|
350651
|
4.3 |
MEDIUM
|
pragma_systems
|
pragma_telnetserver
|
Cross-site scripting (XSS) vulnerability in Pragma Systems Telnetserver 6.0 allows remote attackers to inject arbitrary web script or HTML, and hide activities in log files, via a "<!--" (HTML commen…
|
NVD-CWE-Other
|
CVE-2005-1969
|
2008-09-6 05:50 |
2005-06-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350652
|
7.2 |
HIGH
|
symantec
|
pcanywhere
|
Symantec pcAnywhere 10.5x and 11.x before 11.5, with "Launch with Windows" enabled, allows local users with physical access to execute arbitrary commands via the Caller Properties feature.
|
NVD-CWE-Other
|
CVE-2005-1970
|
2008-09-6 05:50 |
2005-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350653
|
7.5 |
HIGH
|
interactivephp
|
fusionbb
|
Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter.
|
NVD-CWE-Other
|
CVE-2005-1971
|
2008-09-6 05:50 |
2005-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350654
|
7.5 |
HIGH
|
interactivephp
|
fusionbb
|
Multiple SQL injection vulnerabilities in InteractivePHP FusionBB .11 Beta and earlier allow remote attackers to execute arbitrary SQL commands via (1) the username, which is not properly handled by …
|
NVD-CWE-Other
|
CVE-2005-1972
|
2008-09-6 05:50 |
2005-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350655
|
4.3 |
MEDIUM
|
annuaire
|
1two
|
Multiple cross-site scripting (XSS) vulnerabilities in Annuaire 1Two 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter to index.php, or the (2) si…
|
NVD-CWE-Other
|
CVE-2005-1975
|
2008-09-6 05:50 |
2005-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350656
|
1.7 |
LOW
|
novell
|
netmail
|
Novell NetMail 3.5.2a, 3.5.2b, and 3.5.2c, when running on Linux, sets the owner and group ID to 500 for certain files, which could allow users or groups with that ID to execute arbitrary code or cau…
|
NVD-CWE-Other
|
CVE-2005-1976
|
2008-09-6 05:50 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350657
|
6.4 |
MEDIUM
|
edgewall_software
|
trac
|
Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the id parameter to the (1) upload or (2) attachmen…
|
NVD-CWE-Other
|
CVE-2005-2007
|
2008-09-6 05:50 |
2005-06-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350658
|
10.0 |
HIGH
|
symantec
|
norton_antivirus
|
Symantec AntiVirus 9 Corporate Edition allows local users to gain privileges via the "Scan for viruses" option, which launches a help window with raised privileges, a re-introduction of a vulnerabili…
|
NVD-CWE-Other
|
CVE-2005-2017
|
2008-09-6 05:50 |
2005-08-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350659
|
5.0 |
MEDIUM
|
freebsd
|
freebsd
|
ipfw in FreeBSD 5.4, when running on Symmetric Multi-Processor (SMP) or Uni Processor (UP) systems with the PREEMPTION kernel option enabled, does not sufficiently lock certain resources while perfor…
|
NVD-CWE-Other
|
CVE-2005-2019
|
2008-09-6 05:50 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350660
|
4.3 |
MEDIUM
|
cpanel
|
cpanel
|
Cross-site scripting (XSS) vulnerability in cPanel 9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the user parameter in the login page.
|
NVD-CWE-Other
|
CVE-2005-2021
|
2008-09-6 05:50 |
2005-06-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350661
|
5.0 |
MEDIUM
|
vipul
|
razor-agents
|
Vipul Razor Agents (razor-agents) before 2.70 allows remote attackers to cause a denial of service via (1) certain "unusual HTML messages" or (2) "certain malformed headers" such as Content-Type.
|
NVD-CWE-Other
|
CVE-2005-2024
|
2008-09-6 05:50 |
2005-06-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350662
|
7.5 |
HIGH
|
enterasys
|
vertical_horizon-2402s
|
Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 has a hard-coded account and password for debugging, which allows remote attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-2026
|
2008-09-6 05:50 |
2005-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350663
|
5.0 |
MEDIUM
|
enterasys
|
vertical_horizon-2402s
|
Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 does not properly restrict certain debugging commands to the ADMIN account, which could allow attackers to obtain sensitive information …
|
NVD-CWE-Other
|
CVE-2005-2027
|
2008-09-6 05:50 |
2005-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350664
|
7.5 |
HIGH
|
amarok
|
web_frontend
|
amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and pass…
|
NVD-CWE-Other
|
CVE-2005-2029
|
2008-09-6 05:50 |
2005-06-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350665
|
7.5 |
HIGH
|
socialmpn
|
socialmpn
|
Multiple SQL injection vulnerabilities in socialMPN allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter to article.php, (2) uname parameter to user.php, (3) siteid para…
|
NVD-CWE-Other
|
CVE-2005-2031
|
2008-09-6 05:50 |
2005-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350666
|
5.0 |
MEDIUM
|
fortibus
|
fortibus_cms
|
Fortibus CMS 4.0.0 allows remote attackers to modify information of other users, including Admin, via the "My info" page.
|
NVD-CWE-Other
|
CVE-2005-2038
|
2008-09-6 05:50 |
2005-06-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350667
|
5.0 |
MEDIUM
|
nanoblogger
|
nanoblogger
|
Unknown vulnerability in "various plugins" for NanoBlogger 3.2.1 and earlier allows remote attackers to execute arbitrary commands.
|
NVD-CWE-Other
|
CVE-2005-2039
|
2008-09-6 05:50 |
2005-06-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350668
|
5.0 |
MEDIUM
|
telnetd
|
telnetd
|
Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal before 0.6.5 may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2005-0468 and CV…
|
NVD-CWE-Other
|
CVE-2005-2040
|
2008-09-6 05:50 |
2005-06-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350669
|
4.3 |
MEDIUM
|
ajax-spell
|
ajax-spell
|
Cross-site scripting (XSS) vulnerability in ajax-spell before 1.8 allows remote attackers to inject arbitrary web script or HTML via onmouseover or other events in HTML tags.
|
NVD-CWE-Other
|
CVE-2005-2042
|
2008-09-6 05:50 |
2005-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350670
|
5.0 |
MEDIUM
|
xampp
|
apache_distribution
|
Directory traversal vulnerability in XAMPP before 1.4.14 allows remote attackers to inject arbitrary HTML and PHP code via lang.php.
|
NVD-CWE-Other
|
CVE-2005-2043
|
2008-09-6 05:50 |
2005-06-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350671
|
4.3 |
MEDIUM
|
adaptive_technology_resource_centre
|
atutor
|
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3 and 1.5 RC 1 allow remote attackers to inject arbitrary web script or HTML via the (1) show_course parameter to browse.php, (2) sub…
|
NVD-CWE-Other
|
CVE-2005-2044
|
2008-09-6 05:50 |
2005-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350672
|
5.1 |
MEDIUM
|
realnetworks
|
realone_player realplayer
|
Unknown vulnerability in RealPlayer 10 and 10.5 (6.0.12.1040-1069) and RealOne Player v1 and v2 allows remote attackers to overwrite arbitrary files or execute arbitrary ActiveX controls via a crafte…
|
NVD-CWE-Other
|
CVE-2005-2054
|
2008-09-6 05:50 |
2005-06-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350673
|
5.0 |
MEDIUM
|
realnetworks
|
realone_player realplayer
|
RealPlayer 8, 10, 10.5 (6.0.12.1040-1069), and Enterprise and RealOne Player v1 and v2 allows remote malicious web server to create an arbitrary HTML file that executes an RM file via "default settin…
|
NVD-CWE-Other
|
CVE-2005-2055
|
2008-09-6 05:50 |
2005-06-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350674
|
5.0 |
MEDIUM
|
freebsd
|
freebsd
|
FreeBSD 4.x through 4.11 and 5.x through 5.4 allows remote attackers to modify certain TCP options via a TCP packet with the SYN flag set for an already established session.
|
NVD-CWE-Other
|
CVE-2005-2068
|
2008-09-6 05:50 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350675
|
5.0 |
MEDIUM
|
sendmail
|
sendmail
|
The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevent…
|
NVD-CWE-Other
|
CVE-2005-2070
|
2008-09-6 05:50 |
2005-06-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350676
|
2.1 |
LOW
|
ibm
|
db2
|
Unknown vulnerability in IBM DB2 8.1.4 through 8.1.9 and 8.2.0 through 8.2.2 allows local users with SELECT privileges to conduct unauthorized activities and insert, update or delete table contents.
|
NVD-CWE-Other
|
CVE-2005-2073
|
2008-09-6 05:50 |
2005-06-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350677
|
2.1 |
LOW
|
sofotex
|
bisonftp
|
BisonFTP Server V4R1 allows remote authenticated users to cause a denial of service via an invalid command with a long argument.
|
NVD-CWE-Other
|
CVE-2005-2078
|
2008-09-6 05:50 |
2005-06-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350678
|
7.5 |
HIGH
|
symantec_veritas
|
backup_exec
|
Heap-based buffer overflow in the Admin Plus Pack Option for VERITAS Backup Exec 9.0 through 10.0 for Windows Servers allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-2079
|
2008-09-6 05:50 |
2005-08-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350679
|
7.5 |
HIGH
|
symantec_veritas
|
backup_exec
|
Unknown vulnerability in Remote Agent for Windows Servers (RAWS) in VERITAS Backup Exec 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for NetWare, allows remote attackers to gain privile…
|
NVD-CWE-Other
|
CVE-2005-2080
|
2008-09-6 05:50 |
2005-06-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350680
|
5.0 |
MEDIUM
|
kde
|
kde
|
langen2kvtml in KDE 3.0 to 3.4.2 creates insecure temporary files in /tmp with predictable names, which allows local users to overwrite arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-2101
|
2008-09-6 05:50 |
2005-08-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350681
|
7.5 |
HIGH
|
etoshop
|
dynamic_biz_website_builder_quickweb
|
SQL injection vulnerability in verify.asp in EtoShop Dynamic Biz Website Builder (QuickWeb) 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) T1 or (2) T2 parameters.
|
NVD-CWE-Other
|
CVE-2005-2135
|
2008-09-6 05:50 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350682
|
5.0 |
MEDIUM
|
nateon
|
nateon_messenger
|
Unknown vulnerability in NateOn Messenger 3.0 allows remote attackers to list arbitrary directories via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2005-2137
|
2008-09-6 05:50 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350683
|
4.3 |
MEDIUM
|
comdev
|
comdev_ecommerce
|
Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the onMouseOver event of an "A" …
|
NVD-CWE-Other
|
CVE-2005-2138
|
2008-09-6 05:50 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350684
|
5.0 |
MEDIUM
|
fsboard
|
fsboard
|
Directory traversal vulnerability in default.asp for FSboard 2.0 allows remote attackers to read arbitrary files via ".." sequences in the filename parameter.
|
NVD-CWE-Other
|
CVE-2005-2140
|
2008-09-6 05:50 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350685
|
5.0 |
MEDIUM
|
jollybox.de
|
tcp_chat
|
TCP Chat 1.0 allows remote attackers to cause a denial of service (crash) via a long string to the chat service, possibly triggering a buffer overflow.
|
NVD-CWE-Other
|
CVE-2005-2141
|
2008-09-6 05:50 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350686
|
2.1 |
LOW
|
kmint21_software
|
golden_ftp_server
|
Directory traversal vulnerability in Golden FTP Server 2.60 allows remote authenticated attackers to list arbitrary directories via a "\.." (backslash dot dot) in an LS (LIST) command.
|
NVD-CWE-Other
|
CVE-2005-2142
|
2008-09-6 05:50 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350687
|
4.3 |
MEDIUM
|
survivor
|
survivor
|
Cross-site scripting (XSS) vulnerability in SURVIVOR before 0.9.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-1388
|
2008-09-6 05:49 |
2005-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350688
|
4.6 |
MEDIUM
|
freebsd
|
freebsd
|
FreeBSD 4.6 to 4.11 and 5.x to 5.4 uses insecure default permissions for the /dev/iir device, which allows local users to execute restricted ioctl calls to read or modify data on hardware that is con…
|
NVD-CWE-Other
|
CVE-2005-1399
|
2008-09-6 05:49 |
2005-05-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350689
|
4.6 |
MEDIUM
|
freebsd
|
freebsd
|
The i386_get_ldt system call in FreeBSD 4.7 to 4.11 and 5.x to 5.4 allows local users to access sensitive kernel memory via arguments with negative or very large values.
|
NVD-CWE-Other
|
CVE-2005-1400
|
2008-09-6 05:49 |
2005-05-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350690
|
7.5 |
HIGH
|
mtp-target
|
mtp-target
|
Format string vulnerability in the client for Mtp-Target 1.2.2 and earlier allows remote attackers to execute arbitrary code via game messages or other text.
|
NVD-CWE-Other
|
CVE-2005-1401
|
2008-09-6 05:49 |
2005-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350691
|
5.0 |
MEDIUM
|
mtp-target
|
mtp-target
|
Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and possibly other products, allows remote attackers to cause a denial of service (memo…
|
NVD-CWE-Other
|
CVE-2005-1402
|
2008-09-6 05:49 |
2005-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350692
|
6.8 |
MEDIUM
|
-
|
-
|
Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's Amazon Webstore 04050100 allow remote attackers to inject arbitrary web script or HTML via the (1) image parameter to closeup.php,…
|
NVD-CWE-Other
|
CVE-2005-1403
|
2008-09-6 05:49 |
2005-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350693
|
5.0 |
MEDIUM
|
myphp_forum
|
myphp_forum
|
MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.
|
NVD-CWE-Other
|
CVE-2005-1404
|
2008-09-6 05:49 |
2005-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350694
|
4.6 |
MEDIUM
|
skype_technologies
|
skype
|
Skype for Windows 1.2.0.0 to 1.2.0.46 allows local users to bypass the identity check for an authorized application, then call arbitrary Skype API functions by modifying or replacing that application.
|
NVD-CWE-Other
|
CVE-2005-1407
|
2008-09-6 05:49 |
2005-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350695
|
7.5 |
HIGH
|
ecomm
|
professional_guestbook
|
SQL injection vulnerability in verify.asp for Ecomm Professional Guestbook 3.x allows remote attackers to execute arbitrary SQL commands via the AdminPWD parameter.
|
NVD-CWE-Other
|
CVE-2005-1412
|
2008-09-6 05:49 |
2005-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350696
|
10.0 |
HIGH
|
globalscape
|
secure_ftp_server
|
Buffer overflow in GlobalSCAPE Secure FTP Server 3.0.2 allows remote authenticated users to execute arbitrary code via a long FTP command.
|
NVD-CWE-Other
|
CVE-2005-1415
|
2008-09-6 05:49 |
2005-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350697
|
7.5 |
HIGH
|
maxwebportal
|
maxwebportal
|
Multiple SQL injection vulnerabilities in MaxWebPortal 2.x, 1.35, and other versions allow remote attackers to execute arbitrary SQL commands via (1) article_popular.asp, (2) arguments to dl_popular.…
|
NVD-CWE-Other
|
CVE-2005-1417
|
2008-09-6 05:49 |
2005-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350698
|
7.5 |
HIGH
|
maxwebportal
|
maxwebportal
|
The vulnerabilities have been partially fixed in versions 1.3.5 and 2.0. The remaining vulnerabilities will reportedly be fixed in the upcoming 2.1 version.
|
NVD-CWE-Other
|
CVE-2005-1417
|
2008-09-6 05:49 |
2005-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350699
|
7.5 |
HIGH
|
ocean12_technologies
|
mailing_list_manager
|
SQL injection vulnerability in the admin login panel for Ocean12 Mailing List Manager 1.06 allows remote attackers to execute arbitrary SQL commands via the Admin_id parameter.
|
NVD-CWE-Other
|
CVE-2005-1419
|
2008-09-6 05:49 |
2005-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350700
|
5.0 |
MEDIUM
|
raysoft
|
video_cam_server
|
Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to determine the full pathname of the server via a request for an invalid page, as demonstrated using "%20" (hex-encoded space).
|
NVD-CWE-Other
|
CVE-2005-1420
|
2008-09-6 05:49 |
2005-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|