|
362401
|
6.5 |
MEDIUM
|
punbb
|
punbb
|
SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a change_email action.
|
NVD-CWE-Other
|
CVE-2005-1051
|
2016-10-18 12:16 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362402
|
10.0 |
HIGH
|
sun
|
j2se
|
Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06 allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file.
|
NVD-CWE-Other
|
CVE-2005-0836
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362403
|
4.3 |
MEDIUM
|
kayako
|
esupport
|
Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) _i or (2) _c parameter.
|
NVD-CWE-Other
|
CVE-2005-0842
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362404
|
5.0 |
MEDIUM
|
phorum
|
phorum
|
CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the body parameter, which is included in the resulting Location hea…
|
NVD-CWE-Other
|
CVE-2005-0843
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362405
|
5.0 |
MEDIUM
|
-
|
-
|
Directory traversal vulnerability in the Webmail interface in SurgeMail 2.2g3 allows remote authenticated users to write arbitrary files or directories via a .. (dot dot) in the attach_id parameter.
|
NVD-CWE-Other
|
CVE-2005-0845
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362406
|
4.3 |
MEDIUM
|
netwin
|
surgemail
|
Multiple cross-site scripting (XSS) vulnerabilities in the email auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject arbitrary web script or HTML via the (1) message subject or (2)…
|
NVD-CWE-Other
|
CVE-2005-0846
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362407
|
7.5 |
HIGH
|
bosanova ibm mochasoft powerterm
|
launcher400 client_access tn5250 interconnect
|
AS/400 Telnet 5250 terminal emulation clients, as implemented by (1) IBM client access, (2) Bosanova, (3) PowerTerm, (4) Mochasoft, and possibly other emulations, allows malicious AS/400 servers to e…
|
NVD-CWE-Other
|
CVE-2005-0868
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362408
|
4.3 |
MEDIUM
|
oracle
|
10g_reports_server
|
Multiple cross-site scripting (XSS) vulnerabilities in test.jsp in Oracle Reports Server 10g (9.0.4.3.3) allow remote attackers to inject arbitrary web script or HTML via the (1) desname or (2) reppr…
|
NVD-CWE-Other
|
CVE-2005-0873
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362409
|
5.0 |
MEDIUM
|
cerulean_studios
|
trillian
|
Multiple buffer overflows in the (1) AIM, (2) MSN, (3) RSS, and other plug-ins for Trillian 2.0 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP …
|
NVD-CWE-Other
|
CVE-2005-0874
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362410
|
5.0 |
MEDIUM
|
cerulean_studios
|
trillian
|
Multiple buffer overflows in the Yahoo plug-in for Trillian 2.0, 3.0, and 3.1 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response heade…
|
NVD-CWE-Other
|
CVE-2005-0875
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362411
|
10.0 |
HIGH
|
smail
|
smail
|
Buffer overflow in smail 3.2.0.120 allows remote attackers or local users to execute arbitrary code via a long string in the MAIL FROM command and possibly other SMTP commands.
|
NVD-CWE-Other
|
CVE-2005-0892
|
2016-10-18 12:15 |
2005-03-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362412
|
7.6 |
HIGH
|
smail
|
smail
|
modes.c in smail 3.2.0.120 implements signal handlers with certain unsafe library calls, which may allow attackers to execute arbitrary code via signal handler race conditions, possibly using xmalloc.
|
NVD-CWE-Other
|
CVE-2005-0893
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362413
|
3.6 |
LOW
|
openmosixview
|
openmosixview
|
OpenmosixCollector and OpenMosixView in OpenMosixView 1.5 allow local users to overwrite or delete arbitrary files via a symlink attack on (1) temporary files in the openmosixcollector directory or (…
|
NVD-CWE-Other
|
CVE-2005-0894
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362414
|
5.0 |
MEDIUM
|
netcomm
|
nb1300
|
Netcomm 1300NB DSL Modem allows remote attackers to cause a denial of service (device hang) via a large number of ping packets.
|
NVD-CWE-Other
|
CVE-2005-0895
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362415
|
4.3 |
MEDIUM
|
accomplishtechnology
|
phpmydirectory
|
Multiple cross-site scripting (XSS) vulnerabilities in review.php in phpMyDirectory 10.1.3-rel allow remote attackers to inject arbitrary web script or HTML via the (1) subcat, (2) page, or (3) subsu…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2005-0896
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362416
|
7.5 |
HIGH
|
magicscripts
|
e-store_kit-2
|
PHP remote file inclusion vulnerability in catalog.php in E-Store Kit-2 PayPal Edition allows remote attackers to execute arbitrary PHP code by modifying the menu and main parameters to reference a U…
|
NVD-CWE-Other
|
CVE-2005-0897
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362417
|
4.3 |
MEDIUM
|
magicscripts
|
e-store_kit-2
|
Cross-site scripting (XSS) vulnerability in downloadform.php in E-Store Kit-2 PayPal Edition allows remote attackers to inject arbitrary web script or HTML via the txn_id parameter.
|
NVD-CWE-Other
|
CVE-2005-0898
|
2016-10-18 12:15 |
2005-03-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362418
|
2.1 |
LOW
|
ibm
|
os_400
|
AS/400 running OS400 5.2 installs and enables LDAP by default, which allows remote authenticated users to obtain OS/400 user profiles by performing a search.
|
NVD-CWE-Other
|
CVE-2005-0899
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362419
|
5.0 |
MEDIUM
|
nukebookmarks
|
nukebookmarks
|
marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to obtain sensitive information via an invalid (1) file or (2) category parameter, which reveal the path in an error message.
|
NVD-CWE-Other
|
CVE-2005-0900
|
2016-10-18 12:15 |
2005-03-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362420
|
4.3 |
MEDIUM
|
nukebookmarks
|
nukebookmarks
|
Multiple cross-site scripting (XSS) vulnerabilities in NukeBookmarks 0.6 for PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via the (1) catname, (2) markname, (3) comment, or …
|
NVD-CWE-Other
|
CVE-2005-0901
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362421
|
7.5 |
HIGH
|
nukebookmarks
|
nukebookmarks
|
SQL injection vulnerability in marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category parameter.
|
NVD-CWE-Other
|
CVE-2005-0902
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362422
|
2.6 |
LOW
|
apple
|
quicktime_pictureviewer
|
Buffer overflow in QuickTime PictureViewer 6.5.1 allows remote attackers to cause a denial of service (application crash) via a JPEG file with crafted Huffman Table (marker DHT) data.
|
NVD-CWE-Other
|
CVE-2005-0903
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362423
|
2.6 |
LOW
|
maxthon
|
maxthon
|
Maxthon 1.2.0 allows remote malicious web sites to obtain potentially sensitive data from the search bar via the m2_search_text property.
|
NVD-CWE-Other
|
CVE-2005-0905
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362424
|
7.5 |
HIGH
|
tkais_shoutbox
|
tkais_shoutbox
|
PHP remote file inclusion vulnerability in shoutact.php for TKai's Shoutbox allows remote attackers to execute arbitrary PHP code via the query parameter.
|
NVD-CWE-Other
|
CVE-2005-0909
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362425
|
4.3 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in login.asp for Ublog Reload 1.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
|
NVD-CWE-Other
|
CVE-2005-0925
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362426
|
4.3 |
MEDIUM
|
photopost
|
photopost_php_pro
|
Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 5.x allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) password, (3) ppuser, (4) sort, or (5) …
|
NVD-CWE-Other
|
CVE-2005-0928
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362427
|
7.5 |
HIGH
|
-
|
-
|
SQL injection vulnerability in PhotoPost PHP Pro 5.x may allow remote attackers to execute arbitrary SQL commands via (1) the sl parameter to showmembers.php or (2) the photo parameter to showphoto.p…
|
NVD-CWE-Other
|
CVE-2005-0929
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362428
|
7.5 |
HIGH
|
esmi
|
paypal_storefront
|
Multiple SQL injection vulnerabilities in ESMI PayPal Storefront allow remote attackers to execute arbitrary SQL commands via the (1) idpages parameter to pages.php or the (2) id2 parameter to produc…
|
NVD-CWE-Other
|
CVE-2005-0935
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362429
|
5.0 |
MEDIUM
|
esmi
|
paypal_storefront
|
Cross-site scripting vulnerability in products1h.php in ESMI PayPal Storefront allows remote attackers to inject arbitrary web script or HTML via the id parameter.
|
NVD-CWE-Other
|
CVE-2005-0936
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362430
|
5.0 |
MEDIUM
|
uapplication
|
ublog_reload
|
Ublog Reload 1.0 through 1.0.4 stores ublogreload.mdb under the web root, which allows remote attackers to read usernames and hashed passwords via a direct request to ublogreload.mdb.
|
NVD-CWE-Other
|
CVE-2005-0938
|
2016-10-18 12:15 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362431
|
7.5 |
HIGH
|
coinsoft_technologies
|
phpcoin
|
SQL injection vulnerability in phpCoin 1.2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the (1) term/keywords field on the search page, (2) username or (3) e-mail fiel…
|
NVD-CWE-Other
|
CVE-2005-0946
|
2016-10-18 12:15 |
2005-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362432
|
5.0 |
MEDIUM
|
experience2
|
experience2
|
eXPerience2 allows remote attackers to obtain the full path for the web root via a direct request to modules.php without any parameters, which leaks the path in a PHP error message.
|
NVD-CWE-Other
|
CVE-2005-0722
|
2016-10-18 12:14 |
2005-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362433
|
4.3 |
MEDIUM
|
php_arena
|
pafiledb
|
Cross-site scripting (XSS) vulnerability in the jumpmenu function in functions.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameters, …
|
NVD-CWE-Other
|
CVE-2005-0723
|
2016-10-18 12:14 |
2005-03-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362434
|
5.0 |
MEDIUM
|
php_arena
|
pafiledb
|
paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via (1) an invalid str parameter to pafiledb.php, or a direct request to (2) viewall.php, (3) stats.php, (4) search.ph…
|
NVD-CWE-Other
|
CVE-2005-0724
|
2016-10-18 12:14 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362435
|
7.5 |
HIGH
|
ubbcentral
|
ubb.threads
|
SQL injection vulnerability in editpost.php in UBB.threads 6.0 allows remote attackers to execute arbitrary SQL commands via the Number parameter.
|
NVD-CWE-Other
|
CVE-2005-0726
|
2016-10-18 12:14 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362436
|
7.5 |
HIGH
|
kde conectiva gentoo redhat ubuntu
|
quanta linux kde fedora_core ubuntu_linux
|
Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-0754
|
2016-10-18 12:14 |
2005-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362437
|
10.0 |
HIGH
|
goodtech_systems
|
goodtech_telnet_server
|
Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions before 5.0.7, allows remote attackers to execute arbitrary code via a long string to…
|
NVD-CWE-Other
|
CVE-2005-0768
|
2016-10-18 12:14 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362438
|
5.0 |
MEDIUM
|
php_arena
|
pafiledb
|
paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php, (4) file.php, (5) team.php, (6) license.php, (7…
|
NVD-CWE-Other
|
CVE-2005-0780
|
2016-10-18 12:14 |
2005-03-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362439
|
4.3 |
MEDIUM
|
phorum
|
phorum
|
Cross-site scripting (XSS) vulnerability in Phorum before 5.0.14a allows remote attackers to inject arbitrary web script or HTML via the filename of an attached file.
|
NVD-CWE-Other
|
CVE-2005-0783
|
2016-10-18 12:14 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362440
|
4.3 |
MEDIUM
|
phorum
|
phorum
|
Multiple cross-site scripting (XSS) vulnerabilities in Phorum before 5.0.15 allow remote attackers to inject arbitrary web script or HTML via (1) the subject line to follow.php or (2) the subject lin…
|
NVD-CWE-Other
|
CVE-2005-0784
|
2016-10-18 12:14 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362441
|
7.5 |
HIGH
|
zpanel
|
zpanel
|
PHP remote file inclusion vulnerability in zpanel.php in ZPanel allows remote attackers to (1) execute arbitrary PHP code in ZPanel 2.0 or (2) include local files in ZPanel 2.5 beta 10 and earlier by…
|
NVD-CWE-Other
|
CVE-2005-0793
|
2016-10-18 12:14 |
2005-03-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362442
|
5.0 |
MEDIUM
|
-
|
-
|
Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasse…
|
NVD-CWE-Other
|
CVE-2005-0796
|
2016-10-18 12:14 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362443
|
5.0 |
MEDIUM
|
-
|
-
|
Novell iChain Mini FTP Server 2.3 displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.
|
CWE-200
情報漏えい
|
CVE-2005-0797
|
2016-10-18 12:14 |
2005-03-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362444
|
7.5 |
HIGH
|
novell
|
ichain
|
Novell iChain Mini FTP Server 2.3, and possibly earlier versions, does not limit the number of incorrect logins, which makes it easier for remote attackers to conduct brute force login attacks.
|
NVD-CWE-Other
|
CVE-2005-0798
|
2016-10-18 12:14 |
2005-03-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362445
|
5.0 |
MEDIUM
|
includer.cgi
|
includer.cgi
|
Directory traversal vulnerability in includer.cgi in The Includer allows remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) a full pathname in the URL.
|
NVD-CWE-Other
|
CVE-2005-0801
|
2016-10-18 12:14 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362446
|
5.0 |
MEDIUM
|
mailenable
|
mailenable_standard
|
Format string vulnerability in MailEnable 1.8 allows remote attackers to cause a denial of service (application crash) via format string specifiers in the mailto field.
|
NVD-CWE-Other
|
CVE-2005-0804
|
2016-10-18 12:14 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362447
|
4.3 |
MEDIUM
|
php_fusion
|
php_fusion
|
Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitrary web script or HTML via the (1) user_name or (2) user_pas…
|
NVD-CWE-Other
|
CVE-2005-0829
|
2016-10-18 12:14 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362448
|
4.6 |
MEDIUM
|
gfi
|
languard_network_security_scanner
|
lnss.exe in GFI Languard Network Security Scanner 5.0 stores the username and password in memory in plaintext, which could allow local administrators to obtain domain administrator credentials.
|
NVD-CWE-Other
|
CVE-2005-0604
|
2016-10-18 12:13 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362449
|
7.5 |
HIGH
|
phpbb_group
|
phpbb
|
sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie.
|
NVD-CWE-Other
|
CVE-2005-0614
|
2016-10-18 12:13 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362450
|
7.5 |
HIGH
|
postnuke_software_foundation
|
postnuke
|
Multiple SQL injection vulnerabilities in (1) index.php, (2) modules.php, or (3) admin.php in PostNuke 0.760-RC2 allow remote attackers to execute arbitrary SQL code via the catid parameter.
|
NVD-CWE-Other
|
CVE-2005-0615
|
2016-10-18 12:13 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|