273801
|
5.0 |
MEDIUM
|
acnews
|
acnews
|
ACNews stores the database in a file under the web document root with a db.inc extension and insufficient access control, which allows remote attackers to obtain sensitive information such as the ful…
|
NVD-CWE-Other
|
CVE-2005-2677
|
2008-09-6 05:52 |
2005-08-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273802
|
10.0 |
HIGH
|
sysinternals
|
process_explorer
|
Buffer overflow in Sysinternals Process Explorer 9.23, and other versions before 9.25, allows local users to execute arbitrary code via a long CompanyName field in the VersionInfo information in a ru…
|
NVD-CWE-Other
|
CVE-2005-2679
|
2008-09-6 05:52 |
2005-08-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273803
|
7.5 |
HIGH
|
-
|
-
|
nquser.php in Virtual Edge Netquery 3.11 allows remote attackers to execute arbitrary commands via shell metacharacters in the host parameter to a dig query.
|
NVD-CWE-Other
|
CVE-2005-2684
|
2008-09-6 05:52 |
2005-08-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273804
|
7.5 |
HIGH
|
savewebportal
|
savewebportal
|
SaveWebPortal 3.4 allows remote attackers to execute arbitrary PHP code via a direct request to admin/PhpMyExplorer/editerfichier.php, then editing the desired file to contain the PHP code, as demons…
|
NVD-CWE-Other
|
CVE-2005-2685
|
2008-09-6 05:52 |
2005-08-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273805
|
7.5 |
HIGH
|
savewebportal
|
savewebportal
|
Directory traversal vulnerability in SaveWebPortal 3.4 allows remote attackers to include arbitrary files and execute arbitrary local PHP programs via ".." sequences in the (1) SITE_Path parameter to…
|
NVD-CWE-Other
|
CVE-2005-2686
|
2008-09-6 05:52 |
2005-08-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273806
|
4.3 |
MEDIUM
|
savewebportal
|
savewebportal
|
Multiple cross-site scripting (XSS) vulnerabilities in SaveWebPortal 3.4 allow remote attackers to inject arbitrary web script or HTML via a large number of parameters to (1) footer.php, (2) header.p…
|
NVD-CWE-Other
|
CVE-2005-2688
|
2008-09-6 05:52 |
2005-08-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273807
|
2.6 |
LOW
|
postnuke_software_foundation
|
postnuke
|
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote attackers to inject arbitrary web script or HTML via (1) the moderate parameter to the Comments module or (2) …
|
NVD-CWE-Other
|
CVE-2005-2689
|
2008-09-6 05:52 |
2005-08-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273808
|
7.5 |
HIGH
|
postnuke_software_foundation
|
postnuke
|
SQL injection vulnerability in the Downloads module in PostNuke 0.760-RC4b allows PostNuke administrators to execute arbitrary SQL commands via the show parameter to dl-viewdownload.php.
|
NVD-CWE-Other
|
CVE-2005-2690
|
2008-09-6 05:52 |
2005-08-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273809
|
7.5 |
HIGH
|
runcms
|
runcms
|
includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote attackers to overwrite arbitrary variables, possibly allowing …
|
NVD-CWE-Other
|
CVE-2005-2691
|
2008-09-6 05:52 |
2005-08-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273810
|
7.5 |
HIGH
|
runcms
|
runcms
|
Multiple SQL injection vulnerabilities in RunCMS 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) addquery and (2) subquery parameters to the newbb plus module, th…
|
NVD-CWE-Other
|
CVE-2005-2692
|
2008-09-6 05:52 |
2005-08-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273811
|
10.0 |
HIGH
|
symantec_veritas
|
netbackup_data_and_business_center netbackup_enterprise_server_client
|
Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Business Center 4.5FP and 4.5MP, and NetBackup Enterprise/Server/Client 5.0, 5.1, an…
|
NVD-CWE-Other
|
CVE-2005-2715
|
2008-09-6 05:52 |
2005-10-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273812
|
4.6 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
SecurityAgent in Apple Mac OS X 10.4.2, under certain circumstances, can cause the "Switch User..." button to appear even though the "Enable fast user switching" setting is disabled, which can allow …
|
NVD-CWE-Other
|
CVE-2005-2742
|
2008-09-6 05:52 |
2005-10-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273813
|
7.5 |
HIGH
|
apple
|
quicktime mac_os_x mac_os_x_server
|
The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary…
|
NVD-CWE-Other
|
CVE-2005-2743
|
2008-09-6 05:52 |
2005-10-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273814
|
5.0 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
Mail.app in Mail for Apple Mac OS X 10.3.9, when using Kerberos 5 for SMTP authentication, can include uninitialized memory in a message, which might allow remote attackers to obtain sensitive inform…
|
NVD-CWE-Other
|
CVE-2005-2745
|
2008-09-6 05:52 |
2005-10-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273815
|
5.0 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
Mail.app in Mail for Apple Mac OS X 10.3.9 and 10.4.2 includes message contents when using auto-reply rules, which could cause Mail.app to include decrypted message contents for encrypted messages.
|
NVD-CWE-Other
|
CVE-2005-2746
|
2008-09-6 05:52 |
2005-10-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273816
|
2.1 |
LOW
|
apple
|
mac_os_x mac_os_x_server
|
The malloc function in the libSystem library in Apple Mac OS X 10.3.9 and 10.4.2 allows local users to overwrite arbitrary files by setting the MallocLogFile environment variable to the target file b…
|
NVD-CWE-Other
|
CVE-2005-2748
|
2008-09-6 05:52 |
2005-10-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273817
|
4.3 |
MEDIUM
|
phpgroupware
|
phpgroupware
|
Cross-site scripting (XSS) vulnerability in phpGroupWare 0.9.16.000 allows administrators to inject arbitrary web script or HTML by modifying the main screen message.
|
NVD-CWE-Other
|
CVE-2005-2761
|
2008-09-6 05:52 |
2005-09-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273818
|
2.1 |
LOW
|
avaya
|
vpnremote
|
Avaya VPNRemote before 4.2.33 stores credentials in cleartext in process memory, which allows attackers to obtain the VPN user's credentials.
|
NVD-CWE-Other
|
CVE-2005-2762
|
2008-09-6 05:52 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273819
|
2.1 |
LOW
|
microsoft
|
windows_2003_server windows_xp
|
The user interface in the Windows Firewall does not properly display certain malformed entries in the Windows Registry, which makes it easier for attackers with administrator privileges to hide activ…
|
NVD-CWE-Other
|
CVE-2005-2765
|
2008-09-6 05:52 |
2005-09-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273820
|
7.5 |
HIGH
|
wrq
|
wrq_reflection_for_secure_it_windows_server
|
WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) does not properly handle when the Windows Administrator or Guest accounts are renamed after SSH key authenticat…
|
NVD-CWE-Other
|
CVE-2005-2770
|
2008-09-6 05:52 |
2005-09-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273821
|
10.0 |
HIGH
|
f-secure wrq
|
f-secure_ssh_server wrq_reflection_for_secure_it_windows_server
|
WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) processes access and deny lists in a case-sensitive manner, when previous versions were case-insensitive, which…
|
NVD-CWE-Other
|
CVE-2005-2771
|
2008-09-6 05:52 |
2005-09-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273822
|
7.5 |
HIGH
|
linksys
|
wrt54g
|
Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote attackers to execute arbitrary code via a long HTTP POST request.
|
NVD-CWE-Other
|
CVE-2005-2799
|
2008-09-6 05:52 |
2005-09-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273823
|
7.2 |
HIGH
|
frox
|
frox
|
frox 0.7.18, when running setuid root, does not properly drop privileges when reading a configuration file, which allows local users to read portions of arbitrary files via the -f command line option.
|
NVD-CWE-Other
|
CVE-2005-2807
|
2008-09-6 05:52 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273824
|
7.5 |
HIGH
|
frox
|
frox
|
frox 0.7.16 and 0.7.17 does not properly parse certain Deny ACLs, which might allow attackers to bypass intended restrictions and access blocked hosts.
|
NVD-CWE-Other
|
CVE-2005-2808
|
2008-09-6 05:52 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273825
|
2.1 |
LOW
|
silc
|
secure_internet_live_conferencing
|
silc daemon (silcd.c) in Secure Internet Live Conferencing (SILC) 1.0 and earlier allows local users to overwrite arbitrary files via a symlink attack on the silcd.[PID].stats temporary file.
|
NVD-CWE-Other
|
CVE-2005-2809
|
2008-09-6 05:52 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273826
|
4.6 |
MEDIUM
|
net-snmp
|
net-snmp
|
Untrusted search path vulnerability in Net-SNMP 5.2.1.2 and earlier, on Gentoo Linux, installs certain Perl modules with an insecure DT_RPATH, which could allow local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-2811
|
2008-09-6 05:52 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273827
|
7.5 |
HIGH
|
man2web
|
man2web
|
man2web allows remote attackers to execute arbitrary commands via -P arguments.
|
NVD-CWE-Other
|
CVE-2005-2812
|
2008-09-6 05:52 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273828
|
4.3 |
MEDIUM
|
phorum
|
phorum
|
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 5.0.17a and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to register.php or (2) a…
|
NVD-CWE-Other
|
CVE-2005-2836
|
2008-09-6 05:52 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273829
|
4.3 |
MEDIUM
|
maxdev
|
md-pro
|
Multiple cross-site scripting (XSS) vulnerabilities in MAXdev MD-Pro 1.0.72 allow remote attackers to inject arbitrary web script or HTML via (1) dl-search.php or (2) wl-search.php.
|
NVD-CWE-Other
|
CVE-2005-2839
|
2008-09-6 05:52 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273830
|
5.0 |
MEDIUM
|
whitsoft_development
|
slimftpd
|
SlimFTPd 3.17 allows remote attackers to cause a denial of service (crash) via certain (1) USER and (2) PASS commands, possibly due to a buffer overflow or off-by-one error.
|
NVD-CWE-Other
|
CVE-2005-2850
|
2008-09-6 05:52 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273831
|
2.1 |
LOW
|
smb4k
|
smb4k
|
smb4k 0.4 and other versions before 0.6.3 allows local users to read sensitive files via a symlink attack on the (1) smb4k.tmp or (2) sudoers temporary files.
|
NVD-CWE-Other
|
CVE-2005-2851
|
2008-09-6 05:52 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273832
|
5.0 |
MEDIUM
|
novell
|
netware
|
Unknown vulnerability in CIFS.NLM in Novell Netware 6.5 SP2 and SP3, 5.1, and 6.0 allows remote attackers to cause a denial of service (ABEND) via an incorrect password length, as exploited by the "w…
|
NVD-CWE-Other
|
CVE-2005-2852
|
2008-09-6 05:52 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273833
|
4.3 |
MEDIUM
|
guppy
|
guppy
|
Multiple cross-site scripting (XSS) vulnerabilities in GuppY 4.5.3a and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the pg parameter to printfaq.php, or the (2) Refe…
|
NVD-CWE-Other
|
CVE-2005-2853
|
2008-09-6 05:52 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273834
|
5.0 |
MEDIUM
|
thesitewizard.com
|
chfeedback.pl_feedback_form_perl_script
|
CRLF injection vulnerability in thesitewizard.com chfeedback.pl Feedback Form Perl Script 2.0.1 allows remote attackers to use the script as a mail relay (spam proxy) via CRLF sequences in the (1) na…
|
NVD-CWE-Other
|
CVE-2005-2854
|
2008-09-6 05:52 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273835
|
7.5 |
HIGH
|
softstack
|
free_smtp_server
|
Free SMTP Server 2.2 allows remote attackers to use the server as an open mail relay (spam proxy).
|
NVD-CWE-Other
|
CVE-2005-2857
|
2008-09-6 05:52 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273836
|
4.6 |
MEDIUM
|
savant
|
savant_webserver
|
Savant Web Server stores user credentials in plaintext in the Savant\Users registry key, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-2859
|
2008-09-6 05:52 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273837
|
4.3 |
MEDIUM
|
n-stalker
|
n-stealth
|
Cross-site scripting (XSS) vulnerability in N-Stealth Commercial Edition before 5.8.0.38 and Free Edition before 5.8.1.03 allows remote attackers to inject arbitrary web script or HTML via the Server…
|
NVD-CWE-Other
|
CVE-2005-2861
|
2008-09-6 05:52 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273838
|
4.6 |
MEDIUM
|
-
|
-
|
Mercora IMRadio 4.0.0.0 stores usernames and passwords in plaintext in the MercoraClient\Profiles registry key, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-2866
|
2008-09-6 05:52 |
2005-09-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273839
|
7.5 |
HIGH
|
bluewhalecrm
|
bluewhalecrm
|
SQL injection vulnerability in BlueWhaleCRM allows remote attackers to execute arbitrary SQL commands via the Account ID field.
|
NVD-CWE-Other
|
CVE-2005-2867
|
2008-09-6 05:52 |
2005-09-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273840
|
4.3 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php…
|
NVD-CWE-Other
|
CVE-2005-2869
|
2008-09-6 05:52 |
2005-09-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273841
|
7.5 |
HIGH
|
sun
|
solaris
|
Unknown vulnerability in the net-svc script on Solaris 10 allows remote authenticated users to execute arbitrary code on a DHCP client via certain DHCP responses.
|
NVD-CWE-Other
|
CVE-2005-2870
|
2008-09-6 05:52 |
2005-09-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273842
|
7.5 |
HIGH
|
py2play
|
py2play
|
Py2Play allows remote attackers to execute arbitrary Python code via pickled objects, which Py2Play unpickles and executes.
|
NVD-CWE-Other
|
CVE-2005-2875
|
2008-09-6 05:52 |
2005-09-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273843
|
5.0 |
MEDIUM
|
linksys
|
wrt54g
|
Linksys WRT54G router allows remote attackers to cause a denial of service (CPU consumption and server hang) via an HTTP POST request with a negative Content-Length value.
|
NVD-CWE-Other
|
CVE-2005-2912
|
2008-09-6 05:52 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273844
|
7.5 |
HIGH
|
linksys
|
wrt54g
|
ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions, does not use an authentication initialization function, which allows remote a…
|
NVD-CWE-Other
|
CVE-2005-2914
|
2008-09-6 05:52 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273845
|
5.0 |
MEDIUM
|
linksys
|
wrt54g
|
ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions, uses weak encryption (XOR encoding with a fixed byte mask) for configuration …
|
NVD-CWE-Other
|
CVE-2005-2915
|
2008-09-6 05:52 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273846
|
5.0 |
MEDIUM
|
linksys
|
wrt54g
|
Linksys WRT54G 3.01.03, 3.03.6, 4.00.7, and possibly other versions before 4.20.7, does not verify user authentication until after an HTTP POST request has been processed, which allows remote attacke…
|
NVD-CWE-Other
|
CVE-2005-2916
|
2008-09-6 05:52 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273847
|
5.0 |
MEDIUM
|
microsoft
|
frontpage
|
Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page.
|
NVD-CWE-Other
|
CVE-2005-2143
|
2008-09-6 05:51 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273848
|
2.1 |
LOW
|
prevx
|
prevx_pro_2005
|
Prevx Pro 2005 1.0 allows local users to bypass file protection and modify files by using MapViewOfFile to perform memory mapping on the file.
|
NVD-CWE-Other
|
CVE-2005-2144
|
2008-09-6 05:51 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273849
|
4.6 |
MEDIUM
|
prevx
|
prevx_pro_2005
|
The kernel driver in Prevx Pro 2005 1.0 does not verify the source of certain messages, which allows local users to bypass protection by sending certain messages to the driver, as demonstrated by sen…
|
NVD-CWE-Other
|
CVE-2005-2145
|
2008-09-6 05:51 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
273850
|
4.6 |
MEDIUM
|
ssh
|
tectia_server
|
SSH Tectia Server 4.3.1 and earlier, and SSH Secure Shell for Windows Servers, uses insecure permissions when generating the Secure Shell host identification key, which allows local users to access t…
|
NVD-CWE-Other
|
CVE-2005-2146
|
2008-09-6 05:51 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|