265601
|
4.3 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 7.5 allow remote attackers to inject arbitrary HTML or web script via (1) the newdownloadshowdays parameter in a NewDownloads operation…
|
NVD-CWE-Other
|
CVE-2005-0434
|
2017-07-11 10:32 |
2005-02-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265602
|
5.0 |
MEDIUM
|
awstats
|
awstats
|
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog.
|
NVD-CWE-Other
|
CVE-2005-0435
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265603
|
7.5 |
HIGH
|
awstats
|
awstats
|
Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode parameter.
|
NVD-CWE-Other
|
CVE-2005-0436
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265604
|
5.0 |
MEDIUM
|
awstats
|
awstats
|
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.
|
NVD-CWE-Other
|
CVE-2005-0438
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265605
|
7.5 |
HIGH
|
stefan_ritt
|
elog_web_logbook
|
Buffer overflow in the decode_post function in ELOG before 2.5.7 allows remote attackers to execute arbitrary code via attachments with long file names.
|
NVD-CWE-Other
|
CVE-2005-0439
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265606
|
5.0 |
MEDIUM
|
devellion
|
cubecart
|
Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter.
|
NVD-CWE-Other
|
CVE-2005-0442
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265607
|
4.3 |
MEDIUM
|
devellion
|
cubecart
|
index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parameter, which echoes th…
|
NVD-CWE-Other
|
CVE-2005-0443
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265608
|
4.3 |
MEDIUM
|
open_webmail
|
open_webmail
|
Cross-site scripting (XSS) vulnerability in Open WebMail 2.x allows remote attackers to inject arbitrary HTML or web script via the domain name parameter (logindomain) in the login page.
|
NVD-CWE-Other
|
CVE-2005-0445
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265609
|
7.5 |
HIGH
|
putty
|
putty
|
Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sit…
|
NVD-CWE-Other
|
CVE-2005-0467
|
2017-07-11 10:32 |
2005-02-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265610
|
5.0 |
MEDIUM
|
wpa_supplicant gentoo suse
|
wpa_supplicant linux suse_linux
|
Buffer overflow in wpa_supplicant before 0.2.7 allows remote attackers to cause a denial of service (segmentation fault) via invalid EAPOL-Key packet data.
|
NVD-CWE-Other
|
CVE-2005-0470
|
2017-07-11 10:32 |
2005-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265611
|
5.0 |
MEDIUM
|
sun
|
jdk jre
|
Sun Java JRE 1.1.x through 1.4.x writes temporary files with long filenames that become predictable on a file system that uses 8.3 style short names, which allows remote attackers to write arbitrary …
|
NVD-CWE-Other
|
CVE-2005-0471
|
2017-07-11 10:32 |
2005-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265612
|
6.4 |
MEDIUM
|
webcalendar
|
webcalendar
|
SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL commands via an encoded webcalendar_session cookie.
|
NVD-CWE-Other
|
CVE-2005-0474
|
2017-07-11 10:32 |
2005-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265613
|
6.4 |
MEDIUM
|
php_arena
|
pafaq
|
SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1) offset, (2) limit, (3) order, or (4) orderby parameter to qu…
|
NVD-CWE-Other
|
CVE-2005-0475
|
2017-07-11 10:32 |
2005-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265614
|
4.3 |
MEDIUM
|
hpm_guestbook.cgi
|
hpm_guestbook.cgi
|
Cross-site scripting (XSS) vulnerability in hpm_guestbook.cgi allows remote attackers to inject arbitrary web script or HTML by posting a message.
|
NVD-CWE-Other
|
CVE-2005-0476
|
2017-07-11 10:32 |
2005-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265615
|
4.3 |
MEDIUM
|
invision_power_services
|
invision_power_board
|
Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script via (1) a signature file or (2) a message post con…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2005-0477
|
2017-07-11 10:32 |
2005-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265616
|
5.0 |
MEDIUM
|
trackercam
|
trackercam
|
Multiple buffer overflows in TrackerCam 5.12 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP request with a long User-Agent header …
|
NVD-CWE-Other
|
CVE-2005-0478
|
2017-07-11 10:32 |
2005-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265617
|
5.0 |
MEDIUM
|
trackercam
|
trackercam
|
Directory traversal vulnerability in ComGetLogFile.php3 for TrackerCam 5.12 and earlier allows remote attackers to read arbitrary files via ".." sequences and (1) "/" slash), (2) "\" (backslash), or …
|
NVD-CWE-Other
|
CVE-2005-0479
|
2017-07-11 10:32 |
2005-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265618
|
4.3 |
MEDIUM
|
trackercam
|
trackercam
|
Cross-site scripting (XSS) vulnerability in TrackerCam 5.12 and earlier allows remote attackers to inject arbitrary HTML or web script via the login request, which is recorded in a log file but not p…
|
NVD-CWE-Other
|
CVE-2005-0480
|
2017-07-11 10:32 |
2005-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265619
|
5.0 |
MEDIUM
|
trackercam
|
trackercam
|
TrackerCam 5.12 and earlier allows remote attackers to read log files via the fn parameter in a direct request to the ComGetLogFile.php3 script.
|
NVD-CWE-Other
|
CVE-2005-0481
|
2017-07-11 10:32 |
2005-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265620
|
5.0 |
MEDIUM
|
trackercam
|
trackercam
|
TrackerCam 5.12 and earlier allows remote attackers to cause a denial of service (crash) via (1) a large number of connections with a negative Content-Length header, possibly triggering an integer si…
|
NVD-CWE-Other
|
CVE-2005-0482
|
2017-07-11 10:32 |
2005-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265621
|
5.0 |
MEDIUM
|
glftpd
|
glftpd
|
Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files…
|
NVD-CWE-Other
|
CVE-2005-0483
|
2017-07-11 10:32 |
2005-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265622
|
6.8 |
MEDIUM
|
phparena
|
panews
|
Cross-site scripting (XSS) vulnerability in comment.php for paNews 2.0b4 for PHP Arena allows remote attackers to inject arbitrary HTML and web script via the showpost parameter.
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2005-0485
|
2017-07-11 10:32 |
2005-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265623
|
6.8 |
MEDIUM
|
kayako
|
esupport
|
Cross-site scripting (XSS) vulnerability in index.php for Kayako ESupport 2.3.1, and possibly other versions, allows remote attackers to inject arbitrary HTML and web script via the nav parameter.
|
NVD-CWE-Other
|
CVE-2005-0487
|
2017-07-11 10:32 |
2005-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265624
|
10.0 |
HIGH
|
knox_software
|
arkeia_server_backup
|
Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a long type 77 request.
|
NVD-CWE-Other
|
CVE-2005-0491
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265625
|
2.6 |
LOW
|
adobe
|
acrobat_reader
|
Adobe Acrobat Reader 6.0.3 and 7.0.0 allows remote attackers to cause a denial of service (application crash) via a PDF file that contains a negative Count value in the root page node.
|
CWE-20
不適切な入力確認
|
CVE-2005-0492
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265626
|
7.5 |
HIGH
|
thomson
|
thomson_cable_modem
|
The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows …
|
NVD-CWE-Other
|
CVE-2005-0494
|
2017-07-11 10:32 |
2005-02-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265627
|
4.3 |
MEDIUM
|
zeroboard
|
zeroboard
|
Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote attackers to inject arbitrary web script or HTML via the (1) sn1, (2) year, or (3) page parameter to zboard.php or (4) filename to …
|
NVD-CWE-Other
|
CVE-2005-0495
|
2017-07-11 10:32 |
2005-02-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265628
|
7.2 |
HIGH
|
adp
|
elite_system_max_9000
|
ADP Elite System Max 9000 allows remote authenticated users to gain privileges by uploading a .profile that sets the ADPROOT environment variable to the root directory.
|
NVD-CWE-Other
|
CVE-2005-0497
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265629
|
7.5 |
HIGH
|
gigafast_ethernet
|
gigafast_router
|
Gigafast router (aka CompUSA router) allows remote attackers to gain sensitive information and bypass the login page via a direct request to backup.cfg, which reveals the administrator password in pl…
|
NVD-CWE-Other
|
CVE-2005-0498
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265630
|
5.0 |
MEDIUM
|
gigafast_ethernet
|
gigafast_router
|
Gigafast router (aka CompUSA router) with the DNS proxy option enabled allows remote attackers to cause a denial of service via malformed DNS queries.
|
NVD-CWE-Other
|
CVE-2005-0499
|
2017-07-11 10:32 |
2005-02-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265631
|
5.0 |
MEDIUM
|
xinkaa_web_station
|
xinkaa_web_station
|
Directory traversal vulnerability in Xinkaa 1.0.3 and earlier allows remote attackers to read arbitrary files via (1) ../ and (2) ..\ characters in an HTTP request.
|
NVD-CWE-Other
|
CVE-2005-0502
|
2017-07-11 10:32 |
2005-02-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265632
|
10.0 |
HIGH
|
argosoft
|
ftp_server
|
ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK file onto the server…
|
NVD-CWE-Other
|
CVE-2005-0519
|
2017-07-11 10:32 |
2005-02-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265633
|
10.0 |
HIGH
|
argosoft
|
ftp_server
|
ArGoSoft FTP Server before 1.4.2.8 allows remote attackers to read arbitrary files via shortcut (.LNK) files in the SITE COPY command, a different vulnerability than CVE-2005-0519.
|
NVD-CWE-Other
|
CVE-2005-0520
|
2017-07-11 10:32 |
2005-02-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265634
|
4.3 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in s…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2005-0543
|
2017-07-11 10:32 |
2005-02-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265635
|
7.5 |
HIGH
|
phpwebsite
|
phpwebsite
|
The Announce module in phpWebSite 0.10.0 and earlier allows remote attackers to execute arbitrary PHP code by setting the Image field to reference a PHP file whose name contains a .gif.php extension.
|
NVD-CWE-Other
|
CVE-2005-0565
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265636
|
7.5 |
HIGH
|
kmint21_software
|
golden_ftp_server
|
Buffer overflow in Golden FTP Server Pro (goldenftpd) 2.x allows remote attackers to execute arbitrary code via a long RNTO command.
|
NVD-CWE-Other
|
CVE-2005-0566
|
2017-07-11 10:32 |
2005-01-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265637
|
7.5 |
HIGH
|
phpmyadmin
|
phpmyadmin
|
Multiple PHP remote file inclusion vulnerabilities in phpMyAdmin 2.6.1 allow remote attackers to execute arbitrary PHP code by modifying the (1) theme parameter to phpmyadmin.css.php or (2) cfg[Serve…
|
NVD-CWE-Other
|
CVE-2005-0567
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265638
|
7.5 |
HIGH
|
punbb
|
punbb
|
Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) language parameter to register.php, (2) change email feature in profile.php,…
|
NVD-CWE-Other
|
CVE-2005-0569
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265639
|
5.0 |
MEDIUM
|
punbb
|
punbb
|
profile.php in PunBB 1.2.1 allows remote attackers to cause a denial of service (account lockout) by setting the user's password to NULL.
|
NVD-CWE-Other
|
CVE-2005-0570
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265640
|
5.0 |
MEDIUM
|
punbb
|
punbb
|
admin_loader.php in PunBB 1.2.1 allows remote attackers to read arbitrary files via the plugin parameter.
|
NVD-CWE-Other
|
CVE-2005-0571
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265641
|
5.0 |
MEDIUM
|
cisco
|
application_and_content_networking_software
|
Cisco devices running Application and Content Networking System (ACNS) 4.x, 5.0, or 5.1 before 5.1.11.6 allow remote attackers to cause a denial of service (CPU consumption) via malformed IP packets.
|
NVD-CWE-Other
|
CVE-2005-0599
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265642
|
7.5 |
HIGH
|
cisco
|
application_and_content_networking_software
|
Cisco devices running Application and Content Networking System (ACNS) 4.x, 5.0, 5.1, or 5.2 use a default password when the setup dialog has not been run, which allows remote attackers to gain acces…
|
NVD-CWE-Other
|
CVE-2005-0601
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265643
|
4.3 |
MEDIUM
|
devellion
|
cubecart
|
Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files, allows remote attackers to inject arbitrary HTML or web script via the (1…
|
NVD-CWE-Other
|
CVE-2005-0606
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265644
|
5.0 |
MEDIUM
|
devellion
|
cubecart
|
CubeCart 2.0.0 through 2.0.5 allows remote attackers to determine the full path of the server via direct calls without parameters to (1) information.php, (2) language.php, (3) list_docs.php, (4) popu…
|
NVD-CWE-Other
|
CVE-2005-0607
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265645
|
2.1 |
LOW
|
debian
|
reportbug
|
reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords.
|
NVD-CWE-Other
|
CVE-2005-0624
|
2017-07-11 10:32 |
2005-02-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265646
|
2.1 |
LOW
|
debian
|
reportbug
|
reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser and smtppasswd.
|
NVD-CWE-Other
|
CVE-2005-0625
|
2017-07-11 10:32 |
2005-02-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265647
|
4.3 |
MEDIUM
|
427bb
|
fourtwosevenbb
|
Multiple cross-site scripting (XSS) vulnerabilities in profile.php in 427BB 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) Avatar parameters.
|
NVD-CWE-Other
|
CVE-2005-0629
|
2017-07-11 10:32 |
2005-03-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265648
|
2.1 |
LOW
|
pblang
|
pblang
|
sendpm.php in PBLang 4.63 allows remote authenticated users to read arbitrary files via a full pathname in the orig parameter.
|
NVD-CWE-Other
|
CVE-2005-0630
|
2017-07-11 10:32 |
2005-03-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265649
|
2.1 |
LOW
|
pblang
|
pblang
|
delpm.php in PBLang 4.63 allows remote authenticated users to delete arbitrary PM files by modifying the "id" and "a" parameters.
|
NVD-CWE-Other
|
CVE-2005-0631
|
2017-07-11 10:32 |
2005-03-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
265650
|
5.0 |
MEDIUM
|
openbsd
|
openbsd
|
The copy functions in locore.s such as copyout in OpenBSD 3.5 and 3.6, and possibly other BSD based operating systems, may allow attackers to exceed certain address boundaries and modify kernel memor…
|
NVD-CWE-Other
|
CVE-2005-0637
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|