Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 855

Количество 372 855

nvd логотип

CVE-2005-2168

около 21 года назад

delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2167

около 21 года назад

Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2166

около 21 года назад

SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2165

около 21 года назад

read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2164

около 21 года назад

SQL injection vulnerability in Covide Groupware-CRM allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2163

около 21 года назад

Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2162

около 21 года назад

PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2161

около 21 года назад

Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote attackers to inject arbitrary web script or HTML via nested [url] tags.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2160

около 21 года назад

IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2159

около 21 года назад

mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2158

около 21 года назад

A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vulnerability that was originally identified by CVE-2003-0845.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2157

около 21 года назад

PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2156

около 21 года назад

SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2155

около 21 года назад

PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2154

около 21 года назад

PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and possibly execute arbitrary local files via the inc parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2153

около 21 года назад

SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2152

около 21 года назад

SQL injection vulnerability in Geeklog before 1.3.11 allows remote attackers to execute arbitrary SQL commands via user comments for an article.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2151

около 21 года назад

spf.c in Courier Mail Server does not properly handle DNS failures when looking up Sender Policy Framework (SPF) records, which could allow attackers to cause memory corruption.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2150

около 21 года назад

Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2005-2149

около 21 года назад

config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-2168

delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2167

Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2166

SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2165

read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters.

CVSS2: 7.5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2164

SQL injection vulnerability in Covide Groupware-CRM allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2163

Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

CVSS2: 4.3
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2162

PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter.

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2161

Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote attackers to inject arbitrary web script or HTML via nested [url] tags.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2160

IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.

CVSS3: 7.5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2159

mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2158

A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vulnerability that was originally identified by CVE-2003-0845.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2157

PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter.

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2156

SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2155

PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.

CVSS2: 7.5
3%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2154

PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and possibly execute arbitrary local files via the inc parameter.

CVSS2: 7.5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2153

SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2152

SQL injection vulnerability in Geeklog before 1.3.11 allows remote attackers to execute arbitrary SQL commands via user comments for an article.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2151

spf.c in Courier Mail Server does not properly handle DNS failures when looking up Sender Policy Framework (SPF) records, which could allow attackers to cause memory corruption.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2150

Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.

CVSS2: 5
19%
Средний
около 21 года назад
nvd логотип
CVE-2005-2149

config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.

CVSS2: 10
2%
Низкий
около 21 года назад

Уязвимостей на страницу