|
313321
|
- |
|
postnuke_software_foundation john_lim the_cacti_group mantis moodle mediabeez
|
postnuke adodb cacti mantis moodle mediabeez
|
The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8…
|
CWE-89
SQL Injection
|
CVE-2006-0146
|
2024-02-14 10:17 |
2006-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313322
|
- |
|
dave_carrigan
|
auth_ldap
|
Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the …
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2006-0150
|
2024-02-14 10:17 |
2006-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313323
|
- |
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in WebHost Automation Ltd Helm before 3.2.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors involving the default page.
|
NVD-CWE-Other
|
CVE-2005-4747
|
2024-02-14 10:17 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313324
|
- |
|
neocrome
|
land_down_under
|
Multiple SQL injection vulnerabilities in Land Down Under (LDU) v801 and earlier allow remote attackers to execute arbitrary SQL commands via parameters including (1) the m parameter in auth.php, (2)…
|
NVD-CWE-Other
|
CVE-2005-4821
|
2024-02-14 10:17 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313325
|
- |
|
ethereal_group
|
ethereal
|
Unspecified vulnerability in the GTP dissector for Ethereal 0.9.1 to 0.10.13 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.
|
NVD-CWE-noinfo
|
CVE-2005-4585
|
2024-02-14 10:17 |
2005-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313326
|
- |
|
clearswift
|
mimesweeper_for_web
|
Clearswift MIMEsweeper For Web (a.k.a. WEBsweeper) 4.0 through 5.1 allows remote attackers to bypass filtering via a URL that does not include a .exe extension but returns an executable file.
|
NVD-CWE-Other
|
CVE-2005-4526
|
2024-02-14 10:17 |
2005-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313327
|
- |
|
adp
|
adp_forum
|
ADP Forum 2.0 through 2.0.3 stores sensitive information in plaintext files under the web document root with insufficient access control, which allows remote attackers to obtain user credentials via …
|
NVD-CWE-Other
|
CVE-2005-4249
|
2024-02-14 10:17 |
2005-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313328
|
- |
|
ethereal_group
|
ethereal
|
Stack-based buffer overflow in the dissect_ospf_v3_address_prefix function in the OSPF protocol dissector in Ethereal 0.10.12, and possibly other versions, allows remote attackers to execute arbitrar…
|
NVD-CWE-Other
|
CVE-2005-3651
|
2024-02-14 10:17 |
2005-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313329
|
- |
|
redgraphic
|
sapid_cms
|
SAPID CMS before 1.2.3.03 allows remote attackers to bypass authentication via direct requests to the usr/system files (1) insert_file.php, (2) insert_image.php, (3) insert_link.php, (4) insert_qcfil…
|
CWE-287
Improper Authentication
|
CVE-2005-4006
|
2024-02-14 10:17 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313330
|
- |
|
redgraphic
|
sapid_cms
|
Multiple unspecified vulnerabilities in SAPID CMS before 1.2.3.03, related to newly registered users and possibly authorization checks, have unknown impact and attack vectors involving (1) mvc/contro…
|
NVD-CWE-noinfo
|
CVE-2005-4007
|
2024-02-14 10:17 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|