264631
|
- |
|
web4future
|
portal_solutions
|
Directory traversal vulnerability in arhiva.php in Web4Future Portal Solutions News Portal allows remote attackers to read arbitrary files via the dir parameter.
|
NVD-CWE-Other
|
CVE-2005-4039
|
2017-07-20 10:29 |
2005-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264632
|
- |
|
tawbaware
|
filelister
|
SQL injection vulnerability in FileLister 0.51 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameters, possibly the searchwhat parameter to definesearch.jsp.
|
CWE-89
SQL Injection
|
CVE-2005-4040
|
2017-07-20 10:29 |
2005-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264633
|
- |
|
hobosworld
|
hobsr
|
SQL injection vulnerability in view.php in Hobosworld HobSR 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) arrange and (2) p parameters.
|
NVD-CWE-Other
|
CVE-2005-4043
|
2017-07-20 10:29 |
2005-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264634
|
- |
|
mr._cgi_guy
|
amazon_search_directory
|
Cross-site scripting (XSS) vulnerability in search.cgi in Amazon Search Directory 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly th…
|
NVD-CWE-Other
|
CVE-2005-4044
|
2017-07-20 10:29 |
2005-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264635
|
- |
|
cars_portal
|
cars_portal
|
SQL injection vulnerability in index.php in Cars Portal 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) page and (2) car parameters.
|
NVD-CWE-Other
|
CVE-2005-4055
|
2017-07-20 10:29 |
2005-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264636
|
- |
|
saralblog
|
saralblog
|
SQL injection vulnerability in saralblog 1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to viewprofile.php.
|
CWE-89
SQL Injection
|
CVE-2005-4058
|
2017-07-20 10:29 |
2005-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264637
|
- |
|
rainworx
|
rwauction_pro
|
Cross-site scripting (XSS) vulnerability in search.asp in rwAuction Pro 4.0 and 5.0 allows remote attackers to inject arbitrary web script or HTML via the searchtxt parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2005-4060
|
2017-07-20 10:29 |
2005-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264638
|
- |
|
christian_ghisler
|
total_commander
|
Total Commander 6.53 uses weak encryption to store FTP usernames and passwords in WCX_FTP.INI, which allows local users to decrypt the passwords and gain access to FTP servers, as possibly demonstrat…
|
CWE-310
Cryptographic Issues
|
CVE-2005-4066
|
2017-07-20 10:29 |
2005-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264639
|
- |
|
cfmagic
|
magic_forum_personal
|
Multiple SQL injection vulnerabilities in CFMagic Magic Forum Personal 2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ForumID parameter in view_forum.cfm, and (2…
|
CWE-89
SQL Injection
|
CVE-2005-4071
|
2017-07-20 10:29 |
2005-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264640
|
- |
|
mycfnuke
|
cf_nuke
|
Directory traversal vulnerability in index.cfm in CF_Nuke 4.6 and earlier, when Sandbox Security is disabled, allows remote attackers to include arbitrary local .cfm files via a .. (dot dot) in the (…
|
NVD-CWE-Other
|
CVE-2005-4074
|
2017-07-20 10:29 |
2005-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|