Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 855

Количество 372 855

nvd логотип

CVE-2005-2190

около 21 года назад

Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or (2) idProduct parameter to comersus_optReviewReadExec.asp.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2189

около 21 года назад

Lantronix SecureLinx console server running firmware 2.0 and 3.0 stores /etc/ssh under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as SSH private keys.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2188

около 21 года назад

McAfee IntruShield Security Management System obtains the user ID from the URL, which allows remote attackers to guess the Manager account and possibly gain privileges via a brute force attack.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2187

около 21 года назад

McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true, as demonstrated using the (1) fullAccess or (2) fullAccessRight parameter in reports-column-center.jsp, or (3) fullAccess parameter to SystemEvent.jsp.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2005-2186

около 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in McAfee IntruShield Security Management System allow remote authenticated users to inject arbitrary web script or HTML via the (1) thirdMenuName or (2) resourceName parameter to SystemEvent.jsp.

CVSS2: 1.9
EPSS: Низкий
nvd логотип

CVE-2005-2185

около 21 года назад

eRoom does not set an expiration for Cookies, which allows remote attackers to capture cookies and conduct replay attacks.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2184

около 21 года назад

eRoom 6.x does not properly restrict files that can be attached, which allows remote attackers to execute arbitrary commands via a .lnk file.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2183

около 21 года назад

class.xmail.php in PhpXmail 0.7 through 1.1 does not properly handle large passwords, which prevents an error message from being returned and allows remote attackers to bypass authentication and gain unauthorized access.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2182

около 21 года назад

Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2181

около 21 года назад

Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2180

около 21 года назад

gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local users to overwrite arbitrary files.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-2179

около 21 года назад

PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2178

около 21 года назад

probe.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the olddat parameter. NOTE: it is unclear which product or vendor this program is associated with, if any.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2177

около 21 года назад

Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2176

около 21 года назад

Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-2175

около 21 года назад

The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2174

около 21 года назад

Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2005-2173

около 21 года назад

The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2170

около 21 года назад

The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connection without sending any data.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2169

около 21 года назад

Directory traversal vulnerability in source.php in Quick & Dirty PHPSource Printer 1.1 and earlier allows remote attackers to read arbitrary files via ".../...//" sequences in the file parameter, which are reduced to "../" when PHPSource Printer uses a regular expression to remove "../" sequences.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-2190

Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or (2) idProduct parameter to comersus_optReviewReadExec.asp.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2189

Lantronix SecureLinx console server running firmware 2.0 and 3.0 stores /etc/ssh under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as SSH private keys.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2188

McAfee IntruShield Security Management System obtains the user ID from the URL, which allows remote attackers to guess the Manager account and possibly gain privileges via a brute force attack.

CVSS2: 7.5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2187

McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true, as demonstrated using the (1) fullAccess or (2) fullAccessRight parameter in reports-column-center.jsp, or (3) fullAccess parameter to SystemEvent.jsp.

CVSS2: 4.6
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2186

Multiple cross-site scripting (XSS) vulnerabilities in McAfee IntruShield Security Management System allow remote authenticated users to inject arbitrary web script or HTML via the (1) thirdMenuName or (2) resourceName parameter to SystemEvent.jsp.

CVSS2: 1.9
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2185

eRoom does not set an expiration for Cookies, which allows remote attackers to capture cookies and conduct replay attacks.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2184

eRoom 6.x does not properly restrict files that can be attached, which allows remote attackers to execute arbitrary commands via a .lnk file.

CVSS2: 7.5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2183

class.xmail.php in PhpXmail 0.7 through 1.1 does not properly handle large passwords, which prevents an error message from being returned and allows remote attackers to bypass authentication and gain unauthorized access.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2182

Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.

CVSS3: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2181

Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.

CVSS3: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2180

gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local users to overwrite arbitrary files.

CVSS2: 2.1
0%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2179

PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter.

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2178

probe.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the olddat parameter. NOTE: it is unclear which product or vendor this program is associated with, if any.

CVSS2: 7.5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2177

Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.

CVSS2: 5
4%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2176

Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.

CVSS2: 6.4
4%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2175

The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.

CVSS2: 5
5%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2174

Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete.

CVSS2: 2.6
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2173

The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2170

The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connection without sending any data.

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2169

Directory traversal vulnerability in source.php in Quick & Dirty PHPSource Printer 1.1 and earlier allows remote attackers to read arbitrary files via ".../...//" sequences in the file parameter, which are reduced to "../" when PHPSource Printer uses a regular expression to remove "../" sequences.

CVSS2: 5
2%
Низкий
около 21 года назад

Уязвимостей на страницу