|
315941
|
- |
|
calogic
|
calogic
|
PHP remote file inclusion vulnerability in CaLogic 1.2.2 allows remote attackers to execute arbitrary code via the CLPATH parameter to (1) cl_minical.php, (2) clmcpreload.php, (3) mcconfig.php, or (4…
|
NVD-CWE-Other
|
CVE-2005-2321
|
2024-02-14 10:17 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315942
|
- |
|
microsoft
|
msn_messenger_service
|
Microsoft MSN Messenger allows remote attackers to cause a denial of service via a plaintext message containing the ".pif" string, which is interpreted as a malicious file extension and causes users …
|
NVD-CWE-Other
|
CVE-2005-2225
|
2024-02-14 10:17 |
2005-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315943
|
- |
|
tonec_inc.
|
internet_download_manager
|
Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL.
|
NVD-CWE-Other
|
CVE-2005-2210
|
2024-02-14 10:17 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315944
|
- |
|
frozenplague.net
|
plague_news_system
|
SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
|
NVD-CWE-Other
|
CVE-2005-2166
|
2024-02-14 10:17 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315945
|
- |
|
frozenplague.net
|
plague_news_system
|
Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter.
|
NVD-CWE-Other
|
CVE-2005-2167
|
2024-02-14 10:17 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315946
|
- |
|
frozenplague.net
|
plague_news_system
|
delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter.
|
NVD-CWE-Other
|
CVE-2005-2168
|
2024-02-14 10:17 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315947
|
- |
|
php_fusion
|
php_fusion
|
Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.0.105 allows remote attackers to inject arbitrary web script or HTML via a news or article post, possibly involving the (1) news_body, (2) art…
|
NVD-CWE-Other
|
CVE-2005-2074
|
2024-02-14 10:17 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315948
|
- |
|
php_fusion
|
php_fusion
|
PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information…
|
NVD-CWE-Other
|
CVE-2005-2075
|
2024-02-14 10:17 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315949
|
- |
|
e107
|
e107
|
The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the eping_h…
|
NVD-CWE-Other
|
CVE-2005-1949
|
2024-02-14 10:17 |
2005-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315950
|
- |
|
vincent_hor
|
calendarix_advanced
|
Multiple SQL injection vulnerabilities in Calendarix Advanced 1.5 allow remote attackers to execute arbitrary SQL commands via the catview parameter to (1) cal_week.php, (2) cal_cat.php, or (3) cal_d…
|
NVD-CWE-Other
|
CVE-2005-1865
|
2024-02-14 10:17 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|