Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-3029 | 1 Ahnlab | 3 V3 Virusblock 2005, V3net, V3pro 2004 | 2016-10-17 | 7.5 HIGH | N/A |
Stack-based buffer overflow in AhnLab V3Pro 2004 build 6.0.0.383, V3 VirusBlock 2005 build 6.0.0.383, and V3Net for Windows Server 6.0 build 6.0.0.383 allows remote attackers to execute arbitrary code via a long filname in an ACE archive. | |||||
CVE-2005-3030 | 1 Ahnlab | 3 V3 Virusblock 2005, V3net, V3pro 2004 | 2016-10-17 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in the archive decompression library in AhnLab V3Pro 2004 build 6.0.0.383, V3 VirusBlock 2005 build 6.0.0.383, and V3Net for Windows Server 6.0 build 6.0.0.383 allows remote attackers to write arbitrary files via a .. (dot dot) in the filename in a compressed archive. | |||||
CVE-2005-3045 | 1 My Little Homepage | 1 My Little Forum | 2016-10-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in search.php in My Little Forum 1.5 and 1.6 beta allows remote attackers to execute arbitrary SQL commands via the phrase field. | |||||
CVE-2005-3046 | 1 Phpmyfaq | 1 Phpmyfaq | 2016-10-17 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field. | |||||
CVE-2005-3047 | 1 Phpmyfaq | 1 Phpmyfaq | 2016-10-17 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMF_CONF[version] parameter to footer.php or (2) PMF_LANG[metaLanguage] to header.php. | |||||
CVE-2005-3048 | 1 Phpmyfaq | 1 Phpmyfaq | 2016-10-17 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or include arbitrary PHP files via a .. (dot dot) in the LANGCODE parameter, which also allows direct code injection via the User Agent field in a request packet, which can be activated by using LANGCODE to reference the user tracking data file. | |||||
CVE-2005-3050 | 1 Phpmyfaq | 1 Phpmyfaq | 2016-10-17 | 5.0 MEDIUM | N/A |
PhpMyFaq 1.5.1 allows remote attackers to obtain sensitive information via a LANGCODE parameter that does not exist, which reveals the path in an error message. | |||||
CVE-2005-3052 | 1 Jportal | 1 Jportal Web Portal | 2016-10-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in module/down.inc.php in jportal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the search field to download.php. | |||||
CVE-2005-3061 | 1 Powerarchiver | 4 Powerarchiver 2002, Powerarchiver 2003, Powerarchiver 2004 and 1 more | 2016-10-17 | 7.5 HIGH | N/A |
Multiple stack-based buffer overflows in PowerArchiver 8.10 through 9.5 Beta 4 and Beta 5 allow remote attackers to execute arbitrary code via a long filename in a (1) ACE or (2) ARJ archive. | |||||
CVE-2005-3062 | 1 Alstrasoft | 1 E-friends | 2016-10-17 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in index.php in AlstraSoft E-Friends 4.0 allows remote attackers to execute arbitrary PHP code via the mode parameter. | |||||
CVE-2005-3063 | 1 Unu Networks | 1 Mailgust | 2016-10-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in MailGust 1.9 allows remote attackers to execute arbitrary SQL commands via the email field on the password reminder page. | |||||
CVE-2005-3083 | 1 Cmsmadesimple | 1 Cms Made Simple | 2016-10-17 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 0.10 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |||||
CVE-2005-3090 | 1 Mantis | 1 Mantis | 2016-10-17 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in bug_actiongroup_page.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the summary of the bug, which is not quoted when view_all_bug_page.php is used to delete the bug, as identified by bug#0006002, a different vulnerability than CVE-2005-2557. | |||||
CVE-2005-3092 | 1 Image-line Software | 1 Fl Studio | 2016-10-17 | 7.5 HIGH | N/A |
Heap-based buffer overflow in Image-Line Software FL Studio 5.0.1 allows remote attackers to execute arbitrary code via a .flp file that contains a long path to a (1) .mid or (2) .wav file. | |||||
CVE-2005-3113 | 1 Nateon | 1 Nateon Messenger | 2016-10-17 | 7.5 HIGH | N/A |
The ActiveX control for NateOn Messenger (NateonDownloadManager.ocx) allows remote attackers to download and execute arbitrary programs by setting the arguments to the GotNate.Excute method. | |||||
CVE-2005-3114 | 1 Nateon | 1 Nateon Messenger | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in the ActiveX control for NateOn Messenger (NateonDownloadManager.ocx) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long third argument to the GotNate.Excute method. | |||||
CVE-2005-3130 | 1 Lucidcms | 1 Lucidcms | 2016-10-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in lucidCMS 1.0.11 allows remote attackers to execute arbitrary SQL commands via the login field. | |||||
CVE-2005-3131 | 2 Icewarp, Merak | 2 Web Mail, Mail Server | 2016-10-17 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendar_d.html, (3) calendar_m.html, or (4) calendar_w.html. | |||||
CVE-2005-3132 | 2 Icewarp, Merak | 2 Web Mail, Mail Server | 2016-10-17 | 5.0 MEDIUM | N/A |
MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to bwlist_inc.html, which reveals the path in an error message. | |||||
CVE-2005-3133 | 2 Icewarp, Merak | 2 Web Mail, Mail Server | 2016-10-17 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to (1) delete arbitrary files or directories via a relative path to the id parameter to logout.html or (2) include arbitrary PHP files or other files via the helpid parameter to help.html. |