|
350601
|
4.3 |
MEDIUM
|
net_portal_dynamic_system
|
net_portal_dynamic_system
|
Multiple cross-site scripting (XSS) vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to inject arbitrary web script or HTML via the language parameter to (1) admin.php, …
|
NVD-CWE-Other
|
CVE-2005-1803
|
2008-09-6 05:50 |
2005-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350602
|
7.5 |
HIGH
|
net_portal_dynamic_system
|
net_portal_dynamic_system
|
Multiple SQL injection vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to execute arbitrary SQL commands via the (1) terme parameter in the glossaire module (glossaire.…
|
NVD-CWE-Other
|
CVE-2005-1804
|
2008-09-6 05:50 |
2005-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350603
|
4.3 |
MEDIUM
|
mybulletinboard
|
mybulletinboard
|
Cross-site scripting (XSS) vulnerability in usercp.php for MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via the website field in a user profile.
|
NVD-CWE-Other
|
CVE-2005-1811
|
2008-09-6 05:50 |
2005-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350604
|
5.0 |
MEDIUM
|
hummingbird
|
connectivity
|
Multiple buffer overflows in Hummingbird Connectivity inetD 10.0.0.1 and 9.0.0.4 allows attackers to cause a denial of service and possibly execute arbitrary code via (1) an FTP command with a long a…
|
NVD-CWE-Other
|
CVE-2005-1815
|
2008-09-6 05:50 |
2005-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350605
|
4.6 |
MEDIUM
|
invision_power_services
|
invision_board
|
Invision Power Board (IPB) 1.0 through 2.0.4 allows non-root admins to add themselves or other users to the root admin group via the "Move users in this group to" screen.
|
NVD-CWE-Other
|
CVE-2005-1816
|
2008-09-6 05:50 |
2005-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350606
|
5.0 |
MEDIUM
|
invision_power_services
|
invision_board
|
Invision Power Board (IPB) 1.0 through 1.3 allows remote attackers to edit arbitrary forum posts via a direct request to index.php with modified parameters.
|
NVD-CWE-Other
|
CVE-2005-1817
|
2008-09-6 05:50 |
2005-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350607
|
7.5 |
HIGH
|
newlife_blogger
|
newlife_blogger
|
Multiple SQL injection vulnerabilities in NewLife Blogger before 3.3.1 allow remote attackers to execute arbitrary SQL commands via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2005-1818
|
2008-09-6 05:50 |
2005-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350608
|
4.3 |
MEDIUM
|
nikosoft
|
webmail
|
Cross-site scripting (XSS) vulnerability in NikoSoft WebMail before 0.11.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-1819
|
2008-09-6 05:50 |
2005-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350609
|
7.5 |
HIGH
|
zeroboard
|
zeroboard
|
zboard.php in Zeroboard version 4.1pl2 to 4.1pl5 allows remote attackers to execute arbitrary PHP code via improper quoting when using the preg_replace function.
|
NVD-CWE-Other
|
CVE-2005-1820
|
2008-09-6 05:50 |
2005-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350610
|
7.5 |
HIGH
|
gnu
|
mailutils
|
The sql_escape_string function in auth/sql.c for the mailutils SQL authentication module does not properly quote the "\" (backslash) character, which is used as an escape character and makes the modu…
|
NVD-CWE-Other
|
CVE-2005-1824
|
2008-09-6 05:50 |
2005-06-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350611
|
2.1 |
LOW
|
adobe
|
acrobat_reader
|
The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary files with the permissions as specified in a user's umask, which could allow local users to read PDF …
|
NVD-CWE-Other
|
CVE-2005-1841
|
2008-09-6 05:50 |
2005-07-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350612
|
2.1 |
LOW
|
adobe
|
version_cue
|
VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with Version Cue Workspace, creates temporary log files with predictable names, which…
|
NVD-CWE-Other
|
CVE-2005-1842
|
2008-09-6 05:50 |
2005-08-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350613
|
4.6 |
MEDIUM
|
adobe
|
version_cue
|
VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with Version Cue Workspace, allows local users to load arbitrary libraries and execut…
|
NVD-CWE-Other
|
CVE-2005-1843
|
2008-09-6 05:50 |
2005-08-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350614
|
5.0 |
MEDIUM
|
yamt
|
yamt
|
Multiple directory traversal vulnerabilities in YaMT before 0.5_2 allow attackers to overwrite arbitrary files via the (1) rename or (2) sort options.
|
NVD-CWE-Other
|
CVE-2005-1846
|
2008-09-6 05:50 |
2005-01-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350615
|
7.5 |
HIGH
|
yamt
|
yamt
|
Multiple buffer overflows in YaMT before 0.5_2 allow attackers to execute arbitrary code via the (1) rename or (2) sort options.
|
NVD-CWE-Other
|
CVE-2005-1847
|
2008-09-6 05:50 |
2005-01-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350616
|
5.0 |
MEDIUM
|
phystech
|
dhcpcd
|
The dhcpcd DHCP client before 1.3.22 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors that cause an out-of-bounds memory read.
|
NVD-CWE-Other
|
CVE-2005-1848
|
2008-09-6 05:50 |
2005-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350617
|
7.2 |
HIGH
|
university_of_minnesota
|
gopher
|
gopher.c in the Gopher client 3.0.5 does not properly create temporary files, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-1853
|
2008-09-6 05:50 |
2005-08-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350618
|
2.1 |
LOW
|
sukria debian
|
backup_manager debian_linux
|
Backup Manager (backup-manager) before 0.5.8 creates backup files with world-readable default permissions, which allows local users to obtain sensitive information.
|
NVD-CWE-Other
|
CVE-2005-1855
|
2008-09-6 05:50 |
2005-08-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350619
|
2.1 |
LOW
|
-
|
-
|
The CD-burning feature in backup-manager 0.5.8 and earlier uses a fixed filename in a world-writable directory for logging, which allows local users to overwrite files via a symlink attack.
|
NVD-CWE-Other
|
CVE-2005-1856
|
2008-09-6 05:50 |
2005-08-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350620
|
2.1 |
LOW
|
fuse
|
fuse
|
FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local users to obtain sensit…
|
NVD-CWE-Other
|
CVE-2005-1858
|
2008-09-6 05:50 |
2005-06-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350621
|
5.0 |
MEDIUM
|
vincent_hor
|
calendarix_advanced
|
PHP remote file inclusion vulnerability in cal_admintop.php in Calendarix Advanced 1.5 allows remote attackers to execute arbitrary PHP code via the calpath parameter.
|
NVD-CWE-Other
|
CVE-2005-1864
|
2008-09-6 05:50 |
2005-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350622
|
4.3 |
MEDIUM
|
vincent_hor
|
calendarix_advanced
|
Cross-site scripting (XSS) vulnerability in calendar.php in Calendarix Advanced 1.5 allows remote attackers to inject arbitrary web script or HTML via the year parameter.
|
NVD-CWE-Other
|
CVE-2005-1866
|
2008-09-6 05:50 |
2005-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350623
|
4.3 |
MEDIUM
|
lpanel
|
lpanel
|
Cross-site scripting (XSS) vulnerability in view_ticket.php in Lpanel 1.59 and earlier allows remote attackers to inject arbitrary web script or HTML and obtain sensitive information via the pid para…
|
NVD-CWE-Other
|
CVE-2005-1877
|
2008-09-6 05:50 |
2005-06-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350624
|
1.2 |
LOW
|
giptables
|
giptables_firewall
|
GIPTables Firewall 1.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the temp.ip.addresses temporary file.
|
NVD-CWE-Other
|
CVE-2005-1878
|
2008-09-6 05:50 |
2005-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350625
|
7.5 |
HIGH
|
yapig
|
yapig
|
PHP remote file inclusion vulnerability in last_gallery.php in YaPiG 0.93u and 0.94u allows remote attackers to execute arbitrary PHP code via the YAPIG_PATH parameter.
|
NVD-CWE-Other
|
CVE-2005-1882
|
2008-09-6 05:50 |
2005-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350626
|
5.0 |
MEDIUM
|
yapig
|
yapig
|
global.php in YaPiG 0.92b allows remote attackers to include arbitrary local files via the BASE_DIR parameter.
|
NVD-CWE-Other
|
CVE-2005-1883
|
2008-09-6 05:50 |
2005-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350627
|
6.4 |
MEDIUM
|
yapig
|
yapig
|
Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to create or delete arbitrary directories via a .. (dot …
|
NVD-CWE-Other
|
CVE-2005-1884
|
2008-09-6 05:50 |
2005-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350628
|
5.0 |
MEDIUM
|
yapig
|
yapig
|
view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to obtain sensitive information via a phid parameter that is not an integer, which reveals the path in an error message.
|
NVD-CWE-Other
|
CVE-2005-1885
|
2008-09-6 05:50 |
2005-06-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350629
|
4.3 |
MEDIUM
|
yapig
|
yapig
|
Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject arbitrary web script or HTML via (1) the phid parameter or (2) unknown parameter…
|
NVD-CWE-Other
|
CVE-2005-1886
|
2008-09-6 05:50 |
2005-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350630
|
4.3 |
MEDIUM
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.5 allows remote attackers to inject arbitrary web script via HTML attributes in page templates.
|
NVD-CWE-Other
|
CVE-2005-1888
|
2008-09-6 05:50 |
2005-06-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350631
|
5.0 |
MEDIUM
|
mortiforo
|
mortiforo
|
Unknown vulnerability in Mortiforo before 0.9.1 allows users to access private forums via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2005-1890
|
2008-09-6 05:50 |
2005-06-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350632
|
10.0 |
HIGH
|
flexcast
|
flexcast_audio_video_streaming_server
|
Unknown vulnerability in FlexCast Audio Video Streaming Server before 2.0 has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2005-1897
|
2008-09-6 05:50 |
2005-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350633
|
5.0 |
MEDIUM
|
phpthumb
|
phpthumb
|
The passthrough functionality in phpThumb.php in phpThumb() before 1.5.4 allows remote attackers to read files that are not images.
|
NVD-CWE-Other
|
CVE-2005-1898
|
2008-09-6 05:50 |
2005-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350634
|
7.5 |
HIGH
|
perception
|
liteweb
|
Perception LiteWeb allows remote attackers to bypass access controls for files via an extra leading / (slash) or leading \ (backslash) in the URL.
|
NVD-CWE-Other
|
CVE-2005-1908
|
2008-09-6 05:50 |
2005-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350635
|
4.3 |
MEDIUM
|
software602
|
602lan_suite
|
The web server control panel in 602LAN SUITE 2004 allows remote attackers to make it more difficult for the administrator to read portions of log files via a "</pre><!-" sequence in an HTTP GET reque…
|
NVD-CWE-Other
|
CVE-2005-1909
|
2008-09-6 05:50 |
2005-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350636
|
5.0 |
MEDIUM
|
leafnode
|
leafnode
|
The fetchnews NNTP client in leafnode 1.11.2 and earlier can hang while waiting for input that never arrives, which allows remote NNTP servers to cause a denial of service (news loss).
|
NVD-CWE-Other
|
CVE-2005-1911
|
2008-09-6 05:50 |
2005-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350637
|
2.1 |
LOW
|
centericq
|
centericq
|
CenterICQ 4.20.0 and earlier creates temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack on the gg.token.PID temporary file.
|
NVD-CWE-Other
|
CVE-2005-1914
|
2008-09-6 05:50 |
2005-07-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350638
|
2.1 |
LOW
|
kpopper
|
kpopper
|
kpopper 1.0 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the .popper-new temporary file.
|
NVD-CWE-Other
|
CVE-2005-1917
|
2008-09-6 05:50 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350639
|
5.0 |
MEDIUM
|
clam_anti-virus
|
clamav
|
The MS-Expand file handling in Clam AntiVirus (ClamAV) before 0.86 allows remote attackers to cause a denial of service (file descriptor and memory consumption) via a crafted file that causes repeate…
|
NVD-CWE-Other
|
CVE-2005-1922
|
2008-09-6 05:50 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350640
|
2.6 |
LOW
|
clam_anti-virus
|
clamav
|
The ENSURE_BITS macro in mszipd.c for Clam AntiVirus (ClamAV) 0.83, and other versions vefore 0.86, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a cabin…
|
NVD-CWE-Other
|
CVE-2005-1923
|
2008-09-6 05:50 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350641
|
2.1 |
LOW
|
lpanel
|
lpanel
|
Lpanel 1.59 and earlier, and other versions before 1.597, allows remote authenticated users to modify certain critical variables and (1) modify DNS settings for arbitrary domains via the domain param…
|
NVD-CWE-Other
|
CVE-2005-1932
|
2008-09-6 05:50 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350642
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget with the same bundle identifier (CFBundleIdentifie…
|
NVD-CWE-Other
|
CVE-2005-1933
|
2008-09-6 05:50 |
2005-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350643
|
7.5 |
HIGH
|
jammail
|
jammail
|
jammail.pl in jamchen JamMail 1.8 allows remote attackers to execute arbitrary commands via shell metacharacters in the mail parameter.
|
NVD-CWE-Other
|
CVE-2005-1959
|
2008-09-6 05:50 |
2005-06-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350644
|
7.5 |
HIGH
|
-
|
-
|
The getemails function in C.J. Steele Tattle allows remote attackers to execute arbitrary commands via shell metacharacters in certain log entries, as demonstrated using shell metacharacters in an FT…
|
NVD-CWE-Other
|
CVE-2005-1960
|
2008-09-6 05:50 |
2005-06-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350645
|
4.6 |
MEDIUM
|
objectweb
|
consortium_c-jdbc
|
Unknown vulnerability in ObjectWeb Consortium C-JDBC before 1.3.1 allows local users to bypass intended access restrictions and obtain the cache results from another user.
|
NVD-CWE-Other
|
CVE-2005-1961
|
2008-09-6 05:50 |
2005-06-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350646
|
4.3 |
MEDIUM
|
cerberus
|
cerberus_helpdesk
|
Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3 allows remote attackers to inject arbitrary web script or HTML via the (1) errorcode parameter to index.php or (2) certain fields …
|
NVD-CWE-Other
|
CVE-2005-1962
|
2008-09-6 05:50 |
2005-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350647
|
5.0 |
MEDIUM
|
cerberus
|
cerberus_helpdesk
|
Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which leaks the information …
|
NVD-CWE-Other
|
CVE-2005-1963
|
2008-09-6 05:50 |
2005-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350648
|
7.5 |
HIGH
|
cantico
|
ovidentia
|
PHP remote file inclusion vulnerability in utilit.php for Ovidentia Portal allows remote attackers to execute arbitrary PHP code via the babInstallPath parameter.
|
NVD-CWE-Other
|
CVE-2005-1964
|
2008-09-6 05:50 |
2005-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350649
|
7.5 |
HIGH
|
early_impact
|
productcart_ecommerce
|
Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter …
|
NVD-CWE-Other
|
CVE-2005-1967
|
2008-09-6 05:50 |
2005-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350650
|
4.3 |
MEDIUM
|
early_impact
|
productcart
|
Cross-site scripting (XSS) vulnerability in ProductCart Ecommerce before 2.7 allows remote attackers to inject arbitrary web script or HTML via the error parameter to techErr.asp.
|
NVD-CWE-Other
|
CVE-2005-1968
|
2008-09-6 05:50 |
2005-06-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|