|
357901
|
5.0 |
MEDIUM
|
linksys
|
wrt54g
|
Linksys WRT54G router allows remote attackers to cause a denial of service (CPU consumption and server hang) via an HTTP POST request with a negative Content-Length value.
|
NVD-CWE-Other
|
CVE-2005-2912
|
2008-09-6 05:52 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357902
|
7.5 |
HIGH
|
linksys
|
wrt54g
|
ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions, does not use an authentication initialization function, which allows remote a…
|
NVD-CWE-Other
|
CVE-2005-2914
|
2008-09-6 05:52 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357903
|
5.0 |
MEDIUM
|
linksys
|
wrt54g
|
ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions, uses weak encryption (XOR encoding with a fixed byte mask) for configuration …
|
NVD-CWE-Other
|
CVE-2005-2915
|
2008-09-6 05:52 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357904
|
5.0 |
MEDIUM
|
linksys
|
wrt54g
|
Linksys WRT54G 3.01.03, 3.03.6, 4.00.7, and possibly other versions before 4.20.7, does not verify user authentication until after an HTTP POST request has been processed, which allows remote attacke…
|
NVD-CWE-Other
|
CVE-2005-2916
|
2008-09-6 05:52 |
2005-09-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357905
|
5.0 |
MEDIUM
|
microsoft
|
frontpage
|
Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page.
|
NVD-CWE-Other
|
CVE-2005-2143
|
2008-09-6 05:51 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357906
|
2.1 |
LOW
|
prevx
|
prevx_pro_2005
|
Prevx Pro 2005 1.0 allows local users to bypass file protection and modify files by using MapViewOfFile to perform memory mapping on the file.
|
NVD-CWE-Other
|
CVE-2005-2144
|
2008-09-6 05:51 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357907
|
4.6 |
MEDIUM
|
prevx
|
prevx_pro_2005
|
The kernel driver in Prevx Pro 2005 1.0 does not verify the source of certain messages, which allows local users to bypass protection by sending certain messages to the driver, as demonstrated by sen…
|
NVD-CWE-Other
|
CVE-2005-2145
|
2008-09-6 05:51 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357908
|
4.6 |
MEDIUM
|
ssh
|
tectia_server
|
SSH Tectia Server 4.3.1 and earlier, and SSH Secure Shell for Windows Servers, uses insecure permissions when generating the Secure Shell host identification key, which allows local users to access t…
|
NVD-CWE-Other
|
CVE-2005-2146
|
2008-09-6 05:51 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357909
|
6.4 |
MEDIUM
|
edgewall_software
|
trac
|
Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts.
|
NVD-CWE-Other
|
CVE-2005-2147
|
2008-09-6 05:51 |
2005-07-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357910
|
5.0 |
MEDIUM
|
double_precision_incorporated
|
courier_mail_server
|
spf.c in Courier Mail Server does not properly handle DNS failures when looking up Sender Policy Framework (SPF) records, which could allow attackers to cause memory corruption.
|
NVD-CWE-Other
|
CVE-2005-2151
|
2008-09-6 05:51 |
2005-07-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357911
|
7.5 |
HIGH
|
geeklog
|
geeklog
|
SQL injection vulnerability in Geeklog before 1.3.11 allows remote attackers to execute arbitrary SQL commands via user comments for an article.
|
NVD-CWE-Other
|
CVE-2005-2152
|
2008-09-6 05:51 |
2005-07-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357912
|
7.5 |
HIGH
|
osticket
|
osticket_sts
|
SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable.
|
NVD-CWE-Other
|
CVE-2005-2153
|
2008-09-6 05:51 |
2005-07-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357913
|
7.5 |
HIGH
|
osticket
|
osticket_sts
|
PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and possibly execute arbitrary local files via the inc pa…
|
NVD-CWE-Other
|
CVE-2005-2154
|
2008-09-6 05:51 |
2005-07-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357914
|
7.5 |
HIGH
|
phpnews
|
phpnews
|
SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter.
|
NVD-CWE-Other
|
CVE-2005-2156
|
2008-09-6 05:51 |
2005-07-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357915
|
7.5 |
HIGH
|
globalnotescript
|
globalnotescript
|
read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters.
|
NVD-CWE-Other
|
CVE-2005-2165
|
2008-09-6 05:51 |
2005-07-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357916
|
5.0 |
MEDIUM
|
kaf_oseo
|
quick_and_dirty_phpsource_printer
|
Directory traversal vulnerability in source.php in Quick & Dirty PHPSource Printer 1.1 and earlier allows remote attackers to read arbitrary files via ".../...//" sequences in the file parameter, whi…
|
NVD-CWE-Other
|
CVE-2005-2169
|
2008-09-6 05:51 |
2005-07-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357917
|
5.0 |
MEDIUM
|
mozilla
|
bugzilla
|
The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to…
|
NVD-CWE-Other
|
CVE-2005-2173
|
2008-09-6 05:51 |
2005-07-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357918
|
2.6 |
LOW
|
mozilla
|
bugzilla
|
Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access info…
|
NVD-CWE-Other
|
CVE-2005-2174
|
2008-09-6 05:51 |
2005-07-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357919
|
5.0 |
MEDIUM
|
ibm
|
lotus_notes
|
The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based att…
|
NVD-CWE-Other
|
CVE-2005-2175
|
2008-09-6 05:51 |
2005-07-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357920
|
2.1 |
LOW
|
apple
|
airport_card
|
The Apple AirPort card uses a default WEP key when not connected to a known or trusted network, which can cause it to automatically connect to a malicious network.
|
NVD-CWE-Other
|
CVE-2005-2196
|
2008-09-6 05:51 |
2005-07-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357921
|
7.5 |
HIGH
|
spid
|
spid
|
PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary code via the lang_path parameter.
|
NVD-CWE-Other
|
CVE-2005-2198
|
2008-09-6 05:51 |
2005-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357922
|
7.5 |
HIGH
|
skrypty
|
ppa_gallery
|
PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via the config[ppa_root_path] variable.
|
NVD-CWE-Other
|
CVE-2005-2199
|
2008-09-6 05:51 |
2005-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357923
|
7.5 |
HIGH
|
xerox
|
workcentre_2128 workcentre_2636 workcentre_3545
|
Multiple unknown vulnerabilities in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to bypass authentication.
|
NVD-CWE-Other
|
CVE-2005-2200
|
2008-09-6 05:51 |
2005-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357924
|
6.4 |
MEDIUM
|
xerox
|
workcentre_2128 workcentre_2636 workcentre_3545
|
Unknown vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to cause a denial of service or acc…
|
NVD-CWE-Other
|
CVE-2005-2201
|
2008-09-6 05:51 |
2005-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357925
|
4.3 |
MEDIUM
|
xerox
|
workcentre_2128 workcentre_2636 workcentre_3545
|
Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to injec…
|
NVD-CWE-Other
|
CVE-2005-2202
|
2008-09-6 05:51 |
2005-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357926
|
7.5 |
HIGH
|
phpwishlist
|
phpwishlist
|
login.php in phpWishlist before 0.1.15 allows remote attackers to bypass authentication via a direct request to admin.php.
|
NVD-CWE-Other
|
CVE-2005-2203
|
2008-09-6 05:51 |
2005-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357927
|
7.5 |
HIGH
|
pngren
|
pngren
|
The ReadLog function in kaiseki.cgi in pngren allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.
|
NVD-CWE-Other
|
CVE-2005-2205
|
2008-09-6 05:51 |
2005-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357928
|
7.5 |
HIGH
|
elemental_software
|
cartwiz
|
Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp,…
|
NVD-CWE-Other
|
CVE-2005-2206
|
2008-09-6 05:51 |
2005-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357929
|
4.3 |
MEDIUM
|
elemental_software
|
cartwiz
|
Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.
|
NVD-CWE-Other
|
CVE-2005-2207
|
2008-09-6 05:51 |
2005-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357930
|
5.0 |
MEDIUM
|
privashare
|
privashare
|
PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message.
|
NVD-CWE-Other
|
CVE-2005-2208
|
2008-09-6 05:51 |
2005-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357931
|
4.6 |
MEDIUM
|
sukria
|
backup_manager
|
Backup Manager 0.5.8a creates temporary files insecurely, which allows local users to conduct unauthorized file operations when a user is burning a CDR.
|
NVD-CWE-Other
|
CVE-2005-2211
|
2008-09-6 05:51 |
2005-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357932
|
6.4 |
MEDIUM
|
sukria
|
backup_manager
|
Backup Manager 0.5.8a creates an archive repository with world readable and writable permissions, which allows attackers to modify or read the repository.
|
NVD-CWE-Other
|
CVE-2005-2212
|
2008-09-6 05:51 |
2005-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357933
|
4.6 |
MEDIUM
|
debian
|
apt-setup
|
apt-setup in Debian GNU/Linux installs the apt.conf file with insecure permissions, which allows local users to obtain sensitive information such as passwords.
|
NVD-CWE-Other
|
CVE-2005-2214
|
2008-09-6 05:51 |
2005-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357934
|
4.3 |
MEDIUM
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.x before 1.4.6 and 1.5 before 1.5beta3 allows remote attackers to inject arbitrary web script or HTML via a parameter in the page move…
|
NVD-CWE-Other
|
CVE-2005-2215
|
2008-09-6 05:51 |
2005-07-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357935
|
7.5 |
HIGH
|
photogal
|
photogal_photo_gallery
|
PHP remote file inclusion vulnerability in gals.php in PhotoGal Photo Gallery 1.5 and earlier allows remote attackers to execute arbitrary code via the news_file parameter.
|
NVD-CWE-Other
|
CVE-2005-2216
|
2008-09-6 05:51 |
2005-07-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357936
|
5.0 |
MEDIUM
|
craig_dansie
|
dansie_shopping_cart
|
Dansie Shopping Cart stores the vars.dat file under the web root with insufficient access control, which might allow remote attackers to obtain sensitive information such as program variables.
|
NVD-CWE-Other
|
CVE-2005-2217
|
2008-09-6 05:51 |
2005-07-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357937
|
4.6 |
MEDIUM
|
hosting_controller
|
hosting_controller
|
Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the C…
|
NVD-CWE-Other
|
CVE-2005-2219
|
2008-09-6 05:51 |
2005-07-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357938
|
10.0 |
HIGH
|
mailenable
|
mailenable_professional
|
Unknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2005-2222
|
2008-09-6 05:51 |
2005-07-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357939
|
5.0 |
MEDIUM
|
mailenable
|
mailenable_professional mailenable_standard
|
Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authentication.
|
NVD-CWE-Other
|
CVE-2005-2223
|
2008-09-6 05:51 |
2005-07-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357940
|
5.0 |
MEDIUM
|
microsoft
|
outlook_express
|
Microsoft Outlook Express 6.0 leaks the default news server account when a user responds to a "watched" conversation thread, which could allow remote attackers to obtain sensitive information.
|
NVD-CWE-Other
|
CVE-2005-2226
|
2008-09-6 05:51 |
2005-07-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357941
|
5.0 |
MEDIUM
|
bdc_enterprises
|
web_wiz_forums
|
Web Wiz Forums 7.9 and 8.0 allows remote attackers to view message titles of a hidden forum.
|
NVD-CWE-Other
|
CVE-2005-2228
|
2008-09-6 05:51 |
2005-07-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357942
|
2.1 |
LOW
|
elmo
|
elmo
|
Electronic Mail Operator (elmo) 1.3.2-r1 and earlier creates the elmostats temporary file insecurely, which allows local users to overwrite arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-2230
|
2008-09-6 05:51 |
2005-07-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357943
|
2.1 |
LOW
|
high_availability_linux_project
|
heartbeat
|
High Availability Linux Project Heartbeat 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2005-2231
|
2008-09-6 05:51 |
2005-07-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357944
|
4.6 |
MEDIUM
|
ibm
|
aix
|
Buffer overflow in invscout in IBM AIX 5.1.0 through 5.3.0 might allow local users to execute arbitrary code via a long command line argument.
|
NVD-CWE-Other
|
CVE-2005-2232
|
2008-09-6 05:51 |
2005-07-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357945
|
7.2 |
HIGH
|
ibm
|
aix
|
Buffer overflow in multiple "p" commands in IBM AIX 5.1, 5.2 and 5.3 might allow local users to execute arbitrary code via long command line arguments to (1) penable or other hard-linked files includ…
|
NVD-CWE-Other
|
CVE-2005-2233
|
2008-09-6 05:51 |
2005-07-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357946
|
7.2 |
HIGH
|
-
|
-
|
Buffer overflow in the getlvname command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.
|
NVD-CWE-Other
|
CVE-2005-2234
|
2008-09-6 05:51 |
2005-07-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357947
|
7.2 |
HIGH
|
ibm
|
aix
|
Buffer overflow in the diagTasksWebSM command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.
|
NVD-CWE-Other
|
CVE-2005-2235
|
2008-09-6 05:51 |
2005-07-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357948
|
7.2 |
HIGH
|
ibm
|
aix
|
Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via format strings in command line arguments.
|
NVD-CWE-Other
|
CVE-2005-2236
|
2008-09-6 05:51 |
2005-07-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357949
|
7.2 |
HIGH
|
-
|
-
|
Format string vulnerability in the swcons command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via long command line arguments.
|
NVD-CWE-Other
|
CVE-2005-2237
|
2008-09-6 05:51 |
2005-07-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357950
|
2.1 |
LOW
|
ibm
|
aix
|
ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.
|
NVD-CWE-Other
|
CVE-2005-2238
|
2008-09-6 05:51 |
2005-07-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|