266161
|
- |
|
aeon
|
aeon
|
Buffer overflow in the getConfig function in Aeon 0.2a and earlier allows local users to gain privileges via a long HOME environment variable.
|
NVD-CWE-Other
|
CVE-2005-1019
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266162
|
- |
|
francisco_burzi
|
php-nuke
|
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) min parameter to the Search module, (2) the catego…
|
NVD-CWE-Other
|
CVE-2005-1023
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266163
|
- |
|
francisco_burzi
|
php-nuke
|
modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) my_headlines, (2) userinfo, or (3) search, which reveals the path in a PHP error…
|
NVD-CWE-Other
|
CVE-2005-1024
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266164
|
- |
|
francisco_burzi
|
php-nuke
|
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x through 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in the Your_Account module…
|
NVD-CWE-Other
|
CVE-2005-1027
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266165
|
- |
|
active_web_softwares
|
active_auction_house
|
Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to default.asp, (4) ite…
|
NVD-CWE-Other
|
CVE-2005-1029
|
2017-07-11 10:32 |
2005-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266166
|
- |
|
active_web_softwares
|
active_auction_house
|
Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary web script or HTML via the (1) ReturnURL, (2) password, (3) username parameter, …
|
NVD-CWE-Other
|
CVE-2005-1030
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266167
|
- |
|
e-xoops runcms
|
e-xoops runcms
|
RUNCMS 1.1A, and possibly other products based on e-Xoops (exoops), when "Allow custom avatar upload" is enabled, does not properly verify uploaded files, which allows remote attackers to upload arbi…
|
NVD-CWE-Other
|
CVE-2005-1031
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266168
|
- |
|
netwin
|
surgeftp
|
SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command.
|
NVD-CWE-Other
|
CVE-2005-1034
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266169
|
- |
|
centrinity
|
centrinity_firstclass_desktop_client
|
OpenText FirstClass 8.0 client does not properly sanitize strings before passing them to the Windows ShellExecute API, which allows remote attackers to execute arbitrary commands via a UNC path in a …
|
NVD-CWE-Other
|
CVE-2005-1045
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266170
|
- |
|
postnuke_software_foundation
|
postnuke
|
SQL injection vulnerability in modules.php in PostNuke 0.760 RC3 allows remote attackers to execute arbitrary SQL statements via the sid parameter. NOTE: the vendor reports that they could not repro…
|
NVD-CWE-Other
|
CVE-2005-1048
|
2017-07-11 10:32 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|