Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 140

Количество 373 140

nvd логотип

CVE-2005-2617

почти 21 год назад

The syscall32_setup_pages function in syscall32.c for Linux kernel 2.6.12 and later, on the 64-bit x86 platform, does not check the return value of the insert_vm_struct function, which allows local users to trigger a memory leak via a 32-bit application with crafted ELF headers.

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2005-2616

почти 21 год назад

Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.php, (2) customize.php, (3) form.php, or (4) index.php.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-2615

почти 21 год назад

Unknown vulnerability in session.php in EQdkp before 1.3.0 has unknown impact and attack vectors, possibly involving auto_login_id.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2614

почти 21 год назад

Discuz! 4.0 rc4 does not properly restrict types of files that are uploaded to the server, which allows remote attackers to execute arbitrary commands via a filename containing ".php.rar" or other multiple extensions that include .php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2613

почти 21 год назад

Unknown vulnerability in CPAINT Ajax Toolkit before 1.3-SP allows attackers to execute arbitrary PHP or ASP code or read files via unknown vectors.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-2612

почти 21 год назад

Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[server] cookie.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-2611

почти 21 год назад

VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the backup server.

CVSS2: 10
EPSS: Высокий
nvd логотип

CVE-2005-2610

почти 21 год назад

Cross-site scripting (XSS) vulnerability in index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the message parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2609

почти 21 год назад

index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to obtain the full server path via an invalid VDNS_Sessid parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2608

почти 21 год назад

SafeHTML before 1.3.5 does not properly filter script in UTF-7 and CSS comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks in vulnerable applications that use SafeHTML.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2607

почти 21 год назад

PHP file include vulnerability in download.php in PHPSimplicity Simplicity oF Upload before 1.3.1 allows remote attackers to include arbitrary local and remote files via the language parameter and a terminating null ("%00") characters.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2606

почти 21 год назад

Unknown vulnerability in the "frontend authentication" in PHlyMail 3.02.00 has unknown impact and attack vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2605

почти 21 год назад

Unknown vulnerability in Lasso Professional Server8.0.4 and 8.0.5 allows attackers to bypass authentication, related to [Auth] tags.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-2604

почти 21 год назад

index.php for My Image Gallery (Mig ) 1.4.1 allows remote attackers to obtain the web server path via certain currDir and image arguments, which leaks the path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2603

почти 21 год назад

Cross-site scripting (XSS) vulnerability in index.php for My Image Gallery (Mig ) 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the (1) currDir or (2) image parameters.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2602

почти 21 год назад

Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, which causes the address bar to go blank and could facilitate phishing attacks.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2005-2601

почти 21 год назад

SQL injection vulnerability in MidiCart allows remote attackers to execute arbitrary SQL commands via the code_no parameter to (1) Item_Show.asp or (2) search_list.asp.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2600

почти 21 год назад

FUDForum 2.6.15 with "Tree View" enabled, as used in other products such as phpgroupware and egroupware, allows remote attackers to read private posts via a modified mid parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2599

почти 21 год назад

Hummingbird FTP for Connectivity 10.0 uses weak encryption (trivial encoding) to store the user's password in the FTP profile, which allows attackers to gain privileges.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2598

почти 21 год назад

Multiple directory traversal vulnerabilities in Dokeos 1.6 and earlier, and possibly Claroline, allow remote attackers to (1) delete arbitrary files or directories via the delete parameter to claroline/scorm/scormdocument.php, (2) move arbitrary files via the move_to and move_file parameters to claroline/document/document.php, or determine the existence of arbitrary files via the file parameter to (3) claroline/scorm/showinframes.php or (4) claroline/scorm/contents.php.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-2617

The syscall32_setup_pages function in syscall32.c for Linux kernel 2.6.12 and later, on the 64-bit x86 platform, does not check the return value of the insert_vm_struct function, which allows local users to trigger a memory leak via a 32-bit application with crafted ELF headers.

CVSS2: 3.6
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2616

Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.php, (2) customize.php, (3) form.php, or (4) index.php.

CVSS2: 7.5
11%
Средний
почти 21 год назад
nvd логотип
CVE-2005-2615

Unknown vulnerability in session.php in EQdkp before 1.3.0 has unknown impact and attack vectors, possibly involving auto_login_id.

CVSS2: 7.5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2614

Discuz! 4.0 rc4 does not properly restrict types of files that are uploaded to the server, which allows remote attackers to execute arbitrary commands via a filename containing ".php.rar" or other multiple extensions that include .php.

CVSS2: 7.5
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2613

Unknown vulnerability in CPAINT Ajax Toolkit before 1.3-SP allows attackers to execute arbitrary PHP or ASP code or read files via unknown vectors.

CVSS2: 6.4
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2612

Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[server] cookie.

CVSS2: 7.5
39%
Средний
почти 21 год назад
nvd логотип
CVE-2005-2611

VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the backup server.

CVSS2: 10
87%
Высокий
почти 21 год назад
nvd логотип
CVE-2005-2610

Cross-site scripting (XSS) vulnerability in index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the message parameter.

CVSS2: 4.3
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2609

index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to obtain the full server path via an invalid VDNS_Sessid parameter.

CVSS2: 5
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2608

SafeHTML before 1.3.5 does not properly filter script in UTF-7 and CSS comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks in vulnerable applications that use SafeHTML.

CVSS2: 4.3
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2607

PHP file include vulnerability in download.php in PHPSimplicity Simplicity oF Upload before 1.3.1 allows remote attackers to include arbitrary local and remote files via the language parameter and a terminating null ("%00") characters.

CVSS2: 5
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2606

Unknown vulnerability in the "frontend authentication" in PHlyMail 3.02.00 has unknown impact and attack vectors.

CVSS2: 7.5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2605

Unknown vulnerability in Lasso Professional Server8.0.4 and 8.0.5 allows attackers to bypass authentication, related to [Auth] tags.

CVSS2: 6.4
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2604

index.php for My Image Gallery (Mig ) 1.4.1 allows remote attackers to obtain the web server path via certain currDir and image arguments, which leaks the path in an error message.

CVSS2: 5
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2603

Cross-site scripting (XSS) vulnerability in index.php for My Image Gallery (Mig ) 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the (1) currDir or (2) image parameters.

CVSS2: 4.3
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2602

Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, which causes the address bar to go blank and could facilitate phishing attacks.

CVSS2: 2.6
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2601

SQL injection vulnerability in MidiCart allows remote attackers to execute arbitrary SQL commands via the code_no parameter to (1) Item_Show.asp or (2) search_list.asp.

CVSS2: 7.5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2600

FUDForum 2.6.15 with "Tree View" enabled, as used in other products such as phpgroupware and egroupware, allows remote attackers to read private posts via a modified mid parameter.

CVSS2: 5
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2599

Hummingbird FTP for Connectivity 10.0 uses weak encryption (trivial encoding) to store the user's password in the FTP profile, which allows attackers to gain privileges.

CVSS2: 7.5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2598

Multiple directory traversal vulnerabilities in Dokeos 1.6 and earlier, and possibly Claroline, allow remote attackers to (1) delete arbitrary files or directories via the delete parameter to claroline/scorm/scormdocument.php, (2) move arbitrary files via the move_to and move_file parameters to claroline/document/document.php, or determine the existence of arbitrary files via the file parameter to (3) claroline/scorm/showinframes.php or (4) claroline/scorm/contents.php.

CVSS2: 5
2%
Низкий
почти 21 год назад

Уязвимостей на страницу