Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-3697 | 1 Uresk Links | 1 Uresk Links | 2008-09-05 | 7.5 HIGH | N/A |
Unspecified vulnerability in the administration interface in Uresk Links 2.0 Lite allows remote attackers to bypass authentication via unspecified vectors in index.php. | |||||
CVE-2005-3698 | 1 Php Easy Download | 1 Php Easy Download | 2008-09-05 | 7.5 HIGH | N/A |
PHP Easy Download allows remote attackers to bypass authentication via edit.php. | |||||
CVE-2005-3727 | 1 Revize Cms | 1 Revize Cms | 2008-09-05 | 7.5 HIGH | N/A |
SQL injection vulnerability in debug/query_results.jsp in Idetix Software Systems Revize CMS allows remote attackers to execute arbitrary SQL commands via the query parameter. | |||||
CVE-2005-3728 | 1 Revize Cms | 1 Revize Cms | 2008-09-05 | 5.0 MEDIUM | N/A |
Idetix Software Systems Revize CMS stores conf/revize.xml under the web document root with insufficient access control, which allows remote attackers to obtain sensitive configuration information. | |||||
CVE-2005-3729 | 1 Revize Cms | 1 Revize Cms | 2008-09-05 | 5.0 MEDIUM | N/A |
Idetix Software Systems Revize CMS allows remote attackers to obtain sensitive information via direct requests to files in the revize/debug directory, such as (1) apptables.html and (2) main.html. | |||||
CVE-2005-3730 | 1 Revize Cms | 1 Revize Cms | 2008-09-05 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in HTTPTranslatorServlet in Idetix Software Systems Revize CMS allow remote attackers to inject arbitrary web script or HTML via the (1) resourcetype, (2) objectmap, and (3) redirect parameters, possibly involving setWebSpace.jsp. | |||||
CVE-2005-3731 | 1 Yassl | 1 Yassl | 2008-09-05 | 10.0 HIGH | N/A |
Unspecified vulnerability in yaSSL before 1.0.6 has unknown impact and attack vectors, related to "certificate chain processing." | |||||
CVE-2005-3736 | 1 Coastal Data Management | 1 E-quick Cart | 2008-09-05 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in e-Quick Cart allow remote attackers to inject arbitrary web script or HTML via the (1) strgifttoname parameter in shopgift.asp, (2) strfirstname parameter in shopmaillist.asp, (3) strpid parameter in shopprojectlogin.asp, and (4) Custname parameter in shoptellafriend.asp. | |||||
CVE-2005-3741 | 1 Almondsoft | 1 Almond Classifieds | 2008-09-05 | 7.5 HIGH | N/A |
Almond Classifieds does not properly verify the password, which allows attackers to bypass access restrictions. | |||||
CVE-2005-3743 | 1 Simplepoll | 1 Simplepoll | 2008-09-05 | 7.5 HIGH | N/A |
SQL injection vulnerability in results.php in SimplePoll allows remote attackers to execute arbitrary SQL commands via the pollid parameter. | |||||
CVE-2005-3751 | 1 Apsis | 1 Pound | 2008-09-05 | 4.3 MEDIUM | N/A |
HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with conflicting Content-length and Transfer-encoding headers. | |||||
CVE-2005-3752 | 1 Ldapdiff | 1 Ldapdiff | 2008-09-05 | 10.0 HIGH | N/A |
Unspecified vulnerability in ldapdiff before 1.1.1 has unknown impact and attack vectors, related to "ldapdiff.conf path construction". | |||||
CVE-2005-3753 | 1 Linux | 1 Linux Kernel | 2008-09-05 | 7.8 HIGH | N/A |
Linux kernel before after 2.6.12 and before 2.6.13.1 might allow attackers to cause a denial of service (Oops) via certain IPSec packets that cause alignment problems in standard multi-block cipher processors. NOTE: it is not clear whether this issue can be triggered by an attacker. | |||||
CVE-2005-3761 | 1 Exponent | 1 Exponent | 2008-09-05 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Exponent CMS 0.96.3 and later versions allows remote attackers to inject arbitrary web script or HTML via (1) Javascript in forms produced by the form generator or (2) the parameters to the installer. | |||||
CVE-2005-3763 | 1 Exponent | 1 Exponent | 2008-09-05 | 5.0 MEDIUM | N/A |
Exponent CMS 0.96.3 and later versions includes the full installation path in the base parameter to thumb.php, which allows remote attackers to obtain sensitive information. NOTE: this might be resultant from an absolute path traversal vulnerability. | |||||
CVE-2005-3764 | 1 Exponent | 1 Exponent | 2008-09-05 | 10.0 HIGH | N/A |
The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files, with unknown impact from the preview icon, possibly involving injection of HTML. | |||||
CVE-2005-3765 | 1 Exponent | 1 Exponent | 2008-09-05 | 7.5 HIGH | N/A |
Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to execute arbitrary code. | |||||
CVE-2005-3766 | 1 Exponent | 1 Exponent | 2008-09-05 | 5.0 MEDIUM | N/A |
Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though certain permissions are specified, which allows attackers to access the pages by browsing uploaded files. | |||||
CVE-2005-3769 | 1 Php Download Manager | 1 Php Download Manager | 2008-09-05 | 7.5 HIGH | N/A |
SQL injection vulnerability in files.php in PHP Download Manager 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |||||
CVE-2005-3778 | 1 Mybulletinboard | 1 Mybulletinboard | 2008-09-05 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in MyBulletinBoard (MyBB) before 1.0 PR2 Rev 686 allows attackers to cause a denial of service via unknown vectors. |