266131
|
- |
|
-
|
-
|
SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary SQL via the ne…
|
NVD-CWE-Other
|
CVE-2005-3201
|
2017-07-11 10:33 |
2005-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266132
|
- |
|
oracle
|
html_db
|
Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 allow remote attackers to inject arbitrary web script or HTML, and subsequently execute SQL statements…
|
NVD-CWE-Other
|
CVE-2005-3202
|
2017-07-11 10:33 |
2005-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266133
|
- |
|
oracle
|
html_db
|
The manual installation of Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 stores the SYS password in install.lst in plaintext, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-3203
|
2017-07-11 10:33 |
2005-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266134
|
- |
|
oracle
|
application_server oracle9i
|
Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP request.
|
NVD-CWE-Other
|
CVE-2005-3204
|
2017-07-11 10:33 |
2005-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266135
|
- |
|
oracle
|
database_server
|
Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to inject arbitrary web script or HTML via script in the "set ma…
|
CWE-79
Cross-site Scripting
|
CVE-2005-3205
|
2017-07-11 10:33 |
2005-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266136
|
- |
|
oracle
|
database_server
|
iSQL*Plus (isqlplus) for Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to cause a denial of service (TNS listener stop) via an HTTP request with an sid parameter that contains a …
|
NVD-CWE-Other
|
CVE-2005-3206
|
2017-07-11 10:33 |
2005-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266137
|
- |
|
oracle
|
forms
|
The forms servlet (f90servlet) in Oracle Forms 4.5.10.22 allows remote attackers to cause a denial of service (TNS listener stop) via a userid parameter that contains a STOP command.
|
NVD-CWE-Other
|
CVE-2005-3207
|
2017-07-11 10:33 |
2005-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266138
|
- |
|
aenovo
|
aenovo aenovoshop aenovowysi
|
Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execute arbitrary SQL code via (a) the password parameter in control.asp, and (b) the…
|
NVD-CWE-Other
|
CVE-2005-3208
|
2017-07-11 10:33 |
2005-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266139
|
- |
|
aenovo
|
aenovo aenovoshop aenovowysi
|
Aenovo products (1) aeNovo, (2) aeNovoShop, and (3) aeNovoWYSI store password information in plaintext in the (a) control, (b) content, and (c) page tables, which allows attackers with database acces…
|
NVD-CWE-Other
|
CVE-2005-3209
|
2017-07-11 10:33 |
2005-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266140
|
- |
|
cynox
|
cyphor
|
Multiple SQL injection vulnerabilities in Cyphor 0.19 allow remote attackers to execute arbitrary SQL and obtain administrative access via (1) the fid parameter of newmsg.php, which can enable XSS at…
|
NVD-CWE-Other
|
CVE-2005-3236
|
2017-07-11 10:33 |
2005-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|