Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-3868 | 1 Turn-k | 1 K-search | 2011-03-07 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in K-Search 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term, (2) id, (3) stat, and (4) source parameters to index.php, and (5) through the image parameters with an add request. | |||||
CVE-2005-3870 | 1 Edmobbs | 1 Edmobbs | 2011-03-07 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in edmobbs9r.php in edmoBBS 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) table and (2) messageID parameters. | |||||
CVE-2005-3871 | 1 Jbb | 1 Jbb | 2011-03-07 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Joels Bulletin board (JBB) 0.9.9rc3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) nr parameter in topiczeigen.php, (2) forum and (3) zeigeseite parameters in showforum.php, (4) forum parameter in newtopic.php, and (5) tidnr parameter in neuerbeitrag.php. | |||||
CVE-2005-3872 | 1 Ugroup | 1 Ugroup | 2011-03-07 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Ugroup 2.6.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) FORUM_ID parameter in forum.php, and the (2) TOPIC_ID, (3) FORUM_ID, and (4) CAT_ID parameters in topic.php. | |||||
CVE-2005-3873 | 1 Sourceshock | 1 Shockboard | 2011-03-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in topic.php in ShockBoard 3.0 and 4.0 allows remote attackers to execute arbitrary SQL commands via the offset parameter. | |||||
CVE-2005-3874 | 1 Weaverslave | 1 Netzbrett | 2011-03-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in netzbr.php in Netzbrett 1.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the p_entry parameter in an entry command to index.php. | |||||
CVE-2005-3875 | 1 Enterprise Heart | 1 Enterprise Connector | 2011-03-07 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Enterprise Connector 1.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the messageid parameter in (1) send.php or (2) a delete action in messages.php. | |||||
CVE-2005-3876 | 1 Td-systems | 2 Adc2000 Ng Pro, Adc2000 Ng Pro Lite | 2011-03-07 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in adcbrowres.php in AD Center ADC2000 NG Pro 1.2 and NG Pro Lite allow remote attackers to execute arbitrary SQL commands via the (1) cat and (2) lang parameters. | |||||
CVE-2005-3878 | 1 Alex King | 1 Php Doc System | 2011-03-07 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in index.php in PHP Doc System 1.5.1 and earlier allows remote attackers to access or include arbitrary files via a .. (dot dot) in the show parameter. | |||||
CVE-2005-3880 | 1 Omnistar Interactive | 1 Omnistar Kbase | 2011-03-07 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Omnistar KBase 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter in users/comments.php, (2) category_id and (3) id parameters in users/kb.php. | |||||
CVE-2005-3882 | 1 Faqsystems | 1 Faqring Knowledge Base Software | 2011-03-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in answer.php in FAQSystems FAQRing Knowledge Base Software 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2005-3886 | 1 Cisco | 1 Security Agent | 2011-03-07 | 7.2 HIGH | N/A |
Unspecified vulnerability in Cisco Security Agent (CSA) 4.5.0 and 4.5.1 agents, when running on Windows systems, allows local users to bypass protections and gain system privileges by executing certain local software. | |||||
CVE-2005-3900 | 1 Macromedia | 1 Breeze | 2011-03-07 | 7.8 HIGH | N/A |
Macromedia Breeze Communication Server and Breeze Live Server does 5.1 and earlier not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated using an alpha release build of Flash Player 8.5 (build 133). | |||||
CVE-2005-3908 | 1 Amazon Shop | 1 Amazon Shop | 2011-03-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in search.php in GhostScripter Amazon Shop 5.0.0, and other versions before 5.0.2, allows remote attackers to inject web script or HTML via the query parameter. | |||||
CVE-2005-3911 | 1 Bosdev | 1 Bosdates | 2011-03-07 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in calendar.php in BosDates 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) category parameters. | |||||
CVE-2005-3913 | 1 Vchs | 1 Vchs | 2011-03-07 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the domain alias management in Virtual Hosting Control System (VHCS) 2.4.6.2, related to "creating and deleting forwards for domain aliases," allows users to hijack the forwardings of other users. | |||||
CVE-2005-3914 | 1 Affcommerce | 1 Affcommerce | 2011-03-07 | 6.4 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php. | |||||
CVE-2005-3915 | 1 Clavister | 2 Clavister Firewall, Clavister Security Gateway | 2011-03-07 | 7.5 HIGH | N/A |
The Internet Key Exchange version 1 (IKEv1) implementation in Clavister Client Web allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to. | |||||
CVE-2005-3916 | 1 Wsn Forum | 1 Wsn Forum | 2011-03-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in memberlist.php in WSN Forum 1.21 allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action. | |||||
CVE-2005-3917 | 1 Commodityrentals | 1 Commodityrentals | 2011-03-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in usersession in CommodityRentals 2.0 Online Rental Business Creator script allows remote attackers to execute arbitrary SQL commands via the user_id parameter. |