|
349651
|
4.3 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in formmail.php in Woltlab Burning Board Lite 1.0.0, 1.0.1e, and possibly other versions, allows remote attackers to inject arbitrary web script and HTML via …
|
NVD-CWE-Other
|
CVE-2005-0216
|
2017-07-12 10:29 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349652
|
7.5 |
HIGH
|
digipen_institute_of_technology
|
bontago
|
Buffer overflow in Bontago 1.1 and earlier allows remote attackers to execute arbitrary code via a long nickname.
|
NVD-CWE-Other
|
CVE-2005-0501
|
2017-07-12 10:29 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349653
|
7.5 |
HIGH
|
working_resources_inc.
|
badblue
|
Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand parameter.
|
NVD-CWE-Other
|
CVE-2005-0595
|
2017-07-12 10:29 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349654
|
6.4 |
MEDIUM
|
yager_development
|
yager_game
|
Multiple buffer overflows in Yager 5.24 and earlier allow remote attackers to execute arbitrary code via (1) a crafted nickname or (2) a packet with a large amount of data.
|
NVD-CWE-Other
|
CVE-2005-1163
|
2017-07-12 10:29 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349655
|
7.5 |
HIGH
|
belkin
|
belkin_54g_wireless_router
|
Belkin 54g wireless routers do not properly set an administrative password, which allows remote attackers to gain access via the (1) Telnet or (2) web administration interfaces.
|
NVD-CWE-Other
|
CVE-2005-2374
|
2017-07-12 10:29 |
2005-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349656
|
5.1 |
MEDIUM
|
belkin
|
f5d7230-4 f5d7232-4
|
Belkin F5D7232-4 and F5D7230-4 wireless routers with firmware 4.03.03 and 4.05.03, when a legitimate administrator is logged into the web management interface, allow remote attackers to access the ma…
|
NVD-CWE-Other
|
CVE-2005-3802
|
2017-07-12 10:29 |
2005-11-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349657
|
7.5 |
HIGH
|
dotclear
|
dotclear
|
SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd parameter in a cookie.
|
NVD-CWE-Other
|
CVE-2005-3963
|
2017-07-12 10:29 |
2005-12-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349658
|
4.3 |
MEDIUM
|
ibm
|
net.data
|
Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web script or HTML via a macro filename, which is not properly…
|
NVD-CWE-Other
|
CVE-2004-1442
|
2017-07-12 10:29 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349659
|
7.5 |
HIGH
|
zonelabs
|
imsecure
|
Zone Labs IMsecure and IMsecure Pro before 1.5 allow remote attackers to bypass Active Link Filtering via an instant message containing a URL with hex encoded file extensions.
|
NVD-CWE-Other
|
CVE-2004-1517
|
2017-07-12 10:29 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349660
|
5.0 |
MEDIUM
|
leafnode
|
leafnode
|
fetchnews in leafnode 1.9.47 and earlier allows remote attackers to cause a denial of service (process hang) via an empty NNTP news article with missing mandatory headers.
|
NVD-CWE-Other
|
CVE-2004-2068
|
2017-07-12 10:29 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349661
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic Server and WebLogic Express 8.1 through 8.1 SP2 allow remote attackers to cause a denial of service (network port consumption) via unknown actions in HTTPS sessions, which prevents the s…
|
NVD-CWE-Other
|
CVE-2004-2424
|
2017-07-12 10:29 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349662
|
5.0 |
MEDIUM
|
microsoft
|
frontpage
|
The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name inclu…
|
NVD-CWE-Other
|
CVE-2000-0710
|
2017-07-12 10:29 |
2000-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349663
|
5.0 |
MEDIUM
|
biblioscape
|
biblioweb_server
|
Directory traversal vulnerability in BiblioWeb web server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) or ... attack in an HTTP GET request.
|
NVD-CWE-Other
|
CVE-2001-0226
|
2017-07-12 10:29 |
2001-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349664
|
7.5 |
HIGH
|
network_solutions
|
rwhoisd
|
Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.
|
NVD-CWE-Other
|
CVE-2001-0838
|
2017-07-12 10:29 |
2001-12-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349665
|
5.0 |
MEDIUM
|
phprojekt
|
phprojekt
|
The upload function in PHProjekt 2.0 through 3.1 does not properly verify certain variables related to uploaded data, which allows remote attackers to cause PHProjekt to process arbitrary files.
|
NVD-CWE-Other
|
CVE-2002-1759
|
2017-07-12 10:29 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349666
|
10.0 |
HIGH
|
fake_identd
|
fake_identd
|
Buffer overflow in Fake Identd 0.9 through 1.4 allows remote attackers to execute arbitrary code as root via a long request that is split into multiple packets.
|
NVD-CWE-Other
|
CVE-2002-1792
|
2017-07-12 10:29 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349667
|
10.0 |
HIGH
|
linksys
|
befsr11 befsr41 befsru31
|
Linksys EtherFast Cable/DSL BEFSR11, BEFSR41 and BEFSRU31 with the firmware 1.42.7 upgrade installed opens TCP port 5678 for remote administration even when the "Block WAN" and "Remote Admin" options…
|
NVD-CWE-Other
|
CVE-2002-2159
|
2017-07-12 10:29 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349668
|
5.0 |
MEDIUM
|
acme_labs
|
acme_server
|
Acme.Serve 1.7, as used in Cisco Secure ACS Unix and possibly other products, allows remote attackers to read arbitrary files by prepending several / (slash) characters to the URI.
|
CWE-20
不適切な入力確認
|
CVE-2001-0748
|
2017-07-12 00:15 |
2001-10-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349669
|
7.5 |
HIGH
|
realnetworks
|
realone_player realplayer_intranet
|
Buffer overflow in Real Networks RealPlayer 8.0 and earlier allows remote attackers to execute arbitrary code via a header length value that exceeds the actual length of the header.
|
NVD-CWE-Other
|
CVE-2002-0207
|
2017-07-12 00:15 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349670
|
5.1 |
MEDIUM
|
realnetworks
|
realone_enterprise_desktop realone_player realplayer
|
RealOne player 6.0.11.868 allows remote attackers to execute arbitrary script in the "My Computer" zone via a Synchronized Multimedia Integration Language (SMIL) presentation with a "file:javascript:…
|
NVD-CWE-Other
|
CVE-2004-1798
|
2017-07-11 21:31 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349671
|
5.0 |
MEDIUM
|
novell
|
groupwise
|
Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers to cause a denial of service (application crash) via a large TCP/IP port in the…
|
NVD-CWE-Other
|
CVE-2005-2804
|
2017-07-11 10:33 |
2005-10-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349672
|
5.0 |
MEDIUM
|
e107
|
e107
|
forum_post.php in e107 0.6 allows remote attackers to post to non-existent forums by modifying the forum number.
|
NVD-CWE-Other
|
CVE-2005-2805
|
2017-07-11 10:33 |
2005-09-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349673
|
5.0 |
MEDIUM
|
trevor_hogan
|
bnbt
|
client.cpp in BNBT EasyTracker 7.7r3.2004.10.27 and earlier allows remote attackers to cause a denial of service (application hang) via an HTTP header containing only a ":" (colon), possibly leading …
|
CWE-20
不適切な入力確認
|
CVE-2005-2806
|
2017-07-11 10:33 |
2005-09-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349674
|
4.3 |
MEDIUM
|
flatnuke
|
flatnuke
|
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter in a vis_reg operation to index.php.
|
NVD-CWE-Other
|
CVE-2005-2814
|
2017-07-11 10:33 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349675
|
6.4 |
MEDIUM
|
flatnuke
|
flatnuke
|
print.php in FlatNuke 2.5.6 allows remote attackers to obtain sensitive information (path disclosure on error) or cause a denial of service (resource consumption) via an MS-DOS device name in the new…
|
NVD-CWE-Other
|
CVE-2005-2815
|
2017-07-11 10:33 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349676
|
5.0 |
MEDIUM
|
simple_machines
|
simple_machines_forum
|
Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user …
|
NVD-CWE-Other
|
CVE-2005-2817
|
2017-07-11 10:33 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349677
|
4.3 |
MEDIUM
|
inter7
|
sqwebmail
|
Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message containing Internet Explorer "Conditional Comments" su…
|
NVD-CWE-Other
|
CVE-2005-2820
|
2017-07-11 10:33 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349678
|
7.5 |
HIGH
|
helpdesk_software
|
hesk
|
Helpdesk software Hesk 0.92 does not properly verify usernames and passwords, which allows remote attackers to bypass authentication via a direct request to admin_main.php.
|
NVD-CWE-Other
|
CVE-2005-2843
|
2017-07-11 10:33 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349679
|
7.5 |
HIGH
|
indiatimes_messenger
|
indiatimes_messenger
|
Buffer overflow in MMClient.exe in Indiatimes Messenger 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long group name argument…
|
NVD-CWE-Other
|
CVE-2005-2844
|
2017-07-11 10:33 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349680
|
5.0 |
MEDIUM
|
ariba
|
ariba_spend_management_solutions
|
Ariba Spend Management System sends the username and password to the server in plaintext in a POST request, which allows remote attackers to obtain sensitive information.
|
NVD-CWE-Other
|
CVE-2005-2845
|
2017-07-11 10:33 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349681
|
5.0 |
MEDIUM
|
barracuda_networks
|
barracuda_spam_firewall
|
Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.
|
NVD-CWE-Other
|
CVE-2005-2848
|
2017-07-11 10:33 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349682
|
4.3 |
MEDIUM
|
unclassified_newsboard
|
unclassified_newsboard
|
Cross-site scripting (XSS) vulnerability in Unclassified NewsBoard 1.5.3 allows remote attackers to inject arbitrary web script or HTML via the description field.
|
NVD-CWE-Other
|
CVE-2005-2855
|
2017-07-11 10:33 |
2005-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349683
|
7.5 |
HIGH
|
amember
|
amember
|
Multiple PHP remote file inclusion vulnerabilities in aMember Pro 2.3.4 allow remote attackers to execute arbitrary PHP code via the config[root_dir] parameter to (1) mysql.inc.php, (2) efsnet.inc.ph…
|
NVD-CWE-Other
|
CVE-2005-2865
|
2017-07-11 10:33 |
2005-09-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349684
|
7.5 |
HIGH
|
phpcommunitycalendar
|
phpcommunitycalendar
|
Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via the (1) login field in login.php or (…
|
NVD-CWE-Other
|
CVE-2005-2880
|
2017-07-11 10:33 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349685
|
7.5 |
HIGH
|
phpcommunitycalendar
|
phpcommunitycalendar
|
phpCommunityCalendar 4.0.3 allows remote attackers to bypass authentication and gain unauthorized access via a direct request to the admin directory.
|
NVD-CWE-Other
|
CVE-2005-2881
|
2017-07-11 10:33 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349686
|
4.3 |
MEDIUM
|
phpcommunitycalendar
|
phpcommunitycalendar
|
Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the LocationID para…
|
NVD-CWE-Other
|
CVE-2005-2882
|
2017-07-11 10:33 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349687
|
4.3 |
MEDIUM
|
neocrome
|
land_down_under
|
Cross-site scripting (XSS) vulnerability in events.php in Land Down Under (LDU) 801 and earlier allows remote attackers to inject arbitrary web script or HTML via the Description field in an event.
|
NVD-CWE-Other
|
CVE-2005-2884
|
2017-07-11 10:33 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349688
|
7.5 |
HIGH
|
maxdev
|
md-pro
|
The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which could allow remote attackers to bypass file exten…
|
NVD-CWE-Other
|
CVE-2005-2885
|
2017-07-11 10:33 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349689
|
4.3 |
MEDIUM
|
-
|
-
|
Multiple cross-site scripting (XSS) vulnerabilities in MAXdev MD-Pro 1.0.73, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via (1) the print parameter t…
|
NVD-CWE-Other
|
CVE-2005-2886
|
2017-07-11 10:33 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349690
|
5.0 |
MEDIUM
|
maxdev
|
md-pro
|
MAXdev MD-Pro 1.0.73, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to (1) wiki.php, (2) AutoTheme directory, (3) Blocks directory, (4) a…
|
NVD-CWE-Other
|
CVE-2005-2887
|
2017-07-11 10:33 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349691
|
7.5 |
HIGH
|
-
|
-
|
Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) Preview Release 2 allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter to misc.php or (2) Content-Dispos…
|
NVD-CWE-Other
|
CVE-2005-2888
|
2017-07-11 10:33 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349692
|
4.6 |
MEDIUM
|
secureol
|
ve2
|
SecureOL VE2 1.05.1008 does not properly restrict public access to physical memory, which allows local users to bypass intended restrictions and gain access to the secured environment via direct acce…
|
NVD-CWE-Other
|
CVE-2005-2890
|
2017-07-11 10:33 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349693
|
6.4 |
MEDIUM
|
csystems
|
webarchivex
|
WebArchiveX.dll 5.5.0.76 installed before September 6th, 2005 is marked safe for scripting by default, which allows remote attackers to read or write to arbitrary files via the (1) MakeArchive or (2)…
|
NVD-CWE-Other
|
CVE-2005-2891
|
2017-07-11 10:33 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349694
|
5.0 |
MEDIUM
|
pblang
|
pblang
|
Directory traversal vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) in …
|
NVD-CWE-Other
|
CVE-2005-2892
|
2017-07-11 10:33 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349695
|
7.5 |
HIGH
|
pblang
|
pblang
|
Direct static code injection vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via the username (u parameter), which …
|
NVD-CWE-Other
|
CVE-2005-2893
|
2017-07-11 10:33 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349696
|
4.3 |
MEDIUM
|
pblang
|
pblang
|
Cross-site scripting (XSS) vulnerability in the user registration in PBLang 4.65, and possibly earlier versions, allows remote attackers to inject arbitrary web script or PHP via the location field.
|
NVD-CWE-Other
|
CVE-2005-2894
|
2017-07-11 10:33 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349697
|
5.0 |
MEDIUM
|
pblang
|
pblang
|
setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to obtain sensitive information via a %00 (a null byte) in the u parameter, which reveals the path in an error mes…
|
NVD-CWE-Other
|
CVE-2005-2895
|
2017-07-11 10:33 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349698
|
7.5 |
HIGH
|
stylemotion
|
web_news
|
SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.p…
|
NVD-CWE-Other
|
CVE-2005-2896
|
2017-07-11 10:33 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349699
|
7.5 |
HIGH
|
-
|
-
|
SQL injection vulnerability in class-1 Forum Software 0.24.4 allows remote attackers to execute arbitrary SQL commands and bypass the file extension check via SQL code in the file extension of an upl…
|
NVD-CWE-Other
|
CVE-2005-2902
|
2017-07-11 10:33 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349700
|
7.5 |
HIGH
|
eset_software
|
nod32_antivirus
|
Heap-based buffer overflow in NOD32 2.5 with nod32.002 1.033 build 1127, with active scanning enabled, allows remote attackers to execute arbitrary code via an ARJ archive containing a file with a lo…
|
NVD-CWE-Other
|
CVE-2005-2903
|
2017-07-11 10:33 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|