|
355501
|
7.5 |
HIGH
|
solucija
|
snews
|
SQL injection vulnerability in snews.php in sNews 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category parameters to index.php.
|
NVD-CWE-Other
|
CVE-2005-3853
|
2011-03-8 11:27 |
2005-11-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355502
|
7.5 |
HIGH
|
easybe
|
1-2-3_music_store
|
SQL injection vulnerability in process.php in 1-2-3 music store allows remote attackers to execute arbitrary SQL commands via the AlbumID parameter.
|
NVD-CWE-Other
|
CVE-2005-3855
|
2011-03-8 11:27 |
2005-11-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355503
|
7.5 |
HIGH
|
berlios
|
sourcewell
|
SQL injection vulnerability in index.php in SourceWell 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the cnt parameter. NOTE: various reports indicate that the affe…
|
NVD-CWE-Other
|
CVE-2005-3864
|
2011-03-8 11:27 |
2005-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355504
|
7.5 |
HIGH
|
scripts-templates
|
allweb_search
|
SQL injection vulnerability in index.php in AllWeb search 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameter.
|
NVD-CWE-Other
|
CVE-2005-3865
|
2011-03-8 11:27 |
2005-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355505
|
7.5 |
HIGH
|
turn-k
|
k-search
|
Multiple SQL injection vulnerabilities in K-Search 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term, (2) id, (3) stat, and (4) source parameters to index.php,…
|
NVD-CWE-Other
|
CVE-2005-3868
|
2011-03-8 11:27 |
2005-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355506
|
7.5 |
HIGH
|
edmobbs
|
edmobbs
|
Multiple SQL injection vulnerabilities in edmobbs9r.php in edmoBBS 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) table and (2) messageID parameters.
|
NVD-CWE-Other
|
CVE-2005-3870
|
2011-03-8 11:27 |
2005-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355507
|
7.5 |
HIGH
|
jbb
|
jbb
|
Multiple SQL injection vulnerabilities in Joels Bulletin board (JBB) 0.9.9rc3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) nr parameter in topiczeigen.php, (2) for…
|
NVD-CWE-Other
|
CVE-2005-3871
|
2011-03-8 11:27 |
2005-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355508
|
7.5 |
HIGH
|
ugroup
|
ugroup
|
Multiple SQL injection vulnerabilities in Ugroup 2.6.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) FORUM_ID parameter in forum.php, and the (2) TOPIC_ID, (3) FORU…
|
NVD-CWE-Other
|
CVE-2005-3872
|
2011-03-8 11:27 |
2005-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355509
|
7.5 |
HIGH
|
sourceshock
|
shockboard
|
SQL injection vulnerability in topic.php in ShockBoard 3.0 and 4.0 allows remote attackers to execute arbitrary SQL commands via the offset parameter.
|
NVD-CWE-Other
|
CVE-2005-3873
|
2011-03-8 11:27 |
2005-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355510
|
7.5 |
HIGH
|
weaverslave
|
netzbrett
|
SQL injection vulnerability in netzbr.php in Netzbrett 1.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the p_entry parameter in an entry command to index.php.
|
NVD-CWE-Other
|
CVE-2005-3874
|
2011-03-8 11:27 |
2005-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355511
|
7.5 |
HIGH
|
enterprise_heart
|
enterprise_connector
|
Multiple SQL injection vulnerabilities in Enterprise Connector 1.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the messageid parameter in (1) send.php or (2) a delete a…
|
NVD-CWE-Other
|
CVE-2005-3875
|
2011-03-8 11:27 |
2005-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355512
|
7.5 |
HIGH
|
td-systems
|
adc2000_ng_pro adc2000_ng_pro_lite
|
Multiple SQL injection vulnerabilities in adcbrowres.php in AD Center ADC2000 NG Pro 1.2 and NG Pro Lite allow remote attackers to execute arbitrary SQL commands via the (1) cat and (2) lang paramete…
|
NVD-CWE-Other
|
CVE-2005-3876
|
2011-03-8 11:27 |
2005-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355513
|
6.4 |
MEDIUM
|
alex_king
|
php_doc_system
|
Directory traversal vulnerability in index.php in PHP Doc System 1.5.1 and earlier allows remote attackers to access or include arbitrary files via a .. (dot dot) in the show parameter.
|
NVD-CWE-Other
|
CVE-2005-3878
|
2011-03-8 11:27 |
2005-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355514
|
7.5 |
HIGH
|
omnistar_interactive
|
omnistar_kbase
|
Multiple SQL injection vulnerabilities in Omnistar KBase 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter in users/comments.php, (2) category_…
|
NVD-CWE-Other
|
CVE-2005-3880
|
2011-03-8 11:27 |
2005-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355515
|
7.5 |
HIGH
|
faqsystems
|
faqring_knowledge_base_software
|
SQL injection vulnerability in answer.php in FAQSystems FAQRing Knowledge Base Software 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2005-3882
|
2011-03-8 11:27 |
2005-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355516
|
7.2 |
HIGH
|
-
|
-
|
Unspecified vulnerability in Cisco Security Agent (CSA) 4.5.0 and 4.5.1 agents, when running on Windows systems, allows local users to bypass protections and gain system privileges by executing certa…
|
NVD-CWE-Other
|
CVE-2005-3886
|
2011-03-8 11:27 |
2005-11-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355517
|
7.8 |
HIGH
|
-
|
-
|
Macromedia Breeze Communication Server and Breeze Live Server does 5.1 and earlier not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or cra…
|
NVD-CWE-Other
|
CVE-2005-3900
|
2011-03-8 11:27 |
2005-11-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355518
|
4.3 |
MEDIUM
|
amazon_shop
|
amazon_shop
|
Cross-site scripting (XSS) vulnerability in search.php in GhostScripter Amazon Shop 5.0.0, and other versions before 5.0.2, allows remote attackers to inject web script or HTML via the query paramete…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2005-3908
|
2011-03-8 11:27 |
2005-11-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355519
|
7.5 |
HIGH
|
bosdev
|
bosdates
|
Multiple SQL injection vulnerabilities in calendar.php in BosDates 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) category parameters.
|
NVD-CWE-Other
|
CVE-2005-3911
|
2011-03-8 11:27 |
2005-11-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355520
|
5.0 |
MEDIUM
|
vchs
|
vchs
|
Unspecified vulnerability in the domain alias management in Virtual Hosting Control System (VHCS) 2.4.6.2, related to "creating and deleting forwards for domain aliases," allows users to hijack the f…
|
NVD-CWE-Other
|
CVE-2005-3913
|
2011-03-8 11:27 |
2005-11-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355521
|
6.4 |
MEDIUM
|
affcommerce
|
affcommerce
|
Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemI…
|
NVD-CWE-Other
|
CVE-2005-3914
|
2011-03-8 11:27 |
2005-11-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355522
|
7.5 |
HIGH
|
clavister
|
clavister_firewall clavister_security_gateway
|
The Internet Key Exchange version 1 (IKEv1) implementation in Clavister Client Web allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as…
|
NVD-CWE-Other
|
CVE-2005-3915
|
2011-03-8 11:27 |
2005-11-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355523
|
7.5 |
HIGH
|
wsn_forum
|
wsn_forum
|
SQL injection vulnerability in memberlist.php in WSN Forum 1.21 allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action.
|
NVD-CWE-Other
|
CVE-2005-3916
|
2011-03-8 11:27 |
2005-11-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355524
|
7.5 |
HIGH
|
commodityrentals
|
commodityrentals
|
SQL injection vulnerability in usersession in CommodityRentals 2.0 Online Rental Business Creator script allows remote attackers to execute arbitrary SQL commands via the user_id parameter.
|
NVD-CWE-Other
|
CVE-2005-3917
|
2011-03-8 11:27 |
2005-11-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355525
|
5.0 |
MEDIUM
|
netobjects
|
netobjects_fusion
|
NetObjects Fusion 9 (NOF9) allows remote attackers to obtain sensitive information, including passwords, by downloading the _versioning_repository_/rollbacklog.xml file, then using it to download and…
|
NVD-CWE-Other
|
CVE-2005-3923
|
2011-03-8 11:27 |
2005-11-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355526
|
7.5 |
HIGH
|
helpdesk_issue_manager
|
helpdesk_issue_manager
|
Multiple SQL injection vulnerabilities in Central Manchester CLC Helpdesk Issue Manager 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) detail[], (2) orderdir, an…
|
NVD-CWE-Other
|
CVE-2005-3925
|
2011-03-8 11:27 |
2005-11-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355527
|
7.5 |
HIGH
|
o-kiraku_nikki
|
o-kiraku_nikki
|
SQL injection vulnerability in okiraku.php in O-Kiraku Nikki 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the day_id parameter.
|
NVD-CWE-Other
|
CVE-2005-3932
|
2011-03-8 11:27 |
2005-12-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355528
|
7.5 |
HIGH
|
88script
|
88script_event_calendar
|
SQL injection vulnerability in index.php in 88Script's Event Calendar 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter.
|
NVD-CWE-Other
|
CVE-2005-3933
|
2011-03-8 11:27 |
2005-12-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355529
|
7.5 |
HIGH
|
greywyvern
|
orca_ringmaker
|
SQL injection vulnerability in ringmaker.php in Orca Ringmaker 2.3c and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter.
|
NVD-CWE-Other
|
CVE-2005-3940
|
2011-03-8 11:27 |
2005-12-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355530
|
7.5 |
HIGH
|
greywyvern
|
orca_blog
|
SQL injection vulnerability in blog.php in Orca Blog 1.3b and earlier allows remote attackers to execute arbitrary SQL commands via the msg parameter.
|
NVD-CWE-Other
|
CVE-2005-3941
|
2011-03-8 11:27 |
2005-12-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355531
|
7.5 |
HIGH
|
greywyvern
|
orca_knowledgebase
|
SQL injection vulnerability in knowledgebase-control.php in Orca Knowledgebase 2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter.
|
NVD-CWE-Other
|
CVE-2005-3942
|
2011-03-8 11:27 |
2005-12-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355532
|
7.5 |
HIGH
|
-
|
-
|
Multiple SQL injection vulnerabilities in ilyav FAQ System 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) FAQ_ID and (2) action parameters in (a) viewFAQ.php; a…
|
NVD-CWE-Other
|
CVE-2005-3943
|
2011-03-8 11:27 |
2005-12-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355533
|
7.5 |
HIGH
|
faq_system
|
faq_system
|
SQL injection vulnerability in survey.php in ilyav Survey System 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the SURVEY_ID parameter.
|
NVD-CWE-Other
|
CVE-2005-3944
|
2011-03-8 11:27 |
2005-12-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355534
|
6.8 |
MEDIUM
|
nufw
|
nufw
|
nuauth in NuFW 1.0.x before 1.0.16 and 1.1 allows authenticated users to cause a denial of service via malformed packets.
|
NVD-CWE-Other
|
CVE-2005-3950
|
2011-03-8 11:27 |
2005-12-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355535
|
7.5 |
HIGH
|
php_labs
|
survey_wizard
|
SQL injection vulnerability in survey.php in PHP Labs Survey Wizard allows remote attackers to execute arbitrary SQL commands via the sid parameter.
|
NVD-CWE-Other
|
CVE-2005-3951
|
2011-03-8 11:27 |
2005-12-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355536
|
4.3 |
MEDIUM
|
java_search_engine
|
java_search_engine
|
Cross-site scripting (XSS) vulnerability in search.jsp in Java Search Engine (JSE) 0.9.34 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
|
NVD-CWE-Other
|
CVE-2005-3966
|
2011-03-8 11:27 |
2005-12-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355537
|
4.3 |
MEDIUM
|
atlassian
|
confluence
|
Cross-site scripting (XSS) vulnerability in the dosearchsite.action module in Atlassian Confluence 2.0.1 Build 321 allows remote attackers to inject arbitrary web script or HTML via the searchQuery.q…
|
NVD-CWE-Other
|
CVE-2005-3967
|
2011-03-8 11:27 |
2005-12-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355538
|
7.5 |
HIGH
|
mxchange
|
mxchange
|
SQL injection vulnerability in MXChange before 0.2.0-pre10 PL492 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-3969
|
2011-03-8 11:27 |
2005-12-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355539
|
4.3 |
MEDIUM
|
mxchange
|
mxchange
|
Cross-site scripting (XSS) vulnerability in MXChange before 0.2.0-pre10 PL492 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-3970
|
2011-03-8 11:27 |
2005-12-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355540
|
4.3 |
MEDIUM
|
extreme_corporate
|
extreme_search
|
Cross-site scripting (XSS) vulnerability in extremesearch.php in Extreme Search Corporate Edition 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search paramet…
|
NVD-CWE-Other
|
CVE-2005-3972
|
2011-03-8 11:27 |
2005-12-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355541
|
4.3 |
MEDIUM
|
qualityebiz
|
qualityppc
|
Cross-site scripting (XSS) vulnerability in QualityEBiz Quality PPC 1553 allows remote attackers to inject web script or HTML via the REQ parameter to the search module.
|
NVD-CWE-Other
|
CVE-2005-3977
|
2011-03-8 11:27 |
2005-12-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355542
|
7.5 |
HIGH
|
scriptdevelopers.net
|
netclassifieds
|
Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition 1.0.1 allow remote attackers to execute arbitrar…
|
NVD-CWE-Other
|
CVE-2005-3978
|
2011-03-8 11:27 |
2005-12-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355543
|
7.8 |
HIGH
|
astaro
|
security_linux
|
The Internet Key Exchange version 1 (IKEv1) implementation in Astaro Security Linux before 6.102 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted I…
|
NVD-CWE-Other
|
CVE-2005-3985
|
2011-03-8 11:27 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355544
|
7.5 |
HIGH
|
pineapple_technologies
|
lore
|
SQL injection vulnerability in article.php in Pineapple Technologies Lore 1.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2005-3988
|
2011-03-8 11:27 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355545
|
7.8 |
HIGH
|
avaya
|
tn2602ap_ip_media_resource_320_circuit_pack
|
Memory leak in Avaya TN2602AP IP Media Resource 320 circuit pack before vintage 9 firmware allows remote attackers to cause a denial of service (memory consumption) via crafted VoIP packets.
|
NVD-CWE-Other
|
CVE-2005-3989
|
2011-03-8 11:27 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355546
|
7.8 |
HIGH
|
mailenable
|
mailenable_enterprise mailenable_professional
|
Multiple unspecified vulnerabilities in MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allow attackers to cause a denial of service (crash) via invalid IMAP commands.
|
NVD-CWE-Other
|
CVE-2005-3993
|
2011-03-8 11:27 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355547
|
7.5 |
HIGH
|
phpyellow
|
phpyellowtm_lite phpyellowtm_pro
|
Multiple SQL injection vulnerabilities in phpYellowTM Pro Edition and Lite Edition 5.33 allow remote attackers to execute arbitrary SQL commands via the (1) haystack parameter to search_result.php or…
|
NVD-CWE-Other
|
CVE-2005-4001
|
2011-03-8 11:27 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355548
|
4.3 |
MEDIUM
|
infinetsoftware
|
mytemplatesite
|
Cross-site scripting (XSS) vulnerability in search.asp in MyTemplateSite 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.
|
NVD-CWE-Other
|
CVE-2005-4004
|
2011-03-8 11:27 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355549
|
7.5 |
HIGH
|
php_fusion
|
php_fusion
|
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to obtain path information and possibly execute arbitrary SQL commands via the srch_text parameter in a Sear…
|
NVD-CWE-Other
|
CVE-2005-4005
|
2011-03-8 11:27 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355550
|
7.5 |
HIGH
|
widget_press
|
widget_property
|
SQL injection vulnerability in Widget Property 1.1.19 allows remote attackers to execute arbitrary SQL commands via the (1) property_id, (2) zip_code, (3) property_type_id, (4) price, and (5) city_id…
|
NVD-CWE-Other
|
CVE-2005-4016
|
2011-03-8 11:27 |
2005-12-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|