Total
27865 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-3743 | 1 Simplepoll | 1 Simplepoll | 2008-09-05 | 7.5 HIGH | N/A |
SQL injection vulnerability in results.php in SimplePoll allows remote attackers to execute arbitrary SQL commands via the pollid parameter. | |||||
CVE-2005-3751 | 1 Apsis | 1 Pound | 2008-09-05 | 4.3 MEDIUM | N/A |
HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with conflicting Content-length and Transfer-encoding headers. | |||||
CVE-2005-3752 | 1 Ldapdiff | 1 Ldapdiff | 2008-09-05 | 10.0 HIGH | N/A |
Unspecified vulnerability in ldapdiff before 1.1.1 has unknown impact and attack vectors, related to "ldapdiff.conf path construction". | |||||
CVE-2005-3753 | 1 Linux | 1 Linux Kernel | 2008-09-05 | 7.8 HIGH | N/A |
Linux kernel before after 2.6.12 and before 2.6.13.1 might allow attackers to cause a denial of service (Oops) via certain IPSec packets that cause alignment problems in standard multi-block cipher processors. NOTE: it is not clear whether this issue can be triggered by an attacker. | |||||
CVE-2005-3761 | 1 Exponent | 1 Exponent | 2008-09-05 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Exponent CMS 0.96.3 and later versions allows remote attackers to inject arbitrary web script or HTML via (1) Javascript in forms produced by the form generator or (2) the parameters to the installer. | |||||
CVE-2005-3763 | 1 Exponent | 1 Exponent | 2008-09-05 | 5.0 MEDIUM | N/A |
Exponent CMS 0.96.3 and later versions includes the full installation path in the base parameter to thumb.php, which allows remote attackers to obtain sensitive information. NOTE: this might be resultant from an absolute path traversal vulnerability. | |||||
CVE-2005-3764 | 1 Exponent | 1 Exponent | 2008-09-05 | 10.0 HIGH | N/A |
The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files, with unknown impact from the preview icon, possibly involving injection of HTML. | |||||
CVE-2005-3765 | 1 Exponent | 1 Exponent | 2008-09-05 | 7.5 HIGH | N/A |
Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to execute arbitrary code. | |||||
CVE-2005-3766 | 1 Exponent | 1 Exponent | 2008-09-05 | 5.0 MEDIUM | N/A |
Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though certain permissions are specified, which allows attackers to access the pages by browsing uploaded files. | |||||
CVE-2005-3769 | 1 Php Download Manager | 1 Php Download Manager | 2008-09-05 | 7.5 HIGH | N/A |
SQL injection vulnerability in files.php in PHP Download Manager 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |||||
CVE-2005-3778 | 1 Mybulletinboard | 1 Mybulletinboard | 2008-09-05 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in MyBulletinBoard (MyBB) before 1.0 PR2 Rev 686 allows attackers to cause a denial of service via unknown vectors. | |||||
CVE-2005-3782 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2008-09-05 | 2.1 LOW | N/A |
Mac OS X 10.4.3 up to 10.4.6, when loginwindow uses the "Name and password" setting, and the "Show the Restart, Sleep, and Shut Down buttons" option is disabled, allows users with physical access to bypass login and reboot the system by entering ">restart", ">power", or ">shutdown" sequences after the username. | |||||
CVE-2005-3854 | 1 Easypagecms | 1 Easypagecms | 2008-09-05 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in EasyPageCMS allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | |||||
CVE-2005-3856 | 1 Krusader | 1 Krusader | 2008-09-05 | 4.0 MEDIUM | N/A |
The Popular URL capability (popularurls.cpp) in Krusader 1.60.0 and 1.70.0-beta1 saves passwords in cleartext in the krusaderrc file when the user enters URLs containing passwords in the panel URL field, which might allow attackers to access other sites. | |||||
CVE-2005-3919 | 1 Pblang | 1 Pblang | 2008-09-05 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in PBLang 4.65 allows remote attackers to inject arbitrary web script or HTML via multiple fields in (1) UCP.php and (2) SendPm.php. | |||||
CVE-2005-3957 | 1 Dotclear | 1 Dotclear | 2008-09-05 | 10.0 HIGH | N/A |
Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors. | |||||
CVE-2005-3987 | 1 Tradesoft | 1 Tradesoft Cms | 2008-09-05 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Tradesoft CMS allow remote attackers to execute arbitrary SQL commands via unspecified attack vectors. | |||||
CVE-2005-3992 | 1 Wineggdropshell | 1 Wineggdropshell | 2008-09-05 | 7.5 HIGH | N/A |
Multiple buffer overflows in WinEggDropShell remote access trojan (RAT) 1.7 allow remote attackers to execute arbitrary code via (1) a long GET request to the HTTP server, or a long (2) USER or (3) PASS command to the FTP server. | |||||
CVE-2005-4002 | 1 Esi Products | 1 Webeoc | 2008-09-05 | 4.0 MEDIUM | N/A |
WebEOC before 6.0.2 uses the same secret key for all installations, which allows attackers with the key to decrypt data from any WebEOC installation. | |||||
CVE-2005-4025 | 1 Help Desk Reloaded | 1 Free Help Desk | 2008-09-05 | 7.5 HIGH | N/A |
Help Desk Reloaded Free Help Desk does not remove or protect install.php once installation is complete, which allows remote attackers to gain privileges via a direct request to install.php, then navigating to accountsetup.php and creating a new user. |