Количество 331 703
Количество 331 703
CVE-2005-1310
SQL injection vulnerability in bBlog 0.7.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter.
CVE-2005-1309
Cross-site scripting (XSS) vulnerability in bBlog 0.7.4 allows remote attackers to inject arbitrary web script or HTML via the (1) entry title field or (2) comment body text.
CVE-2005-1308
SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script or HTML.
CVE-2005-1307
The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled directory.
CVE-2005-1306
The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."
CVE-2005-1305
The hyper.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.
CVE-2005-1304
The citat.pl script allows remote attackers to execute arbitrary files via shell metacharacters in the argument.
CVE-2005-1303
The citat.pl script allows remote attackers to read arbitrary files via a full pathname in the argument.
CVE-2005-1302
SQL injection vulnerability in Confixx 3.08 and earlier allows remote attackers to execute arbitrary SQL commands via the "change user" field.
CVE-2005-1301
nProtect:Netizen 2005.3.17.1 does not properly verify that the update module is downloaded from an authorized site, which allows remote malicious web sites to write arbitrary files.
CVE-2005-1300
Cross-site scripting (XSS) vulnerability in the inserter.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.
CVE-2005-1299
The inserter.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.
CVE-2005-1298
The inserter.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.
CVE-2005-1297
Cross-site scripting (XSS) vulnerability in the include.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.
CVE-2005-1296
include.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.
CVE-2005-1295
include.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.
CVE-2005-1294
The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a socket call with a negative protocol value, which is used as an array index.
CVE-2005-1293
Multiple SQL injection vulnerabilities in default.asp in StorePortal 2.63 allow remote attackers to execute arbitrary SQL commands via the (1) language, (2) bpic, (3) idcategory, (4) content, (5) keyword, or (6) idproduct parameter.
CVE-2005-1292
Multiple cross-site scripting (XSS) vulnerabilities in CartWIZ ASP Cart allow remote attackers to inject arbitrary web script or HTML via the idProduct parameter to (1) tellAFriend.asp or (2) addToWishlist.asp, redirect parameter to (3) access.asp or (4) login.asp, message parameter to (5) login.asp or (6) error.asp, or (7) sku or (8) name parameter to searchResults.asp.
CVE-2005-1291
Multiple SQL injection vulnerabilities in CartWIZ ASP Cart allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) addToCart.asp or (2) productDetails.asp, the (3) priceFrom, (4) idCategory, or (5) priceTo parameter to searchResults.asp, or (6) the idParentCategory parameter to productCatalogSubCats.asp.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2005-1310 SQL injection vulnerability in bBlog 0.7.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter. | CVSS2: 7.5 | 1% Низкий | почти 21 год назад | |
CVE-2005-1309 Cross-site scripting (XSS) vulnerability in bBlog 0.7.4 allows remote attackers to inject arbitrary web script or HTML via the (1) entry title field or (2) comment body text. | CVSS2: 4.3 | 0% Низкий | почти 21 год назад | |
CVE-2005-1308 SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script or HTML. | CVSS2: 7.5 | 3% Низкий | почти 21 год назад | |
CVE-2005-1307 The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled directory. | CVSS2: 7.2 | 1% Низкий | больше 20 лет назад | |
CVE-2005-1306 The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability." | CVSS3: 7.5 | 16% Средний | больше 20 лет назад | |
CVE-2005-1305 The hyper.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument. | CVSS2: 5 | 0% Низкий | почти 21 год назад | |
CVE-2005-1304 The citat.pl script allows remote attackers to execute arbitrary files via shell metacharacters in the argument. | CVSS2: 7.5 | 1% Низкий | почти 21 год назад | |
CVE-2005-1303 The citat.pl script allows remote attackers to read arbitrary files via a full pathname in the argument. | CVSS2: 7.5 | 1% Низкий | почти 21 год назад | |
CVE-2005-1302 SQL injection vulnerability in Confixx 3.08 and earlier allows remote attackers to execute arbitrary SQL commands via the "change user" field. | CVSS2: 7.5 | 1% Низкий | почти 21 год назад | |
CVE-2005-1301 nProtect:Netizen 2005.3.17.1 does not properly verify that the update module is downloaded from an authorized site, which allows remote malicious web sites to write arbitrary files. | CVSS2: 2.6 | 0% Низкий | почти 21 год назад | |
CVE-2005-1300 Cross-site scripting (XSS) vulnerability in the inserter.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument. | CVSS2: 6.8 | 1% Низкий | почти 21 год назад | |
CVE-2005-1299 The inserter.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument. | CVSS2: 10 | 3% Низкий | почти 21 год назад | |
CVE-2005-1298 The inserter.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument. | CVSS2: 7.5 | 1% Низкий | почти 21 год назад | |
CVE-2005-1297 Cross-site scripting (XSS) vulnerability in the include.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument. | CVSS2: 6.8 | 1% Низкий | почти 21 год назад | |
CVE-2005-1296 include.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument. | CVSS2: 7.5 | 1% Низкий | почти 21 год назад | |
CVE-2005-1295 include.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument. | CVSS2: 7.5 | 1% Низкий | почти 21 год назад | |
CVE-2005-1294 The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a socket call with a negative protocol value, which is used as an array index. | CVSS2: 7.2 | 0% Низкий | почти 21 год назад | |
CVE-2005-1293 Multiple SQL injection vulnerabilities in default.asp in StorePortal 2.63 allow remote attackers to execute arbitrary SQL commands via the (1) language, (2) bpic, (3) idcategory, (4) content, (5) keyword, or (6) idproduct parameter. | CVSS2: 7.5 | 1% Низкий | почти 21 год назад | |
CVE-2005-1292 Multiple cross-site scripting (XSS) vulnerabilities in CartWIZ ASP Cart allow remote attackers to inject arbitrary web script or HTML via the idProduct parameter to (1) tellAFriend.asp or (2) addToWishlist.asp, redirect parameter to (3) access.asp or (4) login.asp, message parameter to (5) login.asp or (6) error.asp, or (7) sku or (8) name parameter to searchResults.asp. | CVSS2: 4.3 | 1% Низкий | почти 21 год назад | |
CVE-2005-1291 Multiple SQL injection vulnerabilities in CartWIZ ASP Cart allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) addToCart.asp or (2) productDetails.asp, the (3) priceFrom, (4) idCategory, or (5) priceTo parameter to searchResults.asp, or (6) the idParentCategory parameter to productCatalogSubCats.asp. | CVSS2: 7.5 | 1% Низкий | почти 21 год назад |
Уязвимостей на страницу