269041
|
- |
|
cj_design
|
cj_tag_board
|
Multiple cross-site scripting (XSS) vulnerabilities in details.php in CjTagBoard 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date, (2) time, (3) name, (4) ip, (5) ag…
|
NVD-CWE-Other
|
CVE-2005-2899
|
2016-10-18 12:31 |
2005-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269042
|
- |
|
cj_desing
|
cjlinkout
|
Cross-site scripting (XSS) vulnerability in top.php in CjLinkOut 1.0 allows remote attackers to inject arbitrary web script or HTML via the 123 parameter.
|
NVD-CWE-Other
|
CVE-2005-2900
|
2016-10-18 12:31 |
2005-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269043
|
- |
|
cj_desing
|
cjweb2mail
|
Multiple Cross-site scripting (XSS) vulnerabilities in CjWeb2Mail 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) message, or (3) ip parameter to thankyou.php …
|
NVD-CWE-Other
|
CVE-2005-2901
|
2016-10-18 12:31 |
2005-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269044
|
- |
|
zebedee
|
zebedee
|
Zebedee 2.4.1, when "allowed redirection port" is not set, allows remote attackers to cause a denial of service (application crash) via a zero in the port number of the protocol option header, which …
|
NVD-CWE-Other
|
CVE-2005-2904
|
2016-10-18 12:31 |
2005-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269045
|
- |
|
gtkdiskfree
|
gtkdiskfree
|
The open_cmd_tube function in mount.c for gtkdiskfree 1.9.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the gtkdiskfree temporary file.
|
NVD-CWE-Other
|
CVE-2005-2918
|
2016-10-18 12:31 |
2005-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269046
|
- |
|
arc
|
arc
|
arc 5.21j and earlier create temporary files with world-readable permissions, which allows local users to read sensitive information from files created by (1) arc (arc.c) or (2) marc (marc.c).
|
NVD-CWE-Other
|
CVE-2005-2945
|
2016-10-18 12:31 |
2005-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269047
|
- |
|
-
|
-
|
KillProcess 2.20 and earlier allows local users to bypass kill list restrictions by launching multiple processes at the same time, which are not all killed by KillProcess.
|
NVD-CWE-Other
|
CVE-2005-2948
|
2016-10-18 12:31 |
2005-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269048
|
- |
|
mark_d._roth
|
pam_per_user
|
pam_per_user before 0.4 does not verify if the user name changes between authentication attempts and uses the same subrequest handle, which allows remote attackers or local users to login as other us…
|
NVD-CWE-Other
|
CVE-2005-2949
|
2016-10-18 12:31 |
2005-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269049
|
- |
|
miva
|
miva_merchant
|
Cross-site scripting (XSS) vulnerability in merchant.mvc in MIVA Merchant 5 allows remote attackers to inject arbitrary web script or HTML via the Customer_Login parameter.
|
NVD-CWE-Other
|
CVE-2005-2953
|
2016-10-18 12:31 |
2005-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269050
|
- |
|
adaptive_technology_resource_centre
|
atutor
|
config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which allows authenticated administrators or educators to execute a…
|
NVD-CWE-Other
|
CVE-2005-2955
|
2016-10-18 12:31 |
2005-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|