270381
|
- |
|
adaptive_technology_resource_centre
|
atutor
|
registration.PHP in ATutor 1.5.1 pl2 allows remote attackers to execute arbitrary SQL commands via an e-mail address that ends in a NULL character, which bypasses the PHP regular expression check. NO…
|
NVD-CWE-Other
|
CVE-2005-4155
|
2008-09-6 05:56 |
2005-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270382
|
- |
|
mambo
|
mambo_open_source_4.5
|
Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrary files and possibly cause a denial of service via a query …
|
NVD-CWE-Other
|
CVE-2005-4156
|
2008-09-6 05:56 |
2005-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270383
|
- |
|
efiction_project
|
efiction
|
Cross-site scripting (XSS) vulnerability in eFiction 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the let parameter in a viewlist action to titles.php.
|
NVD-CWE-Other
|
CVE-2005-4167
|
2008-09-6 05:56 |
2005-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270384
|
- |
|
efiction_project
|
efiction
|
Multiple SQL injection vulnerabilities in eFiction 1.0, 1.1, and 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the let parameter in a viewlist action to titles.php and (2) the …
|
NVD-CWE-Other
|
CVE-2005-4168
|
2008-09-6 05:56 |
2005-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270385
|
- |
|
efiction_project
|
efiction
|
The "Upload new image" command in the "Manage Images" eFiction 1.1, when members are allowed to upload images, allows remote attackers to execute arbitrary PHP code by uploading a filename with a .ph…
|
NVD-CWE-Other
|
CVE-2005-4171
|
2008-09-6 05:56 |
2005-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270386
|
- |
|
efiction_project
|
efiction
|
eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information via a direct request to storyblock.php without arguments, which leaks the full pathname in the resulting PHP error m…
|
NVD-CWE-Other
|
CVE-2005-4172
|
2008-09-6 05:56 |
2005-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270387
|
- |
|
efiction_project
|
efiction
|
eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information by accessing phpinfo.php, which executes the PHP phpinfo function.
|
NVD-CWE-Other
|
CVE-2005-4173
|
2008-09-6 05:56 |
2005-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270388
|
- |
|
-
|
-
|
eFiction 1.0, 1.1, and 2.0, in unspecified environments, might allow remote attackers to conduct unauthorized operations by directly accessing (1) install.php or (2) upgrade.php. NOTE: it is unclear…
|
NVD-CWE-Other
|
CVE-2005-4174
|
2008-09-6 05:56 |
2005-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270389
|
- |
|
logisphere
|
logisphere
|
Cross-site scripting (XSS) vulnerability in LogiSphere 0.9.9j allows remote attackers to inject arbitrary Javascript via the msg command. NOTE: due to lack of appropriate details by the original rese…
|
NVD-CWE-Other
|
CVE-2005-4204
|
2008-09-6 05:56 |
2005-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270390
|
- |
|
asp-dev
|
xm_forum
|
Cross-site scripting (XSS) vulnerability in forum.asp in ASP-DEV XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via the forum_title parameter. NOTE: the provenance of th…
|
NVD-CWE-Other
|
CVE-2005-4256
|
2008-09-6 05:56 |
2005-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|