Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 855

Количество 372 855

nvd логотип

CVE-2005-2210

около 21 года назад

Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2209

около 21 года назад

Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2005-2208

около 21 года назад

PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2207

около 21 года назад

Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2206

около 21 года назад

Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp, or the id parameter to (3) updateCreditCards.asp or (4) deleteCreditCards.asp.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2205

около 21 года назад

The ReadLog function in kaiseki.cgi in pngren allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2204

около 21 года назад

Cross-site scripting (XSS) vulnerability in Computer Associates (CA) eTrust SiteMinder 5.5, when the "CSSChecking" parameter is set to "NO," allows remote attackers to inject arbitrary web script or HTML via the (1) PASSWORD or (2) BUFFER parameters to smpwservicescgi.exe, (3) the TARGET parameter to login.fcc, and possibly other vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2203

около 21 года назад

login.php in phpWishlist before 0.1.15 allows remote attackers to bypass authentication via a direct request to admin.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2202

около 21 года назад

Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2201

около 21 года назад

Unknown vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to cause a denial of service or access files via crafted HTTP requests.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-2200

около 21 года назад

Multiple unknown vulnerabilities in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to bypass authentication.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2199

около 21 года назад

PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via the config[ppa_root_path] variable.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-2198

около 21 года назад

PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary code via the lang_path parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2197

около 21 года назад

SQL injection vulnerability in sql.cls.php in Id Board 1.1.3 allows remote attackers to modify SQL queries, as demonstrated using the f parameter to index.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2196

около 21 года назад

The Apple AirPort card uses a default WEP key when not connected to a known or trusted network, which can cause it to automatically connect to a malicious network.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-2195

около 21 года назад

Apple Darwin Streaming Server 5.5 and earlier allows remote attackers to cause a denial of service (application crash) via a URL with a filename containing a .cgi extension and an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1, a different vulnerability than CVE-2003-0421 and CVE-2003-0502.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2194

больше 20 лет назад

Unspecified vulnerability in the Apple Mac OS X kernel before 10.4.2 allows remote attackers to cause a denial of service (kernel panic) via a crafted TCP packet, possibly related to source routing or loose source routing.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2193

около 21 года назад

SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote attackers to execute arbitrary SQL statements via the temp array, which is not initialized before it is used and prevents the attacker-supplied portions of the array from being properly escaped.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2192

около 21 года назад

SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2191

около 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Comersus shopping cart allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to comersus_backoffice_listAssignedPricesToCustomer.asp or (2) message parameter to comersus_backoffice_message.asp.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-2210

Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL.

CVSS2: 7.5
4%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2209

Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users.

CVSS3: 5.5
0%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2208

PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message.

CVSS2: 5
3%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2207

Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2206

Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp, or the id parameter to (3) updateCreditCards.asp or (4) deleteCreditCards.asp.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2205

The ReadLog function in kaiseki.cgi in pngren allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.

CVSS2: 7.5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2204

Cross-site scripting (XSS) vulnerability in Computer Associates (CA) eTrust SiteMinder 5.5, when the "CSSChecking" parameter is set to "NO," allows remote attackers to inject arbitrary web script or HTML via the (1) PASSWORD or (2) BUFFER parameters to smpwservicescgi.exe, (3) the TARGET parameter to login.fcc, and possibly other vectors.

CVSS2: 4.3
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2203

login.php in phpWishlist before 0.1.15 allows remote attackers to bypass authentication via a direct request to admin.php.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2202

Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVSS2: 4.3
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2201

Unknown vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to cause a denial of service or access files via crafted HTTP requests.

CVSS2: 6.4
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2200

Multiple unknown vulnerabilities in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to bypass authentication.

CVSS2: 7.5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2199

PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via the config[ppa_root_path] variable.

CVSS2: 7.5
10%
Средний
около 21 года назад
nvd логотип
CVE-2005-2198

PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary code via the lang_path parameter.

CVSS2: 7.5
3%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2197

SQL injection vulnerability in sql.cls.php in Id Board 1.1.3 allows remote attackers to modify SQL queries, as demonstrated using the f parameter to index.php.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2196

The Apple AirPort card uses a default WEP key when not connected to a known or trusted network, which can cause it to automatically connect to a malicious network.

CVSS2: 2.1
0%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2195

Apple Darwin Streaming Server 5.5 and earlier allows remote attackers to cause a denial of service (application crash) via a URL with a filename containing a .cgi extension and an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1, a different vulnerability than CVE-2003-0421 and CVE-2003-0502.

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2194

Unspecified vulnerability in the Apple Mac OS X kernel before 10.4.2 allows remote attackers to cause a denial of service (kernel panic) via a crafted TCP packet, possibly related to source routing or loose source routing.

CVSS2: 5
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-2193

SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote attackers to execute arbitrary SQL statements via the temp array, which is not initialized before it is used and prevents the attacker-supplied portions of the array from being properly escaped.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2192

SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.

CVSS2: 5
4%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2191

Multiple cross-site scripting (XSS) vulnerabilities in Comersus shopping cart allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to comersus_backoffice_listAssignedPricesToCustomer.asp or (2) message parameter to comersus_backoffice_message.asp.

CVSS2: 4.3
1%
Низкий
около 21 года назад

Уязвимостей на страницу