Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-4454 | 1 Livejournal | 1 Livejournal | 2017-07-19 | 4.3 MEDIUM | N/A |
Validate-before-filter vulnerability in cleanhtml.pl 1.129 in LiveJournal CVS before Dec 7 2005, when the cleancss option is enabled, allows remote attackers to conduct cross-site scripting (XSS) attacks via a "\" (backslash) within a "javascript" scheme in a style property (such as "javas\cript"), which bypasses the "javascript" check before the "\" is stripped and then rendered in web browsers that allow scripting in style sheets. | |||||
CVE-2005-4500 | 1 Musicbox | 1 Musicbox | 2017-07-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in MusicBox 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) show and (2) type parameter. NOTE: the provenance of this information is unknown, although it was later rediscovered. | |||||
CVE-2005-4501 | 1 Mediawiki | 1 Mediawiki | 2017-07-19 | 4.3 MEDIUM | N/A |
MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute Javascript using inline style attributes, which are processed by Internet Explorer. | |||||
CVE-2005-4504 | 1 Apple | 4 Mac Os X, Mac Os X Server, Safari and 1 more | 2017-07-19 | 7.8 HIGH | N/A |
The khtml::RenderTableSection::ensureRows function in KHTMLParser in Apple Mac OS X 10.4.3 and earlier, as used by Safari and TextEdit, allows remote attackers to cause a denial of service (memory consumption and application crash) via HTML files with a large ROWSPAN attribute in a TD tag. | |||||
CVE-2005-4505 | 1 Mcafee | 2 Common Management Agent, Virusscan Enterprise | 2017-07-19 | 7.2 HIGH | N/A |
Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run by naPrdMgr.exe when it attempts to execute EntVUtil.EXE under an unquoted "Program Files" path. | |||||
CVE-2005-4509 | 1 Parallel Tools Consortium | 1 Ptools | 2017-07-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.asp in pTools allows remote attackers to execute arbitrary SQL commands via the docID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2005-4511 | 1 Curtis Hawthorne | 1 Tn3270 Resource Gateway | 2017-07-19 | 4.6 MEDIUM | N/A |
Format string vulnerability in TN3270 Resource Gateway 1.1.0 allows local users to cause a denial of service and possibly execute arbitrary code via format string specifiers in syslog function calls. | |||||
CVE-2005-4515 | 1 Lois Software | 1 Webdb | 2017-07-19 | 7.5 HIGH | N/A |
** DISPUTED ** SQL injection vulnerability in WebDB 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified search parameters, possibly Search0. NOTE: the vendor has disputed this issue, saying that "WebDB is a generic online database system used by many of the clients of Lois Software. The flaw that was identified was some code that was added for a client to do some testing of his system and only certain safe commands were allowed. This code has now been removed and it is not now possible to use SQL queries as part of the query string. No installation or patch is required All clients use a common code library and have their own front end and databases and connections. So as soon as a change / upgrade / enhancement is made to the code, all users of the software begin to use the latest changes immediately." Since the issue appeared in a custom web site and no action is required on the part of customers, this issue should not be included in CVE. | |||||
CVE-2005-4527 | 1 Direct News | 1 Direct News | 2017-07-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Direct News 4.9 allow remote attackers to execute arbitrary SQL commands via (1) the setLang parameter in index.php and (2) unspecified search module parameters. | |||||
CVE-2005-4530 | 1 Alstrasoft | 1 Epay | 2017-07-19 | 5.1 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft EPay Enterprise 3.0 (formerly DoPays) allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters in (1) profile.htm, (2) card.htm, (3) bank.htm, (4) subscriptions.htm, (5) send.htm, (6) request.htm, (7) forgot.htm, (8) escrow.htm, (9) donations.htm, and (10) products.htm. | |||||
CVE-2005-4532 | 1 Scponly | 1 Scponly | 2017-07-19 | 7.2 HIGH | N/A |
scponlyc in scponly 4.1 and earlier, when the operating system supports LD_PRELOAD mechanisms, allows local users to execute arbitrary code with root privileges by creating a chroot directory in their home directory, hard linking to a system setuid application, and using a modified LD_PRELOAD to modify expected function calls in the setuid application. | |||||
CVE-2005-4536 | 1 Debian | 1 Libmail-audit-perl | 2017-07-19 | 2.1 LOW | N/A |
Mail::Audit module in libmail-audit-perl 2.1-5, when logging is enabled without a default log file specified, uses predictable log filenames, which allows local users to overwrite arbitrary files via a symlink attack on the [PID]-audit.log temporary file. | |||||
CVE-2005-4545 | 1 Netdirect | 1 Shopengine | 2017-07-19 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in search.asp in NetDirect ShopEngine allows remote attackers to inject arbitrary web script or HTML via the EXPS parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2005-4546 | 1 Epic Designs | 1 Eggblog | 2017-07-19 | 7.8 HIGH | N/A |
search.php in eggblog 2.0 allows remote attackers to obtain the full path via an invalid q parameter, as used by the Keyword and Search fields, possibly due to an SQL injection vulnerability. | |||||
CVE-2005-4547 | 1 Epic Designs | 1 Eggblog | 2017-07-19 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in home/search.php in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the q parameter, as used by the Keyword and Search fields. | |||||
CVE-2005-4550 | 1 Oracle | 1 Application Server Discussion Forum Portlet | 2017-07-19 | 5.0 MEDIUM | N/A |
The PORTAL schema in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to obtain the source code for arbitrary JSP and other files via a df_next_page parameter with a trailing null byte (%00). | |||||
CVE-2005-4553 | 1 Kmint21 Software | 1 Golden Ftp Server | 2017-07-19 | 7.5 HIGH | N/A |
Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long APPE command. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2005-4563 | 1 Enterprise Heart | 1 Enterprise Connector | 2017-07-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in main.php in Enterprise Heart Enterprise Connector 1.0.2 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the loginid parameter, a different vulnerability than CVE-2005-3875. | |||||
CVE-2005-4571 | 1 Myezshop | 1 Myezshop Shopping Cart | 2017-07-19 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in myEZshop Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2005-4572 | 1 Myezshop | 1 Myezshop Shopping Cart | 2017-07-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in myEZshop Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) GroupsId and (2) ItemsId parameters in admin.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |