Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 140

Количество 373 140

nvd логотип

CVE-2005-2849

почти 21 год назад

Argument injection vulnerability in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to (1) read portions of source code via the -f option to Dig (dig_device.cgi), (2) determine file existence via the -r argument to Tcpdump (tcpdump_device.cgi) or (3) modify files in the cgi-bin directory via the -w argument to Tcpdump.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-2848

почти 21 год назад

Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2847

почти 21 год назад

img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-2846

почти 21 год назад

PHP remote file inclusion vulnerability in lang.php in CMS Made Simple 0.10 and earlier allows remote attackers to execute arbitrary PHP code via the nls[file][vx][vxsfx] parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2845

почти 21 год назад

Ariba Spend Management System sends the username and password to the server in plaintext in a POST request, which allows remote attackers to obtain sensitive information.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2844

почти 21 год назад

Buffer overflow in MMClient.exe in Indiatimes Messenger 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long group name argument to the RenameGroup function in the MMClient.MunduMessenger.1 ActiveX object.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2843

почти 21 год назад

Helpdesk software Hesk 0.92 does not properly verify usernames and passwords, which allows remote attackers to bypass authentication via a direct request to admin_main.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2842

почти 21 год назад

Buffer overflow in dwrcs.exe in DameWare Mini Remote Control before 4.9.0 allows remote attackers to execute arbitrary code via the username.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-2841

почти 21 год назад

Buffer overflow in Firewall Authentication Proxy for FTP and/or Telnet Sessions for Cisco IOS 12.2ZH and 12.2ZL, 12.3 and 12.3T, and 12.4 and 12.4T allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted user authentication credentials.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-2840

почти 21 год назад

Multiple unknown vulnerabilities in MAXdev MD-Pro 1.0.72 and earlier have unknown impact and unspecified attack vectors, in one or more of the (1) Download, (2) Search, (3) Web links, (4) Blocks, (5) Messages, (6) News, (7) Comments, (8) Settings, (9) Stats or (10) subjects modules.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2005-2839

почти 21 год назад

Multiple cross-site scripting (XSS) vulnerabilities in MAXdev MD-Pro 1.0.72 allow remote attackers to inject arbitrary web script or HTML via (1) dl-search.php or (2) wl-search.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2838

почти 21 год назад

SQL injection vulnerability in login.php in myBloggie 2.1.3-beta and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2837

почти 21 год назад

Multiple eval injection vulnerabilities in PlainBlack Software WebGUI before 6.7.3 allow remote attackers to execute arbitrary Perl code via (1) Help.pm, (2) International.pm, or (3) WebGUI.pm.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2836

почти 21 год назад

Multiple cross-site scripting (XSS) vulnerabilities in Phorum 5.0.17a and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to register.php or (2) a signature of a logged-in user in "My Control Center," which is not properly handled by control.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2831

больше 20 лет назад

Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-2830

больше 20 лет назад

Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2005-2829

больше 20 лет назад

Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."

CVSS2: 5.1
EPSS: Средний
nvd логотип

CVE-2005-2827

больше 20 лет назад

The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local users to modify kernel memory and execution flow via steps in which a terminating thread causes Asynchronous Procedure Call (APC) entries to free the wrong data, aka the "Windows Kernel Vulnerability."

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2005-2820

почти 21 год назад

Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message containing Internet Explorer "Conditional Comments" such as "[if]" and "[endif]".

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2819

почти 21 год назад

DownFile 1.3 allows remote attackers to gain administrator privileges via a direct request to (1) update.php, (2) del.php, and (3) add_form.php.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-2849

Argument injection vulnerability in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to (1) read portions of source code via the -f option to Dig (dig_device.cgi), (2) determine file existence via the -r argument to Tcpdump (tcpdump_device.cgi) or (3) modify files in the cgi-bin directory via the -w argument to Tcpdump.

CVSS2: 6.4
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2848

Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.

CVSS2: 5
9%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2847

img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.

CVSS2: 7.5
53%
Средний
почти 21 год назад
nvd логотип
CVE-2005-2846

PHP remote file inclusion vulnerability in lang.php in CMS Made Simple 0.10 and earlier allows remote attackers to execute arbitrary PHP code via the nls[file][vx][vxsfx] parameter.

CVSS2: 7.5
7%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2845

Ariba Spend Management System sends the username and password to the server in plaintext in a POST request, which allows remote attackers to obtain sensitive information.

CVSS2: 5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2844

Buffer overflow in MMClient.exe in Indiatimes Messenger 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long group name argument to the RenameGroup function in the MMClient.MunduMessenger.1 ActiveX object.

CVSS2: 7.5
5%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2843

Helpdesk software Hesk 0.92 does not properly verify usernames and passwords, which allows remote attackers to bypass authentication via a direct request to admin_main.php.

CVSS2: 7.5
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2842

Buffer overflow in dwrcs.exe in DameWare Mini Remote Control before 4.9.0 allows remote attackers to execute arbitrary code via the username.

CVSS2: 7.5
21%
Средний
почти 21 год назад
nvd логотип
CVE-2005-2841

Buffer overflow in Firewall Authentication Proxy for FTP and/or Telnet Sessions for Cisco IOS 12.2ZH and 12.2ZL, 12.3 and 12.3T, and 12.4 and 12.4T allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted user authentication credentials.

CVSS2: 7.5
14%
Средний
почти 21 год назад
nvd логотип
CVE-2005-2840

Multiple unknown vulnerabilities in MAXdev MD-Pro 1.0.72 and earlier have unknown impact and unspecified attack vectors, in one or more of the (1) Download, (2) Search, (3) Web links, (4) Blocks, (5) Messages, (6) News, (7) Comments, (8) Settings, (9) Stats or (10) subjects modules.

CVSS2: 10
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2839

Multiple cross-site scripting (XSS) vulnerabilities in MAXdev MD-Pro 1.0.72 allow remote attackers to inject arbitrary web script or HTML via (1) dl-search.php or (2) wl-search.php.

CVSS2: 4.3
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2838

SQL injection vulnerability in login.php in myBloggie 2.1.3-beta and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.

CVSS2: 7.5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2837

Multiple eval injection vulnerabilities in PlainBlack Software WebGUI before 6.7.3 allow remote attackers to execute arbitrary Perl code via (1) Help.pm, (2) International.pm, or (3) WebGUI.pm.

CVSS2: 7.5
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2836

Multiple cross-site scripting (XSS) vulnerabilities in Phorum 5.0.17a and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to register.php or (2) a signature of a logged-in user in "My Control Center," which is not properly handled by control.php.

CVSS2: 4.3
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2831

Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.

CVSS2: 7.5
30%
Средний
больше 20 лет назад
nvd логотип
CVE-2005-2830

Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."

CVSS2: 5
35%
Средний
больше 20 лет назад
nvd логотип
CVE-2005-2829

Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."

CVSS2: 5.1
19%
Средний
больше 20 лет назад
nvd логотип
CVE-2005-2827

The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local users to modify kernel memory and execution flow via steps in which a terminating thread causes Asynchronous Procedure Call (APC) entries to free the wrong data, aka the "Windows Kernel Vulnerability."

CVSS2: 7.2
3%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-2820

Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message containing Internet Explorer "Conditional Comments" such as "[if]" and "[endif]".

CVSS2: 4.3
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2819

DownFile 1.3 allows remote attackers to gain administrator privileges via a direct request to (1) update.php, (2) del.php, and (3) add_form.php.

CVSS2: 7.5
2%
Низкий
почти 21 год назад

Уязвимостей на страницу