Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 083

Количество 374 083

nvd логотип

CVE-2005-4676

больше 20 лет назад

Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null terminate strings before calling the sscanf function, which allows remote attackers to cause a denial of service (application crash) via images with crafted IPTC metadata.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-4675

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in list.php in Complete PHP Counter allows remote attackers to inject arbitrary web script or HTML via the c parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-4674

больше 20 лет назад

Multiple SQL injection vulnerabilities in list.php in Complete PHP Counter allow remote attackers to execute arbitrary SQL commands via the (1) c or (2) s parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-4673

больше 20 лет назад

ioFTPD 0.5.84 u responds with different messages depending on whether or not a username exists, which allows remote attackers to enumerate valid usernames.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-4672

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in image-editor-52/index.php in CityPost Simple Image-Editor 0.52 allows remote attackers to inject arbitrary web script or HTML via the (1) m1, (2) m2, (3) m3, (4) imgsrc, and (5) m4 parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-4671

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in simple-upload-53.php in CityPost Simple PHP Upload 5.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-4670

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in message.php in CityPost Automated Link Exchange (LNKX) allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-4669

больше 20 лет назад

SQL injection vulnerability in RT Internet Solutions (RTIS) WebAdmin allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-4668

больше 20 лет назад

The embedded HSQLDB in ParosProxy before 3.2.7, when running with JDK 1.4.2 before 1.4.2_08, allows local users to execute arbitrary comands via crafted SQL commands that interact with HSQLDB through JDBC, a similar vulnerability to CVE-2003-0845.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2005-4667

больше 20 лет назад

Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.

CVSS2: 3.7
EPSS: Низкий
nvd логотип

CVE-2005-4666

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in PHlyMail before 3.3 Beta1 allows remote attackers to inject arbitrary Javascript via unknown attack vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-4665

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in PunBB 1.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via Javascript contained in nested, malformed BBcode url tags.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-4664

больше 20 лет назад

SQL injection vulnerability in OcoMon 1.21, and possibly other versions, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the logon page, a different vulnerability than CVE-2005-4662.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-4663

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in OcoMon 1.20, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-4662

больше 20 лет назад

Multiple SQL injection vulnerabilities in OcoMon 1.20, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via unknown attack vectors in an unspecified input form, a different vulnerability than CVE-2005-4664.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-4661

больше 20 лет назад

The notifyendsubs cron job in Campsite before 2.3.3 sends an e-mail message containing a certain unencrypted MySQL password, which allows remote attackers to sniff the password.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-4660

больше 20 лет назад

Race condition in IPCop (aka IPCop Firewall) before 1.4.10 might allow local users to overwrite system configuration files and gain privileges by replacing a backup archive during the time window when the archive is owned by "nobody" but not yet encrypted, then executing ipcoprscfg to restore from this backup.

CVSS2: 1.2
EPSS: Низкий
nvd логотип

CVE-2005-4659

больше 20 лет назад

IPCop (aka IPCop Firewall) before 1.4.10 has world-readable permissions for the backup.key file, which might allow local users to overwrite system configuration files and gain privileges by creating a malicious encrypted backup archive owned by "nobody", then executing ipcoprscfg to restore from this backup.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-4658

больше 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in ASP-Programmers.com ASPKnowledgebase allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in the administrative interface.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2005-4657

больше 20 лет назад

Ocean12 Calendar Manager Pro 1.01 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to /admin/view.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-4676

Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null terminate strings before calling the sscanf function, which allows remote attackers to cause a denial of service (application crash) via images with crafted IPTC metadata.

CVSS2: 5
4%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4675

Cross-site scripting (XSS) vulnerability in list.php in Complete PHP Counter allows remote attackers to inject arbitrary web script or HTML via the c parameter.

CVSS2: 4.3
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4674

Multiple SQL injection vulnerabilities in list.php in Complete PHP Counter allow remote attackers to execute arbitrary SQL commands via the (1) c or (2) s parameter.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4673

ioFTPD 0.5.84 u responds with different messages depending on whether or not a username exists, which allows remote attackers to enumerate valid usernames.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4672

Cross-site scripting (XSS) vulnerability in image-editor-52/index.php in CityPost Simple Image-Editor 0.52 allows remote attackers to inject arbitrary web script or HTML via the (1) m1, (2) m2, (3) m3, (4) imgsrc, and (5) m4 parameter.

CVSS2: 4.3
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4671

Cross-site scripting (XSS) vulnerability in simple-upload-53.php in CityPost Simple PHP Upload 5.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

CVSS2: 4.3
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4670

Cross-site scripting (XSS) vulnerability in message.php in CityPost Automated Link Exchange (LNKX) allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

CVSS2: 4.3
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4669

SQL injection vulnerability in RT Internet Solutions (RTIS) WebAdmin allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4668

The embedded HSQLDB in ParosProxy before 3.2.7, when running with JDK 1.4.2 before 1.4.2_08, allows local users to execute arbitrary comands via crafted SQL commands that interact with HSQLDB through JDBC, a similar vulnerability to CVE-2003-0845.

CVSS2: 4.6
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4667

Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.

CVSS2: 3.7
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4666

Cross-site scripting (XSS) vulnerability in PHlyMail before 3.3 Beta1 allows remote attackers to inject arbitrary Javascript via unknown attack vectors.

CVSS2: 4.3
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4665

Cross-site scripting (XSS) vulnerability in PunBB 1.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via Javascript contained in nested, malformed BBcode url tags.

CVSS2: 4.3
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4664

SQL injection vulnerability in OcoMon 1.21, and possibly other versions, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the logon page, a different vulnerability than CVE-2005-4662.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4663

Cross-site scripting (XSS) vulnerability in OcoMon 1.20, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4662

Multiple SQL injection vulnerabilities in OcoMon 1.20, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via unknown attack vectors in an unspecified input form, a different vulnerability than CVE-2005-4664.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4661

The notifyendsubs cron job in Campsite before 2.3.3 sends an e-mail message containing a certain unencrypted MySQL password, which allows remote attackers to sniff the password.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4660

Race condition in IPCop (aka IPCop Firewall) before 1.4.10 might allow local users to overwrite system configuration files and gain privileges by replacing a backup archive during the time window when the archive is owned by "nobody" but not yet encrypted, then executing ipcoprscfg to restore from this backup.

CVSS2: 1.2
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4659

IPCop (aka IPCop Firewall) before 1.4.10 has world-readable permissions for the backup.key file, which might allow local users to overwrite system configuration files and gain privileges by creating a malicious encrypted backup archive owned by "nobody", then executing ipcoprscfg to restore from this backup.

CVSS2: 2.1
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4658

Multiple cross-site scripting (XSS) vulnerabilities in ASP-Programmers.com ASPKnowledgebase allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in the administrative interface.

CVSS2: 6.8
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4657

Ocean12 Calendar Manager Pro 1.01 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to /admin/view.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 7.5
3%
Низкий
больше 20 лет назад

Уязвимостей на страницу