Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 614

Количество 331 614

nvd логотип

CVE-2005-4669

около 20 лет назад

SQL injection vulnerability in RT Internet Solutions (RTIS) WebAdmin allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-4668

около 20 лет назад

The embedded HSQLDB in ParosProxy before 3.2.7, when running with JDK 1.4.2 before 1.4.2_08, allows local users to execute arbitrary comands via crafted SQL commands that interact with HSQLDB through JDBC, a similar vulnerability to CVE-2003-0845.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2005-4667

около 20 лет назад

Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.

CVSS2: 3.7
EPSS: Низкий
nvd логотип

CVE-2005-4666

около 20 лет назад

Cross-site scripting (XSS) vulnerability in PHlyMail before 3.3 Beta1 allows remote attackers to inject arbitrary Javascript via unknown attack vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-4665

около 20 лет назад

Cross-site scripting (XSS) vulnerability in PunBB 1.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via Javascript contained in nested, malformed BBcode url tags.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-4664

около 20 лет назад

SQL injection vulnerability in OcoMon 1.21, and possibly other versions, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the logon page, a different vulnerability than CVE-2005-4662.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-4663

около 20 лет назад

Cross-site scripting (XSS) vulnerability in OcoMon 1.20, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-4662

около 20 лет назад

Multiple SQL injection vulnerabilities in OcoMon 1.20, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via unknown attack vectors in an unspecified input form, a different vulnerability than CVE-2005-4664.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-4661

около 20 лет назад

The notifyendsubs cron job in Campsite before 2.3.3 sends an e-mail message containing a certain unencrypted MySQL password, which allows remote attackers to sniff the password.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-4660

около 20 лет назад

Race condition in IPCop (aka IPCop Firewall) before 1.4.10 might allow local users to overwrite system configuration files and gain privileges by replacing a backup archive during the time window when the archive is owned by "nobody" but not yet encrypted, then executing ipcoprscfg to restore from this backup.

CVSS2: 1.2
EPSS: Низкий
nvd логотип

CVE-2005-4659

около 20 лет назад

IPCop (aka IPCop Firewall) before 1.4.10 has world-readable permissions for the backup.key file, which might allow local users to overwrite system configuration files and gain privileges by creating a malicious encrypted backup archive owned by "nobody", then executing ipcoprscfg to restore from this backup.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-4658

около 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in ASP-Programmers.com ASPKnowledgebase allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in the administrative interface.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2005-4657

около 20 лет назад

Ocean12 Calendar Manager Pro 1.01 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to /admin/view.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-4656

около 20 лет назад

SQL injection vulnerability in index.php in TClanPortal 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands, and retrieve all usernames and passwords, via the id parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-4655

около 20 лет назад

Cross-site scripting (XSS) vulnerability in submit.php in PHP-Fusion 6.0.204 allows remote attackers to inject arbitrary web script or HTML via nested tags in the news_body parameter, as demonstrated by elements such as "<me<meta>ta" and "<sc<script>ript>".

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-4654

около 20 лет назад

Multiple unspecified vulnerabilities in Oracle for OpenView (OfO) 8.1.7, 9.1.01, and 9.2, and OfO for Linux, allow remote attackers to have an unknown impact via unknown attack vectors. NOTE: because of the lack of details in the vendor advisory, it is unclear which set of existing CVEs this advisory might refer to.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-4653

около 20 лет назад

Unspecified vulnerability in ss.php in AL-Caricatier 2.5 and earlier allows remote attackers to bypass login authentication by requesting view_caricatier.php, and then requesting any file in the admin directory with a cookie_username=admin argument.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-4652

около 20 лет назад

SQL injection vulnerability in PHlyMail 3.02.01 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-4651

около 20 лет назад

SQL injection vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the pmodule parameter.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-4650

около 20 лет назад

Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambots.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-4669

SQL injection vulnerability in RT Internet Solutions (RTIS) WebAdmin allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.

CVSS2: 7.5
1%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4668

The embedded HSQLDB in ParosProxy before 3.2.7, when running with JDK 1.4.2 before 1.4.2_08, allows local users to execute arbitrary comands via crafted SQL commands that interact with HSQLDB through JDBC, a similar vulnerability to CVE-2003-0845.

CVSS2: 4.6
0%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4667

Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.

CVSS2: 3.7
3%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4666

Cross-site scripting (XSS) vulnerability in PHlyMail before 3.3 Beta1 allows remote attackers to inject arbitrary Javascript via unknown attack vectors.

CVSS2: 4.3
1%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4665

Cross-site scripting (XSS) vulnerability in PunBB 1.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via Javascript contained in nested, malformed BBcode url tags.

CVSS2: 4.3
1%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4664

SQL injection vulnerability in OcoMon 1.21, and possibly other versions, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the logon page, a different vulnerability than CVE-2005-4662.

CVSS2: 5
0%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4663

Cross-site scripting (XSS) vulnerability in OcoMon 1.20, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
0%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4662

Multiple SQL injection vulnerabilities in OcoMon 1.20, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via unknown attack vectors in an unspecified input form, a different vulnerability than CVE-2005-4664.

CVSS2: 5
0%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4661

The notifyendsubs cron job in Campsite before 2.3.3 sends an e-mail message containing a certain unencrypted MySQL password, which allows remote attackers to sniff the password.

CVSS2: 5
0%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4660

Race condition in IPCop (aka IPCop Firewall) before 1.4.10 might allow local users to overwrite system configuration files and gain privileges by replacing a backup archive during the time window when the archive is owned by "nobody" but not yet encrypted, then executing ipcoprscfg to restore from this backup.

CVSS2: 1.2
0%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4659

IPCop (aka IPCop Firewall) before 1.4.10 has world-readable permissions for the backup.key file, which might allow local users to overwrite system configuration files and gain privileges by creating a malicious encrypted backup archive owned by "nobody", then executing ipcoprscfg to restore from this backup.

CVSS2: 2.1
0%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4658

Multiple cross-site scripting (XSS) vulnerabilities in ASP-Programmers.com ASPKnowledgebase allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in the administrative interface.

CVSS2: 6.8
1%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4657

Ocean12 Calendar Manager Pro 1.01 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to /admin/view.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 7.5
2%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4656

SQL injection vulnerability in index.php in TClanPortal 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands, and retrieve all usernames and passwords, via the id parameter.

CVSS2: 5
1%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4655

Cross-site scripting (XSS) vulnerability in submit.php in PHP-Fusion 6.0.204 allows remote attackers to inject arbitrary web script or HTML via nested tags in the news_body parameter, as demonstrated by elements such as "<me<meta>ta" and "<sc<script>ript>".

CVSS2: 4.3
0%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4654

Multiple unspecified vulnerabilities in Oracle for OpenView (OfO) 8.1.7, 9.1.01, and 9.2, and OfO for Linux, allow remote attackers to have an unknown impact via unknown attack vectors. NOTE: because of the lack of details in the vendor advisory, it is unclear which set of existing CVEs this advisory might refer to.

CVSS2: 6.4
0%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4653

Unspecified vulnerability in ss.php in AL-Caricatier 2.5 and earlier allows remote attackers to bypass login authentication by requesting view_caricatier.php, and then requesting any file in the admin directory with a cookie_username=admin argument.

CVSS2: 5
1%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4652

SQL injection vulnerability in PHlyMail 3.02.01 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

CVSS2: 6.4
0%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4651

SQL injection vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the pmodule parameter.

CVSS2: 6.4
0%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-4650

Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via a large number of Search Mambots.

CVSS3: 5.3
0%
Низкий
около 20 лет назад

Уязвимостей на страницу