|
349801
|
4.6 |
MEDIUM
|
debian
|
toolchain-source debian_linux
|
The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2005-0159
|
2017-07-11 10:32 |
2005-04-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349802
|
5.0 |
MEDIUM
|
mod_dosevasive
|
mod_dosevasive
|
The mod_dosevasive module 1.9 and earlier for Apache creates temporary files with predictable filenames, which could allow remote attackers to overwrite arbitrary files via a symlink attack.
|
NVD-CWE-Other
|
CVE-2005-0182
|
2017-07-11 10:32 |
2005-01-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349803
|
7.2 |
HIGH
|
squirrelmail
|
vacation_plugin
|
ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to execute arbitrary commands via shell metacharacters in a command line argument.
|
NVD-CWE-Other
|
CVE-2005-0183
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349804
|
2.1 |
LOW
|
-
|
-
|
Directory traversal vulnerability in ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to read arbitrary files via a .. (dot dot) in a get request.
|
NVD-CWE-Other
|
CVE-2005-0184
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349805
|
7.5 |
HIGH
|
mnet_soft_factory
|
nodemanager_professional
|
Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a LinkDown-Trap packet that contains a long OCTET-STRING in the Trap variable-bi…
|
NVD-CWE-Other
|
CVE-2005-0185
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349806
|
7.5 |
HIGH
|
athoc
|
athoc_toolbar
|
Stack-based buffer overflow in the SetSkin function in AtHoc toolbar allows remote attackers to execute arbitrary code via a long skin name.
|
NVD-CWE-Other
|
CVE-2005-0187
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349807
|
7.5 |
HIGH
|
athoc
|
athoc_toolbar
|
Format string vulnerability in the SetBaseURL function in AtHoc toolbar allows remote attackers to execute arbitrary code via format string specifiers in an invalid URL that is recorded in the debug …
|
NVD-CWE-Other
|
CVE-2005-0188
|
2017-07-11 10:32 |
2004-10-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349808
|
7.2 |
HIGH
|
isync
|
mrouter
|
Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-0193
|
2017-07-11 10:32 |
2005-01-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349809
|
5.0 |
MEDIUM
|
amp
|
amp_ii_3d_game_engine
|
The Amp II engine as used by Gore: Ultimate Soldier 1.50 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero byte UDP packet.
|
NVD-CWE-Other
|
CVE-2005-0212
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349810
|
5.0 |
MEDIUM
|
webtoolmaster_software
|
winhki
|
Directory traversal vulnerability in WinHKI 1.4d allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a zip file.
|
NVD-CWE-Other
|
CVE-2005-0213
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349811
|
5.0 |
MEDIUM
|
alexander_palmo
|
simple_php_blog
|
Directory traversal vulnerability in Simple PHP Blog (SPHPBlog) 0.3.7c allows remote attackers to read or create arbitrary files via a .. (dot dot) in the entry parameter.
|
NVD-CWE-Other
|
CVE-2005-0214
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349812
|
5.0 |
MEDIUM
|
mozilla
|
mozilla
|
Mozilla 1.6 and possibly other versions allows remote attackers to cause a denial of service (application crash) via a XBM (X BitMap) file with a large (1) height or (2) width value.
|
NVD-CWE-Other
|
CVE-2005-0215
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349813
|
7.5 |
HIGH
|
invision_power_services
|
invision_community_blog
|
SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter.
|
NVD-CWE-Other
|
CVE-2005-0217
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349814
|
4.3 |
MEDIUM
|
gallery_project
|
gallery
|
Multiple cross-site scripting (XSS) vulnerabilities in Gallery 1.3.4-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the index field in add_comment.php, (2) set_albumName, (…
|
NVD-CWE-Other
|
CVE-2005-0219
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349815
|
5.0 |
MEDIUM
|
gallery_project
|
gallery
|
Cross-site scripting vulnerability in login.php in Gallery 1.4.4-pl2 allows remote attackers to inject arbitrary web script or HTML via the username field.
|
NVD-CWE-Other
|
CVE-2005-0220
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349816
|
4.3 |
MEDIUM
|
gallery_project
|
gallery
|
Cross-site scripting (XSS) vulnerability in login.php in Gallery 2.0 Alpha allows remote attackers to inject arbitrary web script or HTML via the g2_form[subject] field.
|
NVD-CWE-Other
|
CVE-2005-0221
|
2017-07-11 10:32 |
2005-01-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349817
|
5.0 |
MEDIUM
|
gallery_project
|
gallery
|
main.php in Gallery 2.0 Alpha allows remote attackers to gain sensitive information by changing the value of g2_subView parameter, which reveals the path in an error message.
|
NVD-CWE-Other
|
CVE-2005-0222
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349818
|
2.1 |
LOW
|
firehol
|
firehol
|
firehol.sh in FireHOL before 1.224 creates temporary files with predictable file names, which could allow local users to overwrite arbitrary files via a symlink attack.
|
NVD-CWE-Other
|
CVE-2005-0225
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349819
|
5.0 |
MEDIUM
|
citrusdb
|
citrusdb_customer_database
|
CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card information via a direct request to newfile.txt.
|
NVD-CWE-Other
|
CVE-2005-0229
|
2017-07-11 10:32 |
2005-04-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349820
|
5.0 |
MEDIUM
|
apple
|
safari
|
The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way th…
|
NVD-CWE-Other
|
CVE-2005-0234
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349821
|
5.0 |
MEDIUM
|
omnigroup
|
omniweb
|
The International Domain Name (IDN) support in Omniweb 5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that …
|
NVD-CWE-Other
|
CVE-2005-0236
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349822
|
7.5 |
HIGH
|
squirrelmail
|
s_mime_plugin
|
viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacters in the cert parameter.
|
NVD-CWE-Other
|
CVE-2005-0239
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349823
|
7.2 |
HIGH
|
ibm
|
aix
|
Format string vulnerability in chdev on IBM AIX 5.2 allows local users to execute arbitrary code via format string specifiers in a command line argument, which is not properly handled when printing a…
|
NVD-CWE-Other
|
CVE-2005-0240
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349824
|
7.2 |
HIGH
|
ibm
|
aix
|
Format string vulnerability in auditselect on IBM AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via format string specifiers in a command line argument.
|
NVD-CWE-Other
|
CVE-2005-0250
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349825
|
2.1 |
LOW
|
ibm
|
aix
|
lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-0261
|
2017-07-11 10:32 |
2005-02-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349826
|
7.2 |
HIGH
|
ibm
|
aix
|
Buffer overflow in ipl_varyon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -d argument.
|
NVD-CWE-Other
|
CVE-2005-0262
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349827
|
7.2 |
HIGH
|
ibm
|
aix
|
Buffer overflow in netpmon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -O argument.
|
NVD-CWE-Other
|
CVE-2005-0263
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349828
|
4.3 |
MEDIUM
|
owl
|
owl_intranet_engine
|
Multiple cross-site scripting (XSS) vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) expand or (2) order parameter.
|
NVD-CWE-Other
|
CVE-2005-0264
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349829
|
7.5 |
HIGH
|
owl
|
owl_intranet_engine
|
Multiple SQL injection vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to execute arbitrary SQL commands via the (1) parent or (2) sortposted parameter.
|
NVD-CWE-Other
|
CVE-2005-0265
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349830
|
4.3 |
MEDIUM
|
sugarcrm
|
sugarcrm
|
Cross-site scripting (XSS) vulnerability in index.php in SugarCRM 1.X allows remote attackers to inject arbitrary web script or HTML via the (1) return_module, (2) return_action, (3) name, (4) module…
|
NVD-CWE-Other
|
CVE-2005-0266
|
2017-07-11 10:32 |
2005-01-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349831
|
7.5 |
HIGH
|
flatnuke
|
flatnuke
|
index.php in FlatNuke 2.5.1 allows remote attackers to create an administrator account via carriage returns and #10 in the url_avatar field, which is interpreted as a sensitive directive.
|
NVD-CWE-Other
|
CVE-2005-0267
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349832
|
7.5 |
HIGH
|
flatnuke
|
flatnuke
|
Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url_avatar field.
|
NVD-CWE-Other
|
CVE-2005-0268
|
2017-07-11 10:32 |
2005-01-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349833
|
4.3 |
MEDIUM
|
photopost
|
reviewpost_php_pro
|
Multiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to inject arbitrary web script or HTML via the (1) si parameter to showcat.php, (2) cat or…
|
NVD-CWE-Other
|
CVE-2005-0270
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349834
|
7.5 |
HIGH
|
photopost
|
reviewpost_php_pro
|
Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) product parameter to …
|
NVD-CWE-Other
|
CVE-2005-0271
|
2017-07-11 10:32 |
2005-01-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349835
|
7.5 |
HIGH
|
photopost
|
reviewpost_php_pro
|
ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review file with multiple extensions, which bypasses the intended restrictions.
|
NVD-CWE-Other
|
CVE-2005-0272
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349836
|
7.5 |
HIGH
|
photopost
|
photopost_php_pro
|
Multiple SQL injection vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) ppuser parameter.
|
NVD-CWE-Other
|
CVE-2005-0273
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349837
|
4.3 |
MEDIUM
|
photopost
|
photopost_php_pro
|
Multiple cross-site scripting (XSS) vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) si, (3) page, or (4)…
|
NVD-CWE-Other
|
CVE-2005-0274
|
2017-07-11 10:32 |
2005-01-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349838
|
5.0 |
MEDIUM
|
3com
|
3cdaemon
|
TFTP in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) via a GET request containing an MS-DOS device name.
|
NVD-CWE-Other
|
CVE-2005-0275
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349839
|
5.0 |
MEDIUM
|
3com
|
3cdaemon
|
Multiple format string vulnerabilities in the FTP service in 3Com 3CDaemon 2.0 revision 10 allow remote attackers to cause a denial of service (application crash) via format string specifiers in (1) …
|
NVD-CWE-Other
|
CVE-2005-0276
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349840
|
5.0 |
MEDIUM
|
3com
|
3cdaemon
|
Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via (1) a long username in the …
|
NVD-CWE-Other
|
CVE-2005-0277
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349841
|
5.0 |
MEDIUM
|
3com
|
3cdaemon
|
The FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to gain sensitive information via a cd command that contains an MS-DOS device name, which reveals the installation path in an …
|
NVD-CWE-Other
|
CVE-2005-0278
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349842
|
5.0 |
MEDIUM
|
jowood_productions
|
soldner_secret_wars
|
Soldner Secret Wars 30830 and earlier does not properly handle the "message too long" socket error, which allows remote attackers to cause a denial of service (socket termination) via a long UDP pack…
|
NVD-CWE-Other
|
CVE-2005-0279
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349843
|
7.5 |
HIGH
|
jowood_productions
|
soldner_secret_wars
|
Format string vulnerability in Soldner Secret Wars 30830 and earlier allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifie…
|
NVD-CWE-Other
|
CVE-2005-0280
|
2017-07-11 10:32 |
2005-01-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349844
|
4.3 |
MEDIUM
|
jowood_productions
|
soldner_secret_wars
|
Cross-site scripting (XSS) vulnerability in the web interface in Soldner Secret Wars 30830 allows remote attackers to inject arbitrary web script or HTML via a user message, which is not filtered or …
|
NVD-CWE-Other
|
CVE-2005-0281
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349845
|
7.5 |
HIGH
|
mybulletinboard
|
mybulletinboard
|
SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the uid parameter.
|
NVD-CWE-Other
|
CVE-2005-0282
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349846
|
5.0 |
MEDIUM
|
david_barrett
|
qwikiwiki
|
Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of the filename in the page parameter.
|
NVD-CWE-Other
|
CVE-2005-0283
|
2017-07-11 10:32 |
2005-01-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349847
|
7.5 |
HIGH
|
woltlab
|
burning_book
|
SQL injection vulnerability in addentry.php in Woltlab Burning Book 1.0 Gold, 1.1.1e, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the user-agent paramet…
|
NVD-CWE-Other
|
CVE-2005-0284
|
2017-07-11 10:32 |
2005-01-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349848
|
4.6 |
MEDIUM
|
bottomline
|
webseries_payment_application
|
Webseries Payment Application does not properly restrict privileged operations, which allows remote authenticated users to gain privileges by directly accessing certain URLs.
|
NVD-CWE-Other
|
CVE-2005-0285
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349849
|
5.0 |
MEDIUM
|
emotion
|
mediapartner_web_server
|
eMotion MediaPartner Web Server 5.0 and 5.1 allows remote attackers to obtain sensitive information via an HTTP request for a .bhtml file that contains a (1) . (dot) or (2) + (plus sign) at the end, …
|
NVD-CWE-Other
|
CVE-2005-0286
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349850
|
5.0 |
MEDIUM
|
bottomline
|
webseries_payment_application
|
Bottomline Webseries Payment Application allows remote attackers to read arbitrary files on the network via a report template with modified ReportPath or ReportName values.
|
NVD-CWE-Other
|
CVE-2005-0287
|
2017-07-11 10:32 |
2005-01-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|