270711
|
- |
|
handy_address_book
|
handy_address_book_server
|
Cross-site scripting (XSS) vulnerability in Handy Address Book Server 1.1 allows remote attackers to inject arbitrary web script or HTML via the SEARCHTEXT parameter in a demos URL.
|
NVD-CWE-Other
|
CVE-2005-3037
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270712
|
- |
|
hosting_controller
|
hosting_controller
|
Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related to "the PHP vulnerability."
|
NVD-CWE-Other
|
CVE-2005-3038
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270713
|
- |
|
mall23
|
mall23
|
SQL injection vulnerability in infopage.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idPage parameter.
|
NVD-CWE-Other
|
CVE-2005-3039
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270714
|
- |
|
tac
|
vista
|
Directory traversal vulnerability in the web interface (ISALogin.dll) for TAC Vista 4.0, and possibly other versions before 4.3, allows remote attackers to read arbitrary files via ".." sequences in …
|
NVD-CWE-Other
|
CVE-2005-3040
|
2008-09-6 05:53 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270715
|
- |
|
multitheftauto
|
multitheftauto
|
MultiTheftAuto 0.5 patch 1 and earlier does not properly verify client privileges when running command 40, which allows remote attackers to change or delete the message of the day (motd.txt).
|
NVD-CWE-Other
|
CVE-2005-3064
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270716
|
- |
|
eric_integrated_development_environment
|
eric_integrated_development_environment
|
Unspecified vulnerability in Eric Integrated Development Environment (eric3) before 3.7.2 has unknown impact and attack vectors related to a "potential security exploit."
|
NVD-CWE-Other
|
CVE-2005-3068
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270717
|
- |
|
hylafax
|
hylafax
|
xferfaxstats in HylaFax 4.2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the xferfax$$ temporary file.
|
NVD-CWE-Other
|
CVE-2005-3069
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270718
|
- |
|
hylafax
|
hylafax
|
HylaFax 4.2.1 and earlier does not create or verify ownership of the UNIX domain socket, which might allow local users to read faxes and cause a denial of service by creating the socket using the hyl…
|
NVD-CWE-Other
|
CVE-2005-3070
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270719
|
- |
|
rsyslog
|
rsyslogd
|
SQL injection vulnerability in rsyslogd in RSyslog before 1.0.1 and before 1.10.1 allows remote attackers to execute arbitrary SQL commands via crafted syslog messages.
|
NVD-CWE-Other
|
CVE-2005-3074
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270720
|
- |
|
mpc-donkey
|
zengaia
|
SQL injection vulnerability in Zengaia before 0.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-3075
|
2008-09-6 05:53 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|