Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 570

Количество 373 570

nvd логотип

CVE-2005-3552

больше 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple vectors in (1) login/profile.php, (2) login/userinfo.php, (3) admin/admin.php, (4) imcenter.php, and the (5) referer statistics, the (6) HTML title element and (7) logo alt attributes in forum postings, and the (8) Homepage field in the Guestbook.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-3551

больше 20 лет назад

toendaCMS before 0.6.2 stores user account and session data in the web root directory, which allows remote attackers to obtain sensitive information via a direct request to the appropriate XML file.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-3550

больше 20 лет назад

Directory traversal vulnerability in admin.php in toendaCMS before 0.6.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the id_user parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-3549

больше 20 лет назад

Direct code injection vulnerability in Task Manager in Invision Power Board 2.0.1 allows limited remote attackers to execute arbitrary code by referencing the file in "Task PHP File To Run" field and selecting "Run Task Now".

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2005-3548

больше 20 лет назад

Directory traversal vulnerability in Task Manager in Invision Power Board (IP.Board) 2.0.1 allows limited remote attackers to include files via a .. (dot dot) in the "Task PHP File To Run" field.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2005-3547

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in Invision Power Board 2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) adsess, (2) name, and (3) description parameters in admin.php, and the (4) ACP Notes, (5) Member Name, (6) Password, (7) Email Address, (8) Components, and multiple other input fields.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-3546

больше 20 лет назад

suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2005-3545

больше 20 лет назад

SQL injection vulnerability in index.php of the report module in ibProArcade 2.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3544

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in u2u.php in XMB 1.9.3 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-3543

больше 20 лет назад

SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the forum_ids parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2005-3542

больше 20 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-3508. Reason: This candidate is a reservation duplicate of CVE-2005-3508. Notes: All CVE users should reference CVE-2005-3508 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий
nvd логотип

CVE-2005-3540

больше 20 лет назад

Buffer overflow in petris before 1.0.1 allows remote attackers to execute arbitrary code via unspecified attack vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3539

больше 20 лет назад

Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-3538

больше 20 лет назад

hfaxd in HylaFAX 4.2.3, when PAM support is disabled, accepts arbitrary passwords, which allows remote attackers to gain privileges.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3537

больше 20 лет назад

A "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit private messages of other users, probably by modifying certain parameters or other inputs.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-3536

больше 20 лет назад

SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3535

больше 20 лет назад

Buffer overflow in KETM 0.0.6 allows local users to execute arbitrary code via unknown vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3534

больше 20 лет назад

Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a large request, which is written past the end of the buffer because nbd does not account for memory taken by the reply header.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3533

больше 20 лет назад

Buffer overflow in OSH before 1.7-15 allows local users to execute arbitrary code via a long current working directory and filename.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2005-3532

больше 20 лет назад

authpam.c in courier-authdaemon for Courier Mail Server 0.37.3 through 0.52.1, when using pam_tally, does not call the pam_acct_mgmt function to verify that access should be granted, which allows attackers to authenticate to the server using accounts that have been disabled.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-3552

Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple vectors in (1) login/profile.php, (2) login/userinfo.php, (3) admin/admin.php, (4) imcenter.php, and the (5) referer statistics, the (6) HTML title element and (7) logo alt attributes in forum postings, and the (8) Homepage field in the Guestbook.

CVSS2: 4.3
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3551

toendaCMS before 0.6.2 stores user account and session data in the web root directory, which allows remote attackers to obtain sensitive information via a direct request to the appropriate XML file.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3550

Directory traversal vulnerability in admin.php in toendaCMS before 0.6.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the id_user parameter.

CVSS2: 5
6%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3549

Direct code injection vulnerability in Task Manager in Invision Power Board 2.0.1 allows limited remote attackers to execute arbitrary code by referencing the file in "Task PHP File To Run" field and selecting "Run Task Now".

CVSS2: 6.5
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3548

Directory traversal vulnerability in Task Manager in Invision Power Board (IP.Board) 2.0.1 allows limited remote attackers to include files via a .. (dot dot) in the "Task PHP File To Run" field.

CVSS2: 4
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3547

Cross-site scripting (XSS) vulnerability in Invision Power Board 2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) adsess, (2) name, and (3) description parameters in admin.php, and the (4) ACP Notes, (5) Member Name, (6) Password, (7) Email Address, (8) Components, and multiple other input fields.

CVSS2: 4.3
3%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3546

suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege.

CVSS2: 7.2
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3545

SQL injection vulnerability in index.php of the report module in ibProArcade 2.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.

CVSS2: 7.5
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3544

Cross-site scripting (XSS) vulnerability in u2u.php in XMB 1.9.3 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

CVSS2: 4.3
5%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3543

SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the forum_ids parameter.

CVSS2: 6.8
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3542

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-3508. Reason: This candidate is a reservation duplicate of CVE-2005-3508. Notes: All CVE users should reference CVE-2005-3508 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

больше 20 лет назад
nvd логотип
CVE-2005-3540

Buffer overflow in petris before 1.0.1 allows remote attackers to execute arbitrary code via unspecified attack vectors.

CVSS2: 7.5
3%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3539

Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.

CVSS2: 7.5
13%
Средний
больше 20 лет назад
nvd логотип
CVE-2005-3538

hfaxd in HylaFAX 4.2.3, when PAM support is disabled, accepts arbitrary passwords, which allows remote attackers to gain privileges.

CVSS2: 7.5
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3537

A "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit private messages of other users, probably by modifying certain parameters or other inputs.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3536

SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3535

Buffer overflow in KETM 0.0.6 allows local users to execute arbitrary code via unknown vectors.

CVSS2: 7.5
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3534

Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a large request, which is written past the end of the buffer because nbd does not account for memory taken by the reply header.

CVSS2: 7.5
6%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3533

Buffer overflow in OSH before 1.7-15 allows local users to execute arbitrary code via a long current working directory and filename.

CVSS2: 7.2
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3532

authpam.c in courier-authdaemon for Courier Mail Server 0.37.3 through 0.52.1, when using pam_tally, does not call the pam_acct_mgmt function to verify that access should be granted, which allows attackers to authenticate to the server using accounts that have been disabled.

CVSS2: 7.5
2%
Низкий
больше 20 лет назад

Уязвимостей на страницу