Total
27865 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-4772 | 1 Suse | 5 Suse Linux, Suse Linux Openexchange Server, Suse Linux School Server and 2 more | 2008-09-05 | 6.4 MEDIUM | N/A |
liby2util in Yet another Setup Tool (YaST) in SUSE Linux before 20051007 preserves permissions and ownerships when copying a remote repository, which might allow local users to read or modify sensitive files, possibly giving local users the ability to exploit CVE-2005-3013. | |||||
CVE-2005-4787 | 1 Turnkey Solutions | 1 Sunshop Shopping Cart | 2008-09-05 | 5.0 MEDIUM | N/A |
** DISPUTED ** Turnkey Web Tools SunShop Shopping Cart allows remote attackers to obtain sensitive information via a phpinfo action to (1) index.php, (2) admin/index.php, and (3) admin/adminindex.php, which executes the PHP phpinfo function. NOTE: The vendor has disputed this issue, saying that "Having this in the code makes it easier for us to troubleshoot when issues arise on individual carts. For someone to have a script to do this type of search would require that they know where your shop is actually located. I dont think it really can be construde [sic] as a security issue." | |||||
CVE-2005-4578 | 1 Hitachi | 1 Business Logic | 2008-09-05 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Hitachi Business Logic - Container (BLC) P-2443-9114 01-00 through 02-06 on Windows, and P-1M43-9111 01-01 through 02-00 on AIX, allow remote attackers to execute arbitrary SQL commands via unknown attack vectors in an unspecified input form. | |||||
CVE-2005-4818 | 1 Copernicus | 1 Europa | 2008-09-05 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Copernicus Europa allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2005-4816 | 1 Proftpd Project | 1 Proftpd | 2008-09-05 | 7.5 HIGH | N/A |
Buffer overflow in mod_radius in ProFTPD before 1.3.0rc2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password. | |||||
CVE-2005-4821 | 1 Neocrome | 1 Land Down Under | 2008-09-05 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Land Down Under (LDU) v801 and earlier allow remote attackers to execute arbitrary SQL commands via parameters including (1) the m parameter in auth.php, (2) the f parameter in events.php, or (3) the e parameter in plug.php. | |||||
CVE-2005-4824 | 1 Glen Campbell | 1 Siteframe | 2008-09-05 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in web/classes.php in Siteframe before 3.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the LOCAL_PATH parameter, a different vulnerability than CVE-2005-1965. | |||||
CVE-2005-4839 | 1 Claymore Systems Inc | 1 Puretls | 2008-09-05 | 5.0 MEDIUM | N/A |
PureTLS before 0.9b5 does not clear optional Extensions and Algorithm.Parameters values before parsing, which might trigger an information leak of values from earlier certificates. | |||||
CVE-2005-4155 | 1 Adaptive Technology Resource Centre | 1 Atutor | 2008-09-05 | 7.5 HIGH | N/A |
registration.PHP in ATutor 1.5.1 pl2 allows remote attackers to execute arbitrary SQL commands via an e-mail address that ends in a NULL character, which bypasses the PHP regular expression check. NOTE: it is possible that this is actually a bug in PHP code, in which case this should not be treated as a vulnerability in ATutor. | |||||
CVE-2005-4156 | 1 Mambo | 1 Mambo Open Source 4.5 | 2008-09-05 | 9.4 HIGH | N/A |
Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrary files and possibly cause a denial of service via a query string that ends with a NULL character. | |||||
CVE-2005-4266 | 1 Alt-n | 2 Mdaemon, Worldclient | 2008-09-05 | 7.5 HIGH | N/A |
WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the random value. | |||||
CVE-2005-4412 | 1 Citrix | 1 Program Neighborhood Client | 2008-09-05 | 2.1 LOW | N/A |
Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the session to obtain the password by using a tool to directly access the field. | |||||
CVE-2005-4415 | 1 Tml | 1 Tml | 2008-09-05 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in TML CMS 0.5 allows remote attackers to inject arbitrary web script or HTML via the form parameter. | |||||
CVE-2005-4416 | 1 Tml | 1 Tml | 2008-09-05 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in TML CMS 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2005-4404 | 1 Media2 Cms | 1 Media2 Cms Shop | 2008-09-05 | 7.5 HIGH | N/A |
SQL injection vulnerability in default.asp in Media2 CMS Shop 18.x allows remote attackers to execute arbitrary SQL commands via the item parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources. | |||||
CVE-2005-4443 | 1 Gauche | 1 Gauche | 2008-09-05 | 7.2 HIGH | N/A |
Untrusted search path vulnerability in Gauche before 0.8.6-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH. | |||||
CVE-2005-4423 | 1 Phpfm | 1 Phpfm | 2008-09-05 | 6.5 MEDIUM | N/A |
Unrestricted file upload vulnerability in PHPFM before 0.2.3 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension to an accessible directory, as demonstrated using a file with a .php extension, aka "upload phpshell." | |||||
CVE-2005-4422 | 1 Toenda Software Development | 1 Toendacms | 2008-09-05 | 6.5 MEDIUM | N/A |
Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in data/images/albums. | |||||
CVE-2005-4334 | 1 John Andersson | 1 Zixforum | 2008-09-05 | 7.5 HIGH | N/A |
SQL injection vulnerability in ZixForum 1.12 allows remote attackers to execute arbitrary SQL commands via the H_ID parameter to (1) zixforum/forum.asp, as used in (2) Headforums.asp and (3) Subject.asp. | |||||
CVE-2005-4337 | 1 Blackboard | 1 Academic Suite | 2008-09-05 | 7.5 HIGH | N/A |
The login page in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to bypass authentication and gain privileges as other users via a modified user_id parameter and a "/" in the encoded_pw parameter. |