possibly other versions before 4.3, allows remote attackers to read arbitrary files via ".." sequences in …
|
NVD-CWE-Other
|
CVE-2005-3040
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357756
|
5.0 |
MEDIUM
|
multitheftauto
|
multitheftauto
|
MultiTheftAuto 0.5 patch 1 and earlier does not properly verify client privileges when running command 40, which allows remote attackers to change or delete the message of the day (motd.txt).
|
NVD-CWE-Other
|
CVE-2005-3064
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357757
|
10.0 |
HIGH
|
eric_integrated_development_environment
|
eric_integrated_development_environment
|
Unspecified vulnerability in Eric Integrated Development Environment (eric3) before 3.7.2 has unknown impact and attack vectors related to a "potential security exploit."
|
NVD-CWE-Other
|
CVE-2005-3068
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357758
|
2.1 |
LOW
|
hylafax
|
hylafax
|
xferfaxstats in HylaFax 4.2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the xferfax$$ temporary file.
|
NVD-CWE-Other
|
CVE-2005-3069
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357759
|
3.6 |
LOW
|
hylafax
|
hylafax
|
HylaFax 4.2.1 and earlier does not create or verify ownership of the UNIX domain socket, which might allow local users to read faxes and cause a denial of service by creating the socket using the hyl…
|
NVD-CWE-Other
|
CVE-2005-3070
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357760
|
7.5 |
HIGH
|
rsyslog
|
rsyslogd
|
SQL injection vulnerability in rsyslogd in RSyslog before 1.0.1 and before 1.10.1 allows remote attackers to execute arbitrary SQL commands via crafted syslog messages.
|
NVD-CWE-Other
|
CVE-2005-3074
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357761
|
7.5 |
HIGH
|
mpc-donkey
|
zengaia
|
SQL injection vulnerability in Zengaia before 0.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-3075
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357762
|
7.5 |
HIGH
|
simplog
|
simplog
|
Simplog 0.9.1 might allow remote attackers to execute arbitrary SQL commands or trigger SQL error messages via invalid (1) pid, (2) blogid, (3) cid, or (4) m parameters to archive.php, or the (5) blo…
|
NVD-CWE-Other
|
CVE-2005-3076
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357763
|
5.0 |
MEDIUM
|
microsoft
|
ie_for_macintosh
|
Microsoft Internet Explorer 5.2.3 for Mac OS allows remote attackers to cause a denial of service (crash) via a web page with malformed attributes in a BGSOUND tag, possibly involving double-quotes i…
|
NVD-CWE-Other
|
CVE-2005-3077
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357764
|
4.3 |
MEDIUM
|
punbb
|
punbb
|
Cross-site scripting (XSS) vulnerability in PunBB before 1.2.8 allows remote attackers to inject arbitrary web script or HTML via the "forgotten e-mail" feature.
|
NVD-CWE-Other
|
CVE-2005-3078
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357765
|
4.6 |
MEDIUM
|
punbb
|
punbb
|
PunBB before 1.2.8 allows remote attackers to perform "code inclusion" via the user language selection.
|
NVD-CWE-Other
|
CVE-2005-3079
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357766
|
5.0 |
MEDIUM
|
geshi
|
geshi
|
contrib/example.php in GeSHi before 1.0.7.3 allows remote attackers to read arbitrary files via the language field without a source field set.
|
NVD-CWE-Other
|
CVE-2005-3080
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357767
|
4.6 |
MEDIUM
|
wzdftpd
|
wzdftpd
|
wzdftpd 0.5.4 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the SITE command.
|
NVD-CWE-Other
|
CVE-2005-3081
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357768
|
5.0 |
MEDIUM
|
sony
|
playstation_portable
|
Buffer overflow in the TIFF library in the Photo Viewer for Sony PSP 2.0 firmware allows remote attackers to cause a denial of service via a crafted TIFF image.
|
NVD-CWE-Other
|
CVE-2005-3084
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357769
|
4.3 |
MEDIUM
|
riverdark_studios
|
rss_syndicator_module
|
Multiple cross-site scripting (XSS) vulnerabilities in rss.php in Riverdark Studios RSS Syndicator module 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) forum or (2) …
|
NVD-CWE-Other
|
CVE-2005-3085
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357770
|
6.4 |
MEDIUM
|
contentserv
|
contentserv
|
Directory traversal vulnerability in admin/about.php in contentServ 3.1 allows remote attackers to read or include arbitrary files via ".." sequences in the ctsWebsite parameter.
|
NVD-CWE-Other
|
CVE-2005-3086
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357771
|
5.0 |
MEDIUM
|
securew2
|
securew2
|
The SecureW2 3.0 TLS implementation uses weak random number generators (rand and srand from system time) during generation of the pre-master secret (PMS), which makes it easier for attackers to guess…
|
NVD-CWE-Other
|
CVE-2005-3087
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357772
|
4.3 |
MEDIUM
|
mantis
|
mantis
|
Cross-site scripting (XSS) vulnerability in Mantis before 1.0.0rc1 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, as identified by bug#0005751 "thraxisp".
|
NVD-CWE-Other
|
CVE-2005-3091
|
2008-09-6 05:53 |
2005-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357773
|
5.0 |
MEDIUM
|
nokia
|
3210 7610
|
Nokia 7610 and 3210 phones allows attackers to cause a denial of service via certain characters in the filename of a Bluetooth OBEX transfer.
|
NVD-CWE-Other
|
CVE-2005-3093
|
2008-09-6 05:53 |
2005-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357774
|
5.0 |
MEDIUM
|
avi_alkalay
|
contribute.cgi
|
Directory traversal vulnerability in Avi Alkalay contribute.cgi (aka contribute.pl), dated 16 Jun 2002, allows remote attackers to overwrite arbitrary files via ".." sequences in the contribdir varia…
|
NVD-CWE-Other
|
CVE-2005-3097
|
2008-09-6 05:53 |
2005-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357775
|
5.0 |
MEDIUM
|
astaro
|
security_linux
|
Unspecified "PPTP Remote DoS Vulnerability" in Astaro Security Linux 4.027 allows attackers to cause a denial of service.
|
NVD-CWE-Other
|
CVE-2005-3100
|
2008-09-6 05:53 |
2005-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357776
|
5.0 |
MEDIUM
|
six_apart
|
movable_type
|
The password reset feature in Movable Type before 3.2 generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.
|
NVD-CWE-Other
|
CVE-2005-3101
|
2008-09-6 05:53 |
2005-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357777
|
5.0 |
MEDIUM
|
-
|
-
|
The administrative interface in Movable Type allows attackers to upload files with arbitrary extensions under the web root.
|
NVD-CWE-Other
|
CVE-2005-3102
|
2008-09-6 05:53 |
2005-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357778
|
4.3 |
MEDIUM
|
six_apart
|
movable_type
|
Cross-site scripting (XSS) vulnerability in Movable Type before 3.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title, (2) category, (3) body, (4) extended body, and (5…
|
NVD-CWE-Other
|
CVE-2005-3103
|
2008-09-6 05:53 |
2005-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357779
|
2.6 |
LOW
|
six_apart
|
movable_type
|
mt-comments.cgi in Movable Type before 3.2 allows attackers to redirect users to other web sites via URLs in comments.
|
NVD-CWE-Other
|
CVE-2005-3104
|
2008-09-6 05:53 |
2005-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357780
|
2.1 |
LOW
|
macromedia
|
breeze
|
The "reset password" feature in Macromedia Breeze 5.0 stores passwords in plaintext in the database instead of the hash, which allows attackers with access to the database to obtain the passwords.
|
NVD-CWE-Other
|
CVE-2005-3112
|
2008-09-6 05:53 |
2005-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357781
|
2.1 |
LOW
|
mpeg-tools
|
mpeg-tools
|
mpeg-tools before 1.5b-r2 creates multiple temporary files insecurely, which allows local users to overwrite arbitrary files via (1) ts.stat, (2) ts.mpg, (3) foobar, (4) blockbar, or (5) foobar[NNN].
|
NVD-CWE-Other
|
CVE-2005-3115
|
2008-09-6 05:53 |
2005-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357782
|
2.1 |
LOW
|
eduard_bloch
|
module-assistant
|
A rule file in module-assistant before 0.9.10 causes a temporary file to be created insecurely, which allows local users to conduct unauthorized operations.
|
NVD-CWE-Other
|
CVE-2005-3121
|
2008-09-6 05:53 |
2005-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357783
|
5.0 |
MEDIUM
|
4d
|
webstar
|
Unspecified vulnerability in the Mailbox Server for 4D WebStar before 5.3.5 allows attackers to cause a denial of service (crash) via IMAP clients on Mac OS X 10.4 Mail 2.
|
NVD-CWE-Other
|
CVE-2005-3143
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357784
|
5.0 |
MEDIUM
|
standards_based_linux_instrumentation
|
sblim-sfcb
|
httpAdapter.c in sblim-sfcb before 0.9.2 allows remote attackers to cause a denial of service via long HTTP headers.
|
NVD-CWE-Other
|
CVE-2005-3144
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357785
|
5.0 |
MEDIUM
|
standards_based_linux_instrumentation
|
sblim-sfcb
|
httpAdapter.c in sblim-sfcb before 0.9.2 allows remote attackers to cause a denial of service (resource consumption) by connecting to sblim-sfcb but not sending any data.
|
NVD-CWE-Other
|
CVE-2005-3145
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357786
|
2.1 |
LOW
|
storebackup suse
|
storebackup suse_linux
|
StoreBackup before 1.19 allows local users to perform unauthorized operations on arbitrary files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2005-3146
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357787
|
2.1 |
LOW
|
storebackup suse
|
storebackup suse_linux
|
StoreBackup before 1.19 creates the backup root with world-readable permissions, which allows local users to obtain sensitive information.
|
NVD-CWE-Other
|
CVE-2005-3147
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357788
|
4.6 |
MEDIUM
|
storebackup suse
|
storebackup suse_linux
|
StoreBackup before 1.19 does not properly set the uid and guid for symbolic links (1) that are backed up by storeBackup.pl, or (2) recovered by storeBackupRecover.pl, which could cause files to be re…
|
NVD-CWE-Other
|
CVE-2005-3148
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357789
|
7.5 |
HIGH
|
weex
|
weex
|
Format string vulnerability in the Log_Flush function in Weex 2.6.1.5, 2.6.1, and possibly other versions allows remote FTP servers to execute arbitrary code via format strings in filenames.
|
NVD-CWE-Other
|
CVE-2005-3150
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357790
|
7.5 |
HIGH
|
blender
|
blender
|
Buffer overflow in blenderplay in Blender Player 2.37a allows attackers to execute arbitrary code via a long command line argument.
|
NVD-CWE-Other
|
CVE-2005-3151
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357791
|
7.5 |
HIGH
|
mailenable
|
mailenable_enterprise mailenable_professional
|
Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-3155
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357792
|
7.5 |
HIGH
|
php_fusion
|
php_fusion
|
Multiple SQL injection vulnerabilities in photogallery.php in PHP-Fusion allow remote attackers to execute arbitrary SQL commands via the (1) album and (2) photo parameters.
|
NVD-CWE-Other
|
CVE-2005-3160
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357793
|
5.0 |
MEDIUM
|
polipo
|
polipo
|
Unspecified vulnerability in Polipo 0.9.8 and earlier allows attackers to read files outside of the web root.
|
NVD-CWE-Other
|
CVE-2005-3163
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357794
|
4.3 |
MEDIUM
|
mediawiki
|
mediawiki
|
Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.4.9 allow remote attackers to inject arbitrary web script or HTML via (1) <math> tags or (2) Extension or <nowiki> sections t…
|
NVD-CWE-Other
|
CVE-2005-3165
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357795
|
5.0 |
MEDIUM
|
mediawiki
|
mediawiki
|
Unspecified vulnerability in "edit submission handling" for MediaWiki 1.4.x before 1.4.10 and 1.3.x before 1.3.16 allows remote attackers to cause a denial of service (corruption of the previous subm…
|
NVD-CWE-Other
|
CVE-2005-3166
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357796
|
4.3 |
MEDIUM
|
mediawiki
|
mediawiki
|
Incomplete blacklist vulnerability in MediaWiki before 1.4.11 does not properly remove certain CSS inputs (HTML inline style attributes) that are processed as active content by Internet Explorer, whi…
|
NVD-CWE-Other
|
CVE-2005-3167
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357797
|
7.5 |
HIGH
|
microsoft
|
windows_2000
|
The SECEDIT command on Microsoft Windows 2000 before Update Rollup 1 for SP4, when using a security template to set Access Control Lists (ACLs) on folders, does not apply ACLs on folders that are lis…
|
NVD-CWE-Other
|
CVE-2005-3168
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357798
|
5.0 |
MEDIUM
|
microsoft
|
windows_2000
|
Microsoft Windows 2000 before Update Rollup 1 for SP4, when the "audit directory service access" policy is enabled, does not record a 565 event message for File Delete Child operations on an Active D…
|
NVD-CWE-Other
|
CVE-2005-3169
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357799
|
4.6 |
MEDIUM
|
microsoft
|
windows_2000
|
Microsoft Windows 2000 before Update Rollup 1 for SP4 records Event ID 1704 to indicate that Group Policy security settings were successfully updated, even when the processing fails such as when Ntus…
|
NVD-CWE-Other
|
CVE-2005-3171
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357800
|
5.0 |
MEDIUM
|
microsoft
|
windows_2000
|
The WideCharToMultiByte function in Microsoft Windows 2000 before Update Rollup 1 for SP4 does not properly convert strings with Japanese composite characters in the last character, which could preve…
|
NVD-CWE-Other
|
CVE-2005-3172
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|