271021
|
- |
|
amarok
|
web_frontend
|
amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and pass…
|
NVD-CWE-Other
|
CVE-2005-2029
|
2008-09-6 05:50 |
2005-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271022
|
- |
|
socialmpn
|
socialmpn
|
Multiple SQL injection vulnerabilities in socialMPN allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter to article.php, (2) uname parameter to user.php, (3) siteid para…
|
NVD-CWE-Other
|
CVE-2005-2031
|
2008-09-6 05:50 |
2005-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271023
|
- |
|
fortibus
|
fortibus_cms
|
Fortibus CMS 4.0.0 allows remote attackers to modify information of other users, including Admin, via the "My info" page.
|
NVD-CWE-Other
|
CVE-2005-2038
|
2008-09-6 05:50 |
2005-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271024
|
- |
|
nanoblogger
|
nanoblogger
|
Unknown vulnerability in "various plugins" for NanoBlogger 3.2.1 and earlier allows remote attackers to execute arbitrary commands.
|
NVD-CWE-Other
|
CVE-2005-2039
|
2008-09-6 05:50 |
2005-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271025
|
- |
|
telnetd
|
telnetd
|
Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal before 0.6.5 may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2005-0468 and CV…
|
NVD-CWE-Other
|
CVE-2005-2040
|
2008-09-6 05:50 |
2005-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271026
|
- |
|
ajax-spell
|
ajax-spell
|
Cross-site scripting (XSS) vulnerability in ajax-spell before 1.8 allows remote attackers to inject arbitrary web script or HTML via onmouseover or other events in HTML tags.
|
NVD-CWE-Other
|
CVE-2005-2042
|
2008-09-6 05:50 |
2005-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271027
|
- |
|
xampp
|
apache_distribution
|
Directory traversal vulnerability in XAMPP before 1.4.14 allows remote attackers to inject arbitrary HTML and PHP code via lang.php.
|
NVD-CWE-Other
|
CVE-2005-2043
|
2008-09-6 05:50 |
2005-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271028
|
- |
|
adaptive_technology_resource_centre
|
atutor
|
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3 and 1.5 RC 1 allow remote attackers to inject arbitrary web script or HTML via the (1) show_course parameter to browse.php, (2) sub…
|
NVD-CWE-Other
|
CVE-2005-2044
|
2008-09-6 05:50 |
2005-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271029
|
- |
|
realnetworks
|
realone_player realplayer
|
Unknown vulnerability in RealPlayer 10 and 10.5 (6.0.12.1040-1069) and RealOne Player v1 and v2 allows remote attackers to overwrite arbitrary files or execute arbitrary ActiveX controls via a crafte…
|
NVD-CWE-Other
|
CVE-2005-2054
|
2008-09-6 05:50 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271030
|
- |
|
realnetworks
|
realone_player realplayer
|
RealPlayer 8, 10, 10.5 (6.0.12.1040-1069), and Enterprise and RealOne Player v1 and v2 allows remote malicious web server to create an arbitrary HTML file that executes an RM file via "default settin…
|
NVD-CWE-Other
|
CVE-2005-2055
|
2008-09-6 05:50 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|