|
349851
|
5.0 |
MEDIUM
|
py_software
|
active_webcam
|
PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to Filelist.html.
|
NVD-CWE-Other
|
CVE-2005-0731
|
2017-07-11 10:32 |
2005-03-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349852
|
5.0 |
MEDIUM
|
py_software
|
active_webcam
|
PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to obtain the full path of the web server via a request for a non-existent filename, which leaks the full path in an error…
|
NVD-CWE-Other
|
CVE-2005-0732
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349853
|
5.0 |
MEDIUM
|
py_software
|
active_webcam
|
PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to determine the existence of files via an HTTP request with a full pathname, which produces different messages whether th…
|
NVD-CWE-Other
|
CVE-2005-0733
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349854
|
5.0 |
MEDIUM
|
py_software
|
active_webcam
|
PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (memory exhaustion and process crash) via a large number of HTTP requests.
|
NVD-CWE-Other
|
CVE-2005-0734
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349855
|
7.5 |
HIGH
|
xoops
|
xoops
|
The custom avatar uploading feature (uploader.php) for XOOPS 2.0.9.2 and earlier allows remote attackers to upload arbitrary PHP scripts, whose file extensions are not filtered.
|
NVD-CWE-Other
|
CVE-2005-0743
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349856
|
10.0 |
HIGH
|
novell
|
ichain
|
The web GUI for Novell iChain 2.2 and 2.3 SP2 and SP3 allows attackers to hijack sessions and gain administrator privileges by (1) sniffing the connection on TCP port 51100 and replaying the authenti…
|
NVD-CWE-Other
|
CVE-2005-0744
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349857
|
5.0 |
MEDIUM
|
novell
|
ichain
|
The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD command.
|
NVD-CWE-Other
|
CVE-2005-0746
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349858
|
7.5 |
HIGH
|
webinsta
|
webinsta_mailing_manager
|
PHP remote file inclusion vulnerability in initdb.php for WEBInsta Mailing list manager 1.3d allows remote attackers to execute arbitrary PHP code by modifying the absolute_path parameter to referenc…
|
CWE-94
コード・インジェクション
|
CVE-2005-0748
|
2017-07-11 10:32 |
2005-03-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349859
|
7.5 |
HIGH
|
photopost
|
photopost_php_pro
|
SQL injection vulnerability in member.php and possibly other scripts in PhotoPost PHP 5.0 RC3 allows remote attackers to execute arbitrary SQL commands via the uid parameter.
|
NVD-CWE-Other
|
CVE-2005-0774
|
2017-07-11 10:32 |
2005-03-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349860
|
7.5 |
HIGH
|
photopost
|
photopost_php_pro
|
The reportpost action in misc.php for PhotoPost PHP 5.0 RC3 does not limit the logging data that is sent to the administrator, which allows remote attackers to send large amounts of email to the admi…
|
NVD-CWE-Other
|
CVE-2005-0775
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349861
|
5.0 |
MEDIUM
|
photopost
|
photopost_php_pro
|
adm-photo.php in PhotoPost PHP 5.0 RC3 does not properly verify administrative privileges before manipulating photos, which could allow remote attackers to manipulate other users' photos.
|
NVD-CWE-Other
|
CVE-2005-0776
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349862
|
4.3 |
MEDIUM
|
photopost
|
photopost_php_pro
|
Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP 5.0 RC3 allow remote attackers to inject arbitrary web script or HTML via (1) the check_tags function or (2) the editbio field in …
|
NVD-CWE-Other
|
CVE-2005-0777
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349863
|
5.0 |
MEDIUM
|
photopost
|
photopost_php_pro
|
PhotoPost PHP 5.0 RC3 does not fully verify that an uploaded file is an image file, which allows remote attackers to inject arbitrary Javascript by uploading non-image files with an image extension s…
|
NVD-CWE-Other
|
CVE-2005-0778
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349864
|
7.5 |
HIGH
|
php_arena
|
pafiledb
|
SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter to pafiledb.php.
|
NVD-CWE-Other
|
CVE-2005-0781
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349865
|
4.3 |
MEDIUM
|
php_arena
|
pafiledb
|
Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the start parameter to…
|
NVD-CWE-Other
|
CVE-2005-0782
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349866
|
4.3 |
MEDIUM
|
yabb
|
yabb
|
Cross-site scripting (XSS) vulnerability in usersrecentposts in YaBB 2.0 rc1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
|
NVD-CWE-Other
|
CVE-2005-0785
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349867
|
7.5 |
HIGH
|
simpgb
|
simpgb
|
SQL injection vulnerability in gb_new.inc in SimpGB allows remote attackers to execute arbitrary SQL commands via the quote parameter to guestbook.php.
|
NVD-CWE-Other
|
CVE-2005-0786
|
2017-07-11 10:32 |
2005-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349868
|
2.1 |
LOW
|
wine
|
wine
|
Wine 20050211 and earlier creates temp files with world readable permissions and predictable file names, which allows local users to obtain sensitive information, such as passwords.
|
NVD-CWE-Other
|
CVE-2005-0787
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349869
|
5.0 |
MEDIUM
|
limewire
|
limewire
|
LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request.
|
NVD-CWE-Other
|
CVE-2005-0788
|
2017-07-11 10:32 |
2005-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349870
|
5.0 |
MEDIUM
|
limewire
|
limewire
|
Directory traversal vulnerability in LimeWire 3.9.6 through 4.6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in a magnet request.
|
NVD-CWE-Other
|
CVE-2005-0789
|
2017-07-11 10:32 |
2005-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349871
|
5.0 |
MEDIUM
|
phpadsnew
|
phpadsnew
|
phpAdsNew 2.0.4 allows remote attackers to obtain sensitive information via a direct request to (1) lib-xmlrpcs.inc.php, (2) maintenance-activation.php, (3) maintenance-cleantables.php, (4) maintenan…
|
NVD-CWE-Other
|
CVE-2005-0790
|
2017-07-11 10:32 |
2005-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349872
|
4.3 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the refresh parame…
|
NVD-CWE-Other
|
CVE-2005-0791
|
2017-07-11 10:32 |
2005-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349873
|
7.5 |
HIGH
|
zpanel
|
zpanel
|
SQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter to index.php or (2) page parameter to zpanel.php.
|
NVD-CWE-Other
|
CVE-2005-0792
|
2017-07-11 10:32 |
2005-03-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349874
|
6.4 |
MEDIUM
|
zpanel
|
zpanel
|
ZPanel 2.0 and 2.5 beta 10 does not remove or protect installation scripts after they have been used, which allows remote attackers to reinstall the software and possibly cause a denial of service vi…
|
NVD-CWE-Other
|
CVE-2005-0794
|
2017-07-11 10:32 |
2005-03-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349875
|
5.0 |
MEDIUM
|
hola
|
holacms
|
HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified vote_filename parameter.
|
NVD-CWE-Other
|
CVE-2005-0795
|
2017-07-11 10:32 |
2005-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349876
|
4.3 |
MEDIUM
|
asp_press
|
acs_blog
|
Cross-site scripting (XSS) vulnerability in search.asp in ACS Blog 0.8 through 1.1b allows remote attackers to execute arbitrary web script or HTML via the search parameter.
|
NVD-CWE-Other
|
CVE-2005-0802
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349877
|
7.5 |
HIGH
|
oxid
|
cain_and_abel
|
Multiple buffer overflows in Cain & Abel before 2.67 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via (1) an IKE packet with a large ID …
|
NVD-CWE-Other
|
CVE-2005-0807
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349878
|
5.0 |
MEDIUM
|
apache
|
tomcat
|
Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.
|
NVD-CWE-Other
|
CVE-2005-0808
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349879
|
5.0 |
MEDIUM
|
lysator
|
lsh
|
Unknown vulnerability in lshd in Lysator LSH 1.x and 2.x before 2.0.1 allows remote attackers to cause a denial of service via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-0814
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349880
|
5.0 |
MEDIUM
|
symantec
|
enterprise_firewall velociraptor gateway_security_5300 gateway_security_5400
|
Unknown vulnerability in the DNSd proxy, as used in Symantec Gateway Security 5400 2.x and 5300 1.x, Enterprise Firewall 7.0.x and 8.x, and VelociRaptor 1100/1200/1300 1.5, allows remote attackers to…
|
NVD-CWE-Other
|
CVE-2005-0817
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349881
|
4.3 |
MEDIUM
|
punbb
|
punbb
|
Cross-site scripting (XSS) vulnerability in PunBB 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) email or (2) Jabber parameters.
|
NVD-CWE-Other
|
CVE-2005-0818
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349882
|
7.5 |
HIGH
|
-
|
-
|
Unknown vulnerability in Citrix MetaFrame Conferencing Manager 3.0 allows conference members to bypass organizer restrictions to control the keyboard and mouse.
|
NVD-CWE-Other
|
CVE-2005-0821
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349883
|
4.6 |
MEDIUM
|
thepoolclub
|
ipool isnooker
|
ThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.txt file, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-0823
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349884
|
5.0 |
MEDIUM
|
ollydbg
|
ollydbg
|
OllyDbg 1.10 and earlier allows remote attackers to cause a denial of service (application crash) via a dynamic link library (DLL) with a long filename.
|
NVD-CWE-Other
|
CVE-2005-0826
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349885
|
5.0 |
MEDIUM
|
icecast
|
icecast
|
IceCast 2.20 allows remote attackers to bypass the XSL parser and obtain the source for XSL files via a request for a .xsl file with a trailing . (dot).
|
NVD-CWE-Other
|
CVE-2005-0837
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349886
|
7.5 |
HIGH
|
icecast
|
icecast
|
Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow attackers to cause a denial of service and possibly execute arbitrary code via (1) a long test value in an xsl:when tag, (2) a l…
|
NVD-CWE-Other
|
CVE-2005-0838
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349887
|
7.5 |
HIGH
|
phpmyfamily
|
phpmyfamily
|
SQL injection vulnerability in (1) people.php, (2) track.php, (3) edit.php, (4) document.php, (5) census.php, (6) passthru.php and possibly other php files in phpMyFamily 1.4.0 allows remote attacker…
|
NVD-CWE-Other
|
CVE-2005-0841
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349888
|
4.6 |
MEDIUM
|
nortel
|
contivity
|
Nortel VPN client 5.01 stores the cleartext password in the memory of the Extranet.exe process, which could allow local users to obtain sensitive information.
|
CWE-310
暗号の問題
|
CVE-2005-0844
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349889
|
5.0 |
MEDIUM
|
funlabs
|
4x4_off-road_adventure_iii cabelas_big_game_hunter_2004_season cabelas_big_game_hunter_2005 cabelas_dangerous_hunts cabelas_deer_hunt_2005_season revolution secret_service_in_harms_…
|
Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote att…
|
NVD-CWE-Other
|
CVE-2005-0848
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349890
|
7.5 |
HIGH
|
betaparticle
|
betaparticle_blog
|
betaparticle blog (bp blog), posisbly before version 4, allows remote attackers to bypass authentication and (1) upload files via a direct request to upload.asp or (2) delete files via a direct reque…
|
NVD-CWE-Other
|
CVE-2005-0854
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349891
|
4.3 |
MEDIUM
|
coolforum
|
coolforum
|
Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the img parameter.
|
NVD-CWE-Other
|
CVE-2005-0857
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349892
|
7.5 |
HIGH
|
coolforum
|
coolforum
|
Multiple SQL injection vulnerabilities in CoolForum 0.8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to entete.php or (2) the login parameter to r…
|
NVD-CWE-Other
|
CVE-2005-0858
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349893
|
7.5 |
HIGH
|
delegate
|
delegate
|
Multiple buffer overflows in DeleGate before 8.11.1 may allow attackers to cause a denial of service or execute arbitrary code, possibly due to "overflows on arrays."
|
NVD-CWE-Other
|
CVE-2005-0861
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349894
|
4.3 |
MEDIUM
|
phpopenchat
|
phpopenchat
|
Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or HTML via (1) the chatter parameter to regulars.php or (2) the chatter, chatter1,…
|
NVD-CWE-Other
|
CVE-2005-0863
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349895
|
5.0 |
MEDIUM
|
phpsysinfo
|
phpsysinfo
|
phpSysInfo 2.3 allows remote attackers to obtain sensitive information via a direct request to (1) class.OpenBSD.inc.php, (2) class.NetBSD.inc.php, (3) class.FreeBSD.inc.php, (4) class.Darwin.inc.php…
|
NVD-CWE-Other
|
CVE-2005-0869
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349896
|
4.3 |
MEDIUM
|
phpsysinfo
|
phpsysinfo
|
Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) sensor_program param…
|
NVD-CWE-Other
|
CVE-2005-0870
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349897
|
5.0 |
MEDIUM
|
phpbb_group
|
phpbb
|
calendar_scheduler.php in Topic Calendar 1.0.1 module for phpBB, when running on a Microsoft IIS server, allows remote attackers to obtain sensitive information via invalid parameters, which reveal t…
|
NVD-CWE-Other
|
CVE-2005-0871
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349898
|
4.3 |
MEDIUM
|
phpbb_group
|
phpbb
|
Cross-site scripting (XSS) vulnerability in calendar_scheduler.php in the Topic Calendar 1.0.1 module for phpBB allows remote attackers to inject arbitrary web script or HTML via the start parameter.
|
NVD-CWE-Other
|
CVE-2005-0872
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349899
|
5.0 |
MEDIUM
|
dnsmasq
|
dnsmasq
|
Off-by-one buffer overflow in Dnsmasq before 2.21 may allow attackers to execute arbitrary code via the DHCP lease file.
|
NVD-CWE-Other
|
CVE-2005-0876
|
2017-07-11 10:32 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349900
|
4.3 |
MEDIUM
|
mercuryboard
|
mercuryboard_message_board
|
Cross-site scripting (XSS) vulnerability in MercuryBoard before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the title field of a PM (private message).
|
NVD-CWE-Other
|
CVE-2005-0878
|
2017-07-11 10:32 |
2005-03-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|