Total
27865 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-3939 | 1 Wsn Knowledge Base | 1 Wsn Knowledge Base | 2008-10-02 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in WSN Knowledge Base 1.2.0 and earler allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) perpage, (3) ascdesc, and (4) orderlinks in a displaycat action in (a) index.php; and the (5) id parameter in (b) comments.php and (c) memberlist.php. | |||||
CVE-2005-3948 | 1 Phpalbum.net | 1 Phpalbum | 2008-10-02 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in main.php in PHPAlbum 0.2.3 and earlier allows remote attackers to read arbitrary files via the (1) cmd and (2) var1 parameters. | |||||
CVE-2003-0317 | 1 Iisprotect | 1 Iisprotect | 2008-10-02 | 7.5 HIGH | N/A |
iisPROTECT 2.1 and 2.2 allows remote attackers to bypass authentication via an HTTP request containing URL-encoded characters. | |||||
CVE-2002-0470 | 1 Phpnettoolpack | 1 Phpnettoolpack | 2008-09-23 | 7.2 HIGH | N/A |
PHPNetToolpack 0.1 relies on its environment's PATH to find and execute the traceroute program, which could allow local users to gain privileges by inserting a Trojan horse program into the search path. | |||||
CVE-2002-0471 | 1 Phpnettoolpack | 1 Phpnettoolpack | 2008-09-23 | 10.0 HIGH | N/A |
PHPNetToolpack 0.1 allows remote attackers to execute arbitrary code via shell metacharacters in the a_query variable. | |||||
CVE-2000-0697 | 1 Sun | 1 Solaris Answerbook2 | 2008-09-23 | 10.0 HIGH | N/A |
The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters. | |||||
CVE-2005-4621 | 1 Jelsoft | 1 Vbulletin | 2008-09-19 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which the URL generates a parsing error, and possibly requiring a trailing extension such as .jpg. | |||||
CVE-2005-4408 | 1 Pc Media | 1 Miraserver | 2008-09-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Miraserver 1.0 RC4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) id parameter to newsitem.php, and (3) cat parameter to article.php. | |||||
CVE-2005-4407 | 1 Tmc Visionpool | 1 Mercury Cms | 2008-09-19 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) content and (2) criteria parameters. | |||||
CVE-2005-4406 | 1 Tmc Visionpool | 1 Mercury Cms | 2008-09-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. | |||||
CVE-2005-4781 | 1 Sergids | 1 Top Music Module | 2008-09-19 | 5.0 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in SergiDs Top Music module 3.0 PR3 and earlier for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the (1) idartist, (2) idsong, and (3) idalbum parameters to modules.php. | |||||
CVE-2005-4403 | 1 Qcm | 1 Marwel | 2008-09-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Marwel 2.7 and earlier allows remote attackers to execute arbitrary SQL commands via the show parameter. | |||||
CVE-2005-4475 | 1 Alkacon | 1 Opencms | 2008-09-19 | 6.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in OpenCms 6.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters. | |||||
CVE-2005-4477 | 1 Papaya | 1 Papaya Cms | 2008-09-19 | 6.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in papaya CMS 4.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the bab[searchfor] parameter. | |||||
CVE-2005-4631 | 1 Ryan Lath | 1 Zina | 2008-09-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Zina 0.12.07 and earlier allows remote attackers to execute arbitrary SQL commands via the p parameter. | |||||
CVE-2005-4743 | 1 Nelogic Technologies | 1 Nephp Publisher | 2008-09-19 | 5.0 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in index.php in NeLogic Nephp Publisher 4.5.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) nnet_catid parameters. | |||||
CVE-2005-4373 | 1 Liquid Bytes Technologies | 1 Adaptive Website Framework | 2008-09-19 | 5.0 MEDIUM | N/A |
Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to obtain the full path of the application via an invalid mode parameter to community.html, which leaks the path in an error message. | |||||
CVE-2005-4429 | 1 Cs-cart | 1 Cs-cart | 2008-09-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php. | |||||
CVE-2005-4480 | 1 Plexcor | 1 Plexcor Cms | 2008-09-19 | 6.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Plexcor CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters. | |||||
CVE-2005-4719 | 1 Sysbotz | 1 Systems Panel | 2008-09-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Sysbotz Systems Panel 1.0.6 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the cid parameter in knowledgebase/index.php, (2) the aid parameter in knowledgebase/view.php, (3) the cid parameter in contact/update.php, (4) the letter parameter in links/index.php, (5) the mid parameter in messageboard/view.php, and (6) the tid parameter in tickets/view.php. |