Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-1167 | 1 Musicmatch | 1 Jukebox | 2016-10-17 | 2.1 LOW | N/A |
Musicmatch 10.00.2047 and earlier store log files in the Program Files directory instead of the user profile, which may allow local users to obtain sensitive information. | |||||
CVE-2005-1168 | 1 Musicmatch | 1 Jukebox | 2016-10-17 | 5.0 MEDIUM | N/A |
DiagCollectionControl.dll in Musicmatch 10.00.2047 and earlier allows remote attackers to overwrite arbitrary files via the bstrSavePath argument. | |||||
CVE-2005-1169 | 1 Mafia | 1 Mafia Blog | 2016-10-17 | 7.5 HIGH | N/A |
Mafia Blog .4 BETA does not properly protect the admin directory, which allows remote attackers to execute arbitrary PHP code by using writeinfo.php to inject the code into info.php. | |||||
CVE-2005-1170 | 1 Datenbank Module | 1 Datenbank Module | 2016-10-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2005-1172 | 1 Coppermine | 1 Coppermine Photo Gallery | 2016-10-17 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For parameter. | |||||
CVE-2005-1173 | 1 Pmsoftware | 1 Simple Web Server | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in PMSoftware Simple Web Server 1.0 allows remote attackers to execute arbitrary code via a long GET request. | |||||
CVE-2005-1196 | 1 Phpbb Group | 1 Phpbb | 2016-10-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote attackers to obtain sensitive information and execute SQL commands via the cat parameter. | |||||
CVE-2005-0955 | 1 Interakt | 1 Mx Shop | 2016-10-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in InterAKT MX Shop 1.1.1 allows remote attackers to execute arbitrary SQL commands via the id_ctg parameter. | |||||
CVE-2005-0956 | 1 Interakt | 1 Mx Kart | 2016-10-17 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in index.php in InterAKT MX Kart 1.1.2 allow remote attackers to execute arbitrary SQL commands via the (1) idp, (2) id_ctg, or (3) id_man parameter. | |||||
CVE-2005-0980 | 1 Alstrasoft | 1 Epay | 2016-10-17 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary PHP code by modifying the view parameter to reference a URL on a remote web server that contains the code. | |||||
CVE-2005-0981 | 1 Alstrasoft | 1 Epay | 2016-10-17 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft EPay Pro 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) payment or (2) send parameter. | |||||
CVE-2005-0982 | 1 Yet Another Forum.net | 1 Yet Another Forum.net | 2016-10-17 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Yet Another Forum.net 0.9.9 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) location, or (3) Subject field. | |||||
CVE-2005-0983 | 4 Activision, Id Software, Lucasarts and 1 more | 10 Call Of Duty, Call Of Duty United Offensive, Return To Castle Wolfenstein and 7 more | 2016-10-17 | 5.0 MEDIUM | N/A |
Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes the engine to process the remaining data as if it were network data. | |||||
CVE-2005-0984 | 1 Lucasarts | 1 Star Wars Jedi Knight Jedi Academy | 2016-10-17 | 5.0 MEDIUM | N/A |
Buffer overflow in the G_Printf function in Star Wars Jedi Knight: Jedi Academy 1.011 and earlier allows remote attackers to execute arbitrary code via a long message using commands such as (1) say and (2) tell. | |||||
CVE-2005-0993 | 1 Sco | 1 Openserver | 2016-10-17 | 4.6 MEDIUM | N/A |
Buffer overflow in nwprint in SCO OpenServer 5.0.7 allows local users to execute arbitrary code via a long command line argument. | |||||
CVE-2005-0996 | 1 Francisco Burzi | 1 Php-nuke | 2016-10-17 | 5.0 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the email or url parameters in the Add function, (2) the min parameter in the viewsdownload function, or (3) the min parameter in the search function. | |||||
CVE-2005-0997 | 1 Francisco Burzi | 1 Php-nuke | 2016-10-17 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 7.6 allow remote attackers to execute arbitrary SQL commands via (1) the email or url parameters in the Add function, (2) the url parameter in the modifylinkrequestS function, (3) the orderby or min parameters in the viewlink function, (4) the orderby, min, or show parameters in the search function, or (5) the ratenum parameter in the MostPopular function. | |||||
CVE-2005-0998 | 1 Francisco Burzi | 1 Php-nuke | 2016-10-17 | 5.0 MEDIUM | N/A |
The Web_Links module for PHP-Nuke 7.6 allows remote attackers to obtain sensitive information via an invalid show parameter, which triggers a division by zero PHP error that leaks the full pathname of the server. | |||||
CVE-2005-0999 | 1 Francisco Burzi | 1 Php-nuke | 2016-10-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Top module for PHP-Nuke 6.x through 7.6 allows remote attackers to execute arbitrary SQL commands via the querylang parameter. | |||||
CVE-2005-1002 | 1 Logics Software | 1 Log-ft | 2016-10-17 | 5.0 MEDIUM | N/A |
logwebftbs2000.exe in Logics Software File Transfer (LOG-FT) allows remote attackers to read arbitrary files via modified (1) VAR_FT_LANG and (2) VAR_FT_TMPL parameters. |