Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 878

Количество 331 878

nvd логотип

CVE-2005-0798

почти 21 год назад

Novell iChain Mini FTP Server 2.3, and possibly earlier versions, does not limit the number of incorrect logins, which makes it easier for remote attackers to conduct brute force login attacks.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0797

почти 21 год назад

Novell iChain Mini FTP Server 2.3 displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0796

почти 21 год назад

Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0795

почти 21 год назад

HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified vote_filename parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0794

почти 21 год назад

ZPanel 2.0 and 2.5 beta 10 does not remove or protect installation scripts after they have been used, which allows remote attackers to reinstall the software and possibly cause a denial of service via a direct request to install.php.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-0793

почти 21 год назад

PHP remote file inclusion vulnerability in zpanel.php in ZPanel allows remote attackers to (1) execute arbitrary PHP code in ZPanel 2.0 or (2) include local files in ZPanel 2.5 beta 10 and earlier by modifying the page parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0792

почти 21 год назад

SQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter to index.php or (2) page parameter to zpanel.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0791

почти 21 год назад

Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the refresh parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0790

почти 21 год назад

phpAdsNew 2.0.4 allows remote attackers to obtain sensitive information via a direct request to (1) lib-xmlrpcs.inc.php, (2) maintenance-activation.php, (3) maintenance-cleantables.php, (4) maintenance-autotargeting.php, (5) maintenance-reports.php, (6) phpads.php, (7) remotehtmlview.php, (8) click.php, (9) adcontent.php, which reveal the path in a PHP error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0789

почти 21 год назад

Directory traversal vulnerability in LimeWire 3.9.6 through 4.6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in a magnet request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0788

почти 21 год назад

LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0787

почти 21 год назад

Wine 20050211 and earlier creates temp files with world readable permissions and predictable file names, which allows local users to obtain sensitive information, such as passwords.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-0786

почти 21 год назад

SQL injection vulnerability in gb_new.inc in SimpGB allows remote attackers to execute arbitrary SQL commands via the quote parameter to guestbook.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0785

почти 21 год назад

Cross-site scripting (XSS) vulnerability in usersrecentposts in YaBB 2.0 rc1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0784

почти 21 год назад

Multiple cross-site scripting (XSS) vulnerabilities in Phorum before 5.0.15 allow remote attackers to inject arbitrary web script or HTML via (1) the subject line to follow.php or (2) the subject line in the user's personal control panel.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0783

почти 21 год назад

Cross-site scripting (XSS) vulnerability in Phorum before 5.0.14a allows remote attackers to inject arbitrary web script or HTML via the filename of an attached file.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0782

почти 21 год назад

Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the start parameter to pafiledb.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0781

почти 21 год назад

SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter to pafiledb.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0780

почти 21 год назад

paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php, (4) file.php, (5) team.php, (6) license.php, (7) custom.php, (8) admins.php, or (9) backupdb.php, which reveal the path in a PHP error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0779

почти 21 год назад

PlatinumFTP 1.0.18, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via multiple connection attempts with a \ (backslash) in the username.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-0798

Novell iChain Mini FTP Server 2.3, and possibly earlier versions, does not limit the number of incorrect logins, which makes it easier for remote attackers to conduct brute force login attacks.

CVSS2: 7.5
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0797

Novell iChain Mini FTP Server 2.3 displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.

CVSS2: 5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0796

Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.

CVSS2: 5
3%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0795

HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified vote_filename parameter.

CVSS2: 5
5%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0794

ZPanel 2.0 and 2.5 beta 10 does not remove or protect installation scripts after they have been used, which allows remote attackers to reinstall the software and possibly cause a denial of service via a direct request to install.php.

CVSS2: 6.4
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0793

PHP remote file inclusion vulnerability in zpanel.php in ZPanel allows remote attackers to (1) execute arbitrary PHP code in ZPanel 2.0 or (2) include local files in ZPanel 2.5 beta 10 and earlier by modifying the page parameter.

CVSS2: 7.5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0792

SQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter to index.php or (2) page parameter to zpanel.php.

CVSS2: 7.5
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0791

Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the refresh parameter.

CVSS2: 4.3
5%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0790

phpAdsNew 2.0.4 allows remote attackers to obtain sensitive information via a direct request to (1) lib-xmlrpcs.inc.php, (2) maintenance-activation.php, (3) maintenance-cleantables.php, (4) maintenance-autotargeting.php, (5) maintenance-reports.php, (6) phpads.php, (7) remotehtmlview.php, (8) click.php, (9) adcontent.php, which reveal the path in a PHP error message.

CVSS2: 5
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0789

Directory traversal vulnerability in LimeWire 3.9.6 through 4.6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in a magnet request.

CVSS2: 5
3%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0788

LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request.

CVSS2: 5
6%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0787

Wine 20050211 and earlier creates temp files with world readable permissions and predictable file names, which allows local users to obtain sensitive information, such as passwords.

CVSS2: 2.1
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0786

SQL injection vulnerability in gb_new.inc in SimpGB allows remote attackers to execute arbitrary SQL commands via the quote parameter to guestbook.php.

CVSS2: 7.5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0785

Cross-site scripting (XSS) vulnerability in usersrecentposts in YaBB 2.0 rc1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

CVSS2: 4.3
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0784

Multiple cross-site scripting (XSS) vulnerabilities in Phorum before 5.0.15 allow remote attackers to inject arbitrary web script or HTML via (1) the subject line to follow.php or (2) the subject line in the user's personal control panel.

CVSS2: 4.3
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0783

Cross-site scripting (XSS) vulnerability in Phorum before 5.0.14a allows remote attackers to inject arbitrary web script or HTML via the filename of an attached file.

CVSS2: 4.3
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0782

Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the start parameter to pafiledb.php.

CVSS2: 4.3
4%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0781

SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter to pafiledb.php.

CVSS2: 7.5
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0780

paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php, (4) file.php, (5) team.php, (6) license.php, (7) custom.php, (8) admins.php, or (9) backupdb.php, which reveal the path in a PHP error message.

CVSS2: 5
4%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0779

PlatinumFTP 1.0.18, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via multiple connection attempts with a \ (backslash) in the username.

CVSS2: 5
5%
Низкий
почти 21 год назад

Уязвимостей на страницу