Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 703

Количество 331 703

nvd логотип

CVE-2005-0883

почти 21 год назад

Multiple cross-site scripting (XSS) vulnerabilities in base.php for DigitalHive 2.0 allow remote attackers to inject arbitrary web script or HTML via (1) the mt parameter to the membres.php page or (2) the -afs-1- query string to the msg.php page.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0882

почти 21 год назад

SQL injection vulnerability in admincore.php in BirdBlog before 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) userid or (2) userpw parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0881

почти 21 год назад

Cross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers to inject arbitrary web script or HTML via the Articleld parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0880

почти 21 год назад

content.php in Vortex Portal allows remote attackers to obtain sensitive information via an invalid act parameter, which leaks the full pathname in a PHP error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0879

почти 21 год назад

PHP remote file include vulnerability in (1) content.php and (2) index.php for Vortex Portal allows remote attackers to execute arbitrary PHP code via a URL in the act parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0878

почти 21 год назад

Cross-site scripting (XSS) vulnerability in MercuryBoard before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the title field of a PM (private message).

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0877

почти 21 год назад

Dnsmasq before 2.21 allows remote attackers to poison the DNS cache via answers to queries that were not made by Dnsmasq.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0876

почти 21 год назад

Off-by-one buffer overflow in Dnsmasq before 2.21 may allow attackers to execute arbitrary code via the DHCP lease file.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0875

почти 21 год назад

Multiple buffer overflows in the Yahoo plug-in for Trillian 2.0, 3.0, and 3.1 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response header.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0874

почти 21 год назад

Multiple buffer overflows in the (1) AIM, (2) MSN, (3) RSS, and other plug-ins for Trillian 2.0 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response header.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0873

почти 21 год назад

Multiple cross-site scripting (XSS) vulnerabilities in test.jsp in Oracle Reports Server 10g (9.0.4.3.3) allow remote attackers to inject arbitrary web script or HTML via the (1) desname or (2) repprod parameter.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2005-0872

почти 21 год назад

Cross-site scripting (XSS) vulnerability in calendar_scheduler.php in the Topic Calendar 1.0.1 module for phpBB allows remote attackers to inject arbitrary web script or HTML via the start parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0871

почти 21 год назад

calendar_scheduler.php in Topic Calendar 1.0.1 module for phpBB, when running on a Microsoft IIS server, allows remote attackers to obtain sensitive information via invalid parameters, which reveal the path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0870

почти 21 год назад

Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) sensor_program parameter to index.php, (2) text[language], (3) text[template], or (4) hide_picklist parameter to system_footer.php.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2005-0869

почти 21 год назад

phpSysInfo 2.3 allows remote attackers to obtain sensitive information via a direct request to (1) class.OpenBSD.inc.php, (2) class.NetBSD.inc.php, (3) class.FreeBSD.inc.php, (4) class.Darwin.inc.php, (5) XPath.class.php, (6) system_header.php, or (7) system_footer.php, which reveal the path in a PHP error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0868

почти 21 год назад

AS/400 Telnet 5250 terminal emulation clients, as implemented by (1) IBM client access, (2) Bosanova, (3) PowerTerm, (4) Mochasoft, and possibly other emulations, allows malicious AS/400 servers to execute arbitrary commands via a STRPCO (Start PC Organizer) command followed by STRPCCMD (Start PC command), as demonstrated by creating a backdoor account using REXEC.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0867

почти 21 год назад

Integer overflow in Linux kernel 2.6 allows local users to overwrite kernel memory by writing to a sysfs file.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2005-0866

почти 21 год назад

cdrecord before 4:2.0, when DEBUG is enabled, allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-0865

почти 21 год назад

Samsung ADSL Modem SMDK8947v1.2 uses default passwords for the (1) root, (2) admin, or (3) user users, which allows remote attackers to gain privileges via Telnet or an HTTP request to adsl.cgi.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0864

почти 21 год назад

The Boa web server, as used in Samsung ADSL Modem SMDK8947v1.2 and possibly other products, allows remote attackers to read arbitrary files via a full pathname in the HTTP request.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-0883

Multiple cross-site scripting (XSS) vulnerabilities in base.php for DigitalHive 2.0 allow remote attackers to inject arbitrary web script or HTML via (1) the mt parameter to the membres.php page or (2) the -afs-1- query string to the msg.php page.

CVSS2: 4.3
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0882

SQL injection vulnerability in admincore.php in BirdBlog before 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) userid or (2) userpw parameters.

CVSS2: 7.5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0881

Cross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers to inject arbitrary web script or HTML via the Articleld parameter.

CVSS2: 4.3
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0880

content.php in Vortex Portal allows remote attackers to obtain sensitive information via an invalid act parameter, which leaks the full pathname in a PHP error message.

CVSS2: 5
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0879

PHP remote file include vulnerability in (1) content.php and (2) index.php for Vortex Portal allows remote attackers to execute arbitrary PHP code via a URL in the act parameter.

CVSS2: 7.5
8%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0878

Cross-site scripting (XSS) vulnerability in MercuryBoard before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the title field of a PM (private message).

CVSS2: 4.3
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0877

Dnsmasq before 2.21 allows remote attackers to poison the DNS cache via answers to queries that were not made by Dnsmasq.

CVSS3: 7.5
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0876

Off-by-one buffer overflow in Dnsmasq before 2.21 may allow attackers to execute arbitrary code via the DHCP lease file.

CVSS2: 5
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0875

Multiple buffer overflows in the Yahoo plug-in for Trillian 2.0, 3.0, and 3.1 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response header.

CVSS2: 5
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0874

Multiple buffer overflows in the (1) AIM, (2) MSN, (3) RSS, and other plug-ins for Trillian 2.0 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response header.

CVSS2: 5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0873

Multiple cross-site scripting (XSS) vulnerabilities in test.jsp in Oracle Reports Server 10g (9.0.4.3.3) allow remote attackers to inject arbitrary web script or HTML via the (1) desname or (2) repprod parameter.

CVSS2: 4.3
67%
Средний
почти 21 год назад
nvd логотип
CVE-2005-0872

Cross-site scripting (XSS) vulnerability in calendar_scheduler.php in the Topic Calendar 1.0.1 module for phpBB allows remote attackers to inject arbitrary web script or HTML via the start parameter.

CVSS2: 4.3
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0871

calendar_scheduler.php in Topic Calendar 1.0.1 module for phpBB, when running on a Microsoft IIS server, allows remote attackers to obtain sensitive information via invalid parameters, which reveal the path in an error message.

CVSS2: 5
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0870

Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) sensor_program parameter to index.php, (2) text[language], (3) text[template], or (4) hide_picklist parameter to system_footer.php.

CVSS2: 4.3
12%
Средний
почти 21 год назад
nvd логотип
CVE-2005-0869

phpSysInfo 2.3 allows remote attackers to obtain sensitive information via a direct request to (1) class.OpenBSD.inc.php, (2) class.NetBSD.inc.php, (3) class.FreeBSD.inc.php, (4) class.Darwin.inc.php, (5) XPath.class.php, (6) system_header.php, or (7) system_footer.php, which reveal the path in a PHP error message.

CVSS2: 5
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0868

AS/400 Telnet 5250 terminal emulation clients, as implemented by (1) IBM client access, (2) Bosanova, (3) PowerTerm, (4) Mochasoft, and possibly other emulations, allows malicious AS/400 servers to execute arbitrary commands via a STRPCO (Start PC Organizer) command followed by STRPCCMD (Start PC command), as demonstrated by creating a backdoor account using REXEC.

CVSS2: 7.5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0867

Integer overflow in Linux kernel 2.6 allows local users to overwrite kernel memory by writing to a sysfs file.

CVSS2: 7.2
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0866

cdrecord before 4:2.0, when DEBUG is enabled, allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 2.1
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0865

Samsung ADSL Modem SMDK8947v1.2 uses default passwords for the (1) root, (2) admin, or (3) user users, which allows remote attackers to gain privileges via Telnet or an HTTP request to adsl.cgi.

CVSS2: 7.5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0864

The Boa web server, as used in Samsung ADSL Modem SMDK8947v1.2 and possibly other products, allows remote attackers to read arbitrary files via a full pathname in the HTTP request.

CVSS2: 5
0%
Низкий
почти 21 год назад

Уязвимостей на страницу