|
362451
|
4.3 |
MEDIUM
|
-
|
-
|
Multiple cross-site scripting (XSS) vulnerabilities in the Download module for PostNuke 0.750 and 0.760-RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) Program name, (2)…
|
NVD-CWE-Other
|
CVE-2005-0616
|
2016-10-18 12:13 |
2005-02-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362452
|
7.5 |
HIGH
|
postnuke_software_foundation
|
postnuke
|
SQL injection vulnerability in dl-search.php in PostNuke 0.750 and 0.760-RC2 allows remote attackers to execute arbitrary SQL commands via the show parameter.
|
NVD-CWE-Other
|
CVE-2005-0617
|
2016-10-18 12:13 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362453
|
5.0 |
MEDIUM
|
enlight_software
|
scrapland
|
Scrapland 1.0 and earlier allows remote attackers to cause a denial of service (server termination) by triggering an error, which is treated as a fatal error by the server, as demonstrated using (1) …
|
NVD-CWE-Other
|
CVE-2005-0621
|
2016-10-18 12:13 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362454
|
5.0 |
MEDIUM
|
raidenhttpd
|
raidenhttpd
|
RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to view the PHP source code via an HTTP GET request for a filename with a trailing (1) . (dot) or (2) space.
|
NVD-CWE-Other
|
CVE-2005-0622
|
2016-10-18 12:13 |
2005-03-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362455
|
7.5 |
HIGH
|
raidenhttpd
|
raidenhttpd
|
Buffer overflow in RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to execute arbitrary code via a long URL.
|
NVD-CWE-Other
|
CVE-2005-0623
|
2016-10-18 12:13 |
2005-03-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362456
|
4.3 |
MEDIUM
|
demof
|
forumwa
|
Multiple cross-site scripting (XSS) vulnerabilities in Forumwa 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in search.php or the (2) body or (3) sub…
|
NVD-CWE-Other
|
CVE-2005-0628
|
2016-10-18 12:13 |
2005-03-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362457
|
5.0 |
MEDIUM
|
phpnews
|
phpnews
|
PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter.
|
NVD-CWE-Other
|
CVE-2005-0632
|
2016-10-18 12:13 |
2005-03-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362458
|
7.5 |
HIGH
|
cerulean_studios
|
trillian trillian_pro
|
Buffer overflow in Trillian 3.0 and Pro 3.0 allows remote attackers to execute arbitrary code via a crafted PNG image file.
|
NVD-CWE-Other
|
CVE-2005-0633
|
2016-10-18 12:13 |
2005-03-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362459
|
4.3 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in show.inc.php in cuteNews 1.3.6 allows remote attackers to inject arbitrary HTML, web script, and PHP code via the (1) CLIENT-IP or (2) X-FORWARDED-FOR head…
|
NVD-CWE-Other
|
CVE-2005-0645
|
2016-10-18 12:13 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362460
|
7.5 |
HIGH
|
php_arena
|
panews
|
SQL injection vulnerability in auth.php in paNews 2.0.4b allows remote attackers to execute arbitrary SQL via the mysql_prefix parameter.
|
NVD-CWE-Other
|
CVE-2005-0646
|
2016-10-18 12:13 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362461
|
5.0 |
MEDIUM
|
php_arena
|
panews
|
admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2) $form[autoapprove] parameters, which are written to config.php.
|
NVD-CWE-Other
|
CVE-2005-0647
|
2016-10-18 12:13 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362462
|
5.0 |
MEDIUM
|
arif_supriyanto
|
auracms
|
auraCMS 1.5 allows remote attackers to obtain sensitive information via an HTTP request with an invalid id parameter to (1) teman.php, (2) hal.php, or (3) arsip.php, which reveals the path in a PHP e…
|
NVD-CWE-Other
|
CVE-2005-0655
|
2016-10-18 12:13 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362463
|
4.3 |
MEDIUM
|
arif_supriyanto
|
auracms
|
Multiple cross-site scripting (XSS) vulnerabilities in auraCMS 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) hits parameter to hits.php, (2) query parameter to index.p…
|
NVD-CWE-Other
|
CVE-2005-0656
|
2016-10-18 12:13 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362464
|
7.5 |
HIGH
|
cmw_linklist
|
cmw_linklist
|
SQL injection vulnerability in a third party extension to TYPO3 allows remote attackers to execute arbitrary SQL commands via the category_uid parameter.
|
NVD-CWE-Other
|
CVE-2005-0658
|
2016-10-18 12:13 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362465
|
5.0 |
MEDIUM
|
phpbb_group
|
phpbb
|
phpBB 2.0.13 and earlier allows remote attackers to obtain sensitive information via a direct request to oracle.php, which reveals the path in a PHP error message.
|
NVD-CWE-Other
|
CVE-2005-0659
|
2016-10-18 12:13 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362466
|
4.3 |
MEDIUM
|
php_arena
|
pabox
|
Cross-site scripting (XSS) vulnerability in the News module for paBox 1.6 allows remote attackers to inject arbitrary web script or HTML via the text hidden parameter in an HTTP POST request.
|
NVD-CWE-Other
|
CVE-2005-0674
|
2016-10-18 12:13 |
2005-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362467
|
7.5 |
HIGH
|
stadtaus
|
form_mail_script
|
PHP remote file inclusion vulnerability in formmail.inc.php for Form Mail Script 2.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the script_root to reference a URL …
|
NVD-CWE-Other
|
CVE-2005-0678
|
2016-10-18 12:13 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362468
|
7.5 |
HIGH
|
-
|
-
|
PHP remote file inclusion vulnerability in download_center_lite.inc.php for Download Center Lite 1.6 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to re…
|
NVD-CWE-Other
|
CVE-2005-0680
|
2016-10-18 12:13 |
2005-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362469
|
7.5 |
HIGH
|
jimmy
|
the_includer
|
includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the URL or (2) the template parameter.
|
NVD-CWE-Other
|
CVE-2005-0689
|
2016-10-18 12:13 |
2005-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362470
|
2.1 |
LOW
|
gene6
|
g6_ftp_server
|
Gene6 FTP Server does not properly restrict access to the control console, which allows local users to modify the server configuration and gain privileges, as demonstrated by defining a SITE command.
|
NVD-CWE-Other
|
CVE-2005-0690
|
2016-10-18 12:13 |
2005-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362471
|
7.5 |
HIGH
|
socialmpn
|
socialmpn
|
PHP remote file inclusion vulnerability in article mode for modules.php in SocialMPN allows remote attackers to execute arbitrary PHP code by modifying the name parameter to reference a URL on a remo…
|
NVD-CWE-Other
|
CVE-2005-0691
|
2016-10-18 12:13 |
2005-03-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362472
|
4.3 |
MEDIUM
|
php_fusion
|
php_fusion
|
Cross-site scripting (XSS) vulnerability in fusion_core.php for PHP-Fusion 5.x allows remote attackers to inject arbitrary web script or HTML via a message with IMG bbcode containing character-encode…
|
NVD-CWE-Other
|
CVE-2005-0692
|
2016-10-18 12:13 |
2005-03-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362473
|
5.0 |
MEDIUM
|
hosting_controller
|
hosting_controller
|
Hosting Controller 6.1 Hotfix 1.7 and earlier stores log files under the web root, which allows remote attackers to obtain sensitive information via a direct request to HCDiskQuotaService.csv.
|
NVD-CWE-Other
|
CVE-2005-0694
|
2016-10-18 12:13 |
2005-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362474
|
5.0 |
MEDIUM
|
hosting_controller
|
hosting_controller
|
The password recovery feature (forgotpassword.asp) in Hosting Controller 6.1 Hotfix 1.7 and earlier allows remote attackers to determine the owner's e-mail address by providing a portion of the domai…
|
NVD-CWE-Other
|
CVE-2005-0695
|
2016-10-18 12:13 |
2005-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362475
|
5.0 |
MEDIUM
|
oracle
|
database_server
|
Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via "\\.\\.." (modified dot dot backslash) sequences to UTL_FILE funct…
|
NVD-CWE-Other
|
CVE-2005-0701
|
2016-10-18 12:13 |
2005-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362476
|
7.5 |
HIGH
|
gamearena
|
experience2
|
PHP remote file inclusion vulnerability in modules.php in eXPerience2 allows remote attackers to execute arbitrary PHP code by modifying the file parameter to reference a URL on a remote web server t…
|
NVD-CWE-Other
|
CVE-2005-0721
|
2016-10-18 12:13 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362477
|
5.0 |
MEDIUM
|
seth_m._knorr
|
biz_mail_form
|
CRLF injection vulnerability in bizmail.cgi in Biz Mail Form before 2.2 allows remote attackers to bypass the email check and send spam e-mail via CRLF sequences and forged mail headers in the email …
|
NVD-CWE-Other
|
CVE-2005-0493
|
2016-10-18 12:12 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362478
|
5.0 |
MEDIUM
|
seth_m._knorr
|
biz_mail_form
|
Upgrade to newest version.
|
NVD-CWE-Other
|
CVE-2005-0493
|
2016-10-18 12:12 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362479
|
5.0 |
MEDIUM
|
avaya
|
ip_office_phone_manager ip_soft_phone
|
The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key, which allows local and possibly remote users to steal usernames a…
|
NVD-CWE-Other
|
CVE-2005-0506
|
2016-10-18 12:12 |
2005-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362480
|
5.0 |
MEDIUM
|
gd_software
|
sd_server
|
Directory traversal vulnerability in SD Server 4.0.70 and earlier allows remote attackers to read arbitrary files via .. sequences in an HTTP request.
|
NVD-CWE-Other
|
CVE-2005-0507
|
2016-10-18 12:12 |
2005-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362481
|
4.3 |
MEDIUM
|
microsoft mono
|
.net_framework mono
|
Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for AS…
|
NVD-CWE-Other
|
CVE-2005-0509
|
2016-10-18 12:12 |
2005-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362482
|
7.5 |
HIGH
|
jelsoft
|
vbulletin
|
misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.
|
NVD-CWE-Other
|
CVE-2005-0511
|
2016-10-18 12:12 |
2005-02-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362483
|
7.5 |
HIGH
|
pmachine
|
pmachine_pro
|
PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions including pMachine Free, allows remote attackers to exec…
|
NVD-CWE-Other
|
CVE-2005-0513
|
2016-10-18 12:12 |
2005-02-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362484
|
7.5 |
HIGH
|
twiki
|
imagegalleryplugin
|
The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that generate thumbnails.
|
NVD-CWE-Other
|
CVE-2005-0516
|
2016-10-18 12:12 |
2005-02-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362485
|
4.3 |
MEDIUM
|
pblang
|
pblang
|
Multiple cross-site scripting (XSS) vulnerabilities in PBLang 4.65 allow remote attackers to inject arbitrary web script or HTML via (1) the search string to search.php, (2) the subject of a PM, whic…
|
NVD-CWE-Other
|
CVE-2005-0526
|
2016-10-18 12:12 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362486
|
7.5 |
HIGH
|
igeneric
|
free_shopping_cart
|
Multiple SQL injection vulnerabilities in page.php for iGeneric (iG) Shop 1.2 may allow remote attackers to execute arbitrary SQL statements via the (1) cats, (2) l_price, or (3) u_price parameters.
|
NVD-CWE-Other
|
CVE-2005-0537
|
2016-10-18 12:12 |
2005-02-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362487
|
5.0 |
MEDIUM
|
cyclades
|
alterpath_manager
|
Cyclades AlterPath Manager (APM) Console Server 1.2.1 allows remote attackers to obtain sensitive information via a direct request to the /about.html page.
|
NVD-CWE-Other
|
CVE-2005-0540
|
2016-10-18 12:12 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362488
|
7.5 |
HIGH
|
cyclades
|
alterpath_manager
|
consoleConnect.jsp in Cyclades AlterPath Manager (APM) Console Server 1.2.1 allows remote attackers to connect to arbitrary consoles by modifying the consolename parameter.
|
NVD-CWE-Other
|
CVE-2005-0541
|
2016-10-18 12:12 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362489
|
4.6 |
MEDIUM
|
cyclades
|
alterpath_manager
|
saveUser.do in Cyclades AlterPath Manager (APM) Console Server 1.2.1 allows local users to gain privileges by setting the adminUser parameter to true.
|
NVD-CWE-Other
|
CVE-2005-0542
|
2016-10-18 12:12 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362490
|
4.3 |
MEDIUM
|
sun
|
solaris_answerbook2
|
Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search function.
|
NVD-CWE-Other
|
CVE-2005-0548
|
2016-10-18 12:12 |
2005-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362491
|
4.3 |
MEDIUM
|
sun
|
solaris_answerbook2
|
Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the "View Log Files" function.
|
NVD-CWE-Other
|
CVE-2005-0549
|
2016-10-18 12:12 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362492
|
5.0 |
MEDIUM
|
raven_software
|
soldier_of_fortune_2
|
Soldier of Fortune II 1.03 gold allows remote attackers to cause a denial of service (application crash) via a large cl_guid value, which results in an invalid pointer dereference.
|
NVD-CWE-Other
|
CVE-2005-0568
|
2016-10-18 12:12 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362493
|
5.0 |
MEDIUM
|
rob_flynn
|
gaim
|
Gaim 1.1.3 on Windows systems allows remote attackers to cause a denial of service (client crash) via a file transfer in which the filename contains "(" or ")" (parenthesis) characters.
|
NVD-CWE-Other
|
CVE-2005-0573
|
2016-10-18 12:12 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362494
|
7.5 |
HIGH
|
stormy_studios
|
knet
|
Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP GET request.
|
NVD-CWE-Other
|
CVE-2005-0575
|
2016-10-18 12:12 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362495
|
6.2 |
MEDIUM
|
info-zip
|
unzip
|
Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-0602
|
2016-10-18 12:12 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362496
|
4.6 |
MEDIUM
|
argosoft
|
argosoft_mail_server
|
Multiple directory traversal vulnerabilities in ArGoSoft Mail Server 1.8.7.3 allow remote authenticated users to read, delete, or upload arbitrary files via a .. (dot dot) in (1) the filename of an e…
|
NVD-CWE-Other
|
CVE-2005-0367
|
2016-10-18 12:11 |
2005-02-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362497
|
5.0 |
MEDIUM
|
armagetron
|
armagetron armagetron_advanced
|
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (network disconnection) via an empty UDP packet, which is not properly d…
|
NVD-CWE-Other
|
CVE-2005-0370
|
2016-10-18 12:11 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362498
|
5.0 |
MEDIUM
|
armagetron
|
armagetron armagetron_advanced
|
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (freeze) via a large number of player connections that do not send any d…
|
NVD-CWE-Other
|
CVE-2005-0371
|
2016-10-18 12:11 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362499
|
10.0 |
HIGH
|
ibm
|
db2_universal_database
|
Unknown "high risk" vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and attack vectors. NOTE: due to the delayed disclosure of details for this issue, this candidate may b…
|
NVD-CWE-Other
|
CVE-2005-0417
|
2016-10-18 12:11 |
2005-04-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362500
|
5.0 |
MEDIUM
|
jelsoft
|
vbulletin
|
Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma …
|
NVD-CWE-Other
|
CVE-2005-0429
|
2016-10-18 12:11 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|