|
315001
|
- |
|
dave_carrigan
|
auth_ldap
|
Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the …
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2006-0150
|
2024-02-14 10:17 |
2006-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315002
|
- |
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in WebHost Automation Ltd Helm before 3.2.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors involving the default page.
|
NVD-CWE-Other
|
CVE-2005-4747
|
2024-02-14 10:17 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315003
|
- |
|
neocrome
|
land_down_under
|
Multiple SQL injection vulnerabilities in Land Down Under (LDU) v801 and earlier allow remote attackers to execute arbitrary SQL commands via parameters including (1) the m parameter in auth.php, (2)…
|
NVD-CWE-Other
|
CVE-2005-4821
|
2024-02-14 10:17 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315004
|
- |
|
ethereal_group
|
ethereal
|
Unspecified vulnerability in the GTP dissector for Ethereal 0.9.1 to 0.10.13 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.
|
NVD-CWE-noinfo
|
CVE-2005-4585
|
2024-02-14 10:17 |
2005-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315005
|
- |
|
clearswift
|
mimesweeper_for_web
|
Clearswift MIMEsweeper For Web (a.k.a. WEBsweeper) 4.0 through 5.1 allows remote attackers to bypass filtering via a URL that does not include a .exe extension but returns an executable file.
|
NVD-CWE-Other
|
CVE-2005-4526
|
2024-02-14 10:17 |
2005-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315006
|
- |
|
adp
|
adp_forum
|
ADP Forum 2.0 through 2.0.3 stores sensitive information in plaintext files under the web document root with insufficient access control, which allows remote attackers to obtain user credentials via …
|
NVD-CWE-Other
|
CVE-2005-4249
|
2024-02-14 10:17 |
2005-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315007
|
- |
|
ethereal_group
|
ethereal
|
Stack-based buffer overflow in the dissect_ospf_v3_address_prefix function in the OSPF protocol dissector in Ethereal 0.10.12, and possibly other versions, allows remote attackers to execute arbitrar…
|
NVD-CWE-Other
|
CVE-2005-3651
|
2024-02-14 10:17 |
2005-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315008
|
- |
|
redgraphic
|
sapid_cms
|
SAPID CMS before 1.2.3.03 allows remote attackers to bypass authentication via direct requests to the usr/system files (1) insert_file.php, (2) insert_image.php, (3) insert_link.php, (4) insert_qcfil…
|
CWE-287
Improper Authentication
|
CVE-2005-4006
|
2024-02-14 10:17 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315009
|
- |
|
redgraphic
|
sapid_cms
|
Multiple unspecified vulnerabilities in SAPID CMS before 1.2.3.03, related to newly registered users and possibly authorization checks, have unknown impact and attack vectors involving (1) mvc/contro…
|
NVD-CWE-noinfo
|
CVE-2005-4007
|
2024-02-14 10:17 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315010
|
- |
|
phpx
|
phpx
|
SQL injection vulnerability in auth.inc.php in PHPX 3.5.9 and earlier allows remote attackers to execute arbitrary SQL commands, bypass authentication, and upload arbitrary PHP code via the username …
|
NVD-CWE-Other
|
CVE-2005-3968
|
2024-02-14 10:17 |
2005-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|