Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 855

Количество 372 855

nvd логотип

CVE-2005-2043

около 21 года назад

Directory traversal vulnerability in XAMPP before 1.4.14 allows remote attackers to inject arbitrary HTML and PHP code via lang.php.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2042

около 21 года назад

Cross-site scripting (XSS) vulnerability in ajax-spell before 1.8 allows remote attackers to inject arbitrary web script or HTML via onmouseover or other events in HTML tags.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2041

около 21 года назад

Buffer overflow in addschup in HAURI ViRobot 2.0, and possibly other products, allows remote attackers to execute arbitrary code via a long ViRobot_ID cookie (HTTP_COOKIE).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2040

около 21 года назад

Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal before 0.6.5 may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2005-0468 and CVE-2005-0469.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2039

около 21 года назад

Unknown vulnerability in "various plugins" for NanoBlogger 3.2.1 and earlier allows remote attackers to execute arbitrary commands.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2038

около 21 года назад

Fortibus CMS 4.0.0 allows remote attackers to modify information of other users, including Admin, via the "My info" page.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2037

около 21 года назад

Multiple SQL injection vulnerabilities in Fortibus CMS 4.0.0 allow remote attackers to execute arbitrary SQL commands via (1) the username or password to logon.asp, (2) WeeklyNotesDisplay.asp, or (3) the Search page.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2036

около 21 года назад

modifyUser.asp in Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to obtain the administrator password and email address via a modified nickname value.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2035

около 21 года назад

SQL injection vulnerability in login.asp for Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2034

около 21 года назад

Cross-site scripting (XSS) vulnerability in folderview.asp for BlueCollar iGallery 3.3 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2033

около 21 года назад

Directory traversal vulnerability in folderview.asp for Blue-Collar Productions i-Gallery 3.3 allows remote attackers to read arbitrary files and directories via the folder parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2032

около 21 года назад

Unknown vulnerability in lpadmin on Sun Solaris 7, 8, and 9 allows local users to overwrite arbitrary files.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-2031

около 21 года назад

Multiple SQL injection vulnerabilities in socialMPN allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter to article.php, (2) uname parameter to user.php, (3) siteid parameter to viewforum.php, (4) username parameter to newtopic.php, the (5) secid or (6) artid parameter to sections.php, (7) siteid parameter to index.php, or (8) sid parameter to friend.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2030

около 21 года назад

Ultimate PHP Board (UPB) 1.9.6 GOLD uses weak encryption for passwords in the users.dat file, which allows attackers to easily decrypt the passwords and gain privileges, possibly after exploiting CVE-2005-2005 to obtain users.dat.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2029

около 21 года назад

amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and password via a direct request to the file.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2028

около 21 года назад

SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2027

около 21 года назад

Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 does not properly restrict certain debugging commands to the ADMIN account, which could allow attackers to obtain sensitive information or modify the registry.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2026

около 21 года назад

Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 has a hard-coded account and password for debugging, which allows remote attackers to gain privileges.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2025

около 21 года назад

Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2024

около 21 года назад

Vipul Razor Agents (razor-agents) before 2.70 allows remote attackers to cause a denial of service via (1) certain "unusual HTML messages" or (2) "certain malformed headers" such as Content-Type.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-2043

Directory traversal vulnerability in XAMPP before 1.4.14 allows remote attackers to inject arbitrary HTML and PHP code via lang.php.

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2042

Cross-site scripting (XSS) vulnerability in ajax-spell before 1.8 allows remote attackers to inject arbitrary web script or HTML via onmouseover or other events in HTML tags.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2041

Buffer overflow in addschup in HAURI ViRobot 2.0, and possibly other products, allows remote attackers to execute arbitrary code via a long ViRobot_ID cookie (HTTP_COOKIE).

CVSS2: 5
6%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2040

Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal before 0.6.5 may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2005-0468 and CVE-2005-0469.

CVSS2: 5
3%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2039

Unknown vulnerability in "various plugins" for NanoBlogger 3.2.1 and earlier allows remote attackers to execute arbitrary commands.

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2038

Fortibus CMS 4.0.0 allows remote attackers to modify information of other users, including Admin, via the "My info" page.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2037

Multiple SQL injection vulnerabilities in Fortibus CMS 4.0.0 allow remote attackers to execute arbitrary SQL commands via (1) the username or password to logon.asp, (2) WeeklyNotesDisplay.asp, or (3) the Search page.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2036

modifyUser.asp in Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to obtain the administrator password and email address via a modified nickname value.

CVSS2: 7.5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2035

SQL injection vulnerability in login.asp for Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2034

Cross-site scripting (XSS) vulnerability in folderview.asp for BlueCollar iGallery 3.3 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2033

Directory traversal vulnerability in folderview.asp for Blue-Collar Productions i-Gallery 3.3 allows remote attackers to read arbitrary files and directories via the folder parameter.

CVSS2: 5
7%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2032

Unknown vulnerability in lpadmin on Sun Solaris 7, 8, and 9 allows local users to overwrite arbitrary files.

CVSS2: 2.1
0%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2031

Multiple SQL injection vulnerabilities in socialMPN allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter to article.php, (2) uname parameter to user.php, (3) siteid parameter to viewforum.php, (4) username parameter to newtopic.php, the (5) secid or (6) artid parameter to sections.php, (7) siteid parameter to index.php, or (8) sid parameter to friend.php.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2030

Ultimate PHP Board (UPB) 1.9.6 GOLD uses weak encryption for passwords in the users.dat file, which allows attackers to easily decrypt the passwords and gain privileges, possibly after exploiting CVE-2005-2005 to obtain users.dat.

CVSS2: 5
3%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2029

amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and password via a direct request to the file.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2028

SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.

CVSS2: 7.5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2027

Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 does not properly restrict certain debugging commands to the ADMIN account, which could allow attackers to obtain sensitive information or modify the registry.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2026

Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 has a hard-coded account and password for debugging, which allows remote attackers to gain privileges.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2025

Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname.

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2024

Vipul Razor Agents (razor-agents) before 2.70 allows remote attackers to cause a denial of service via (1) certain "unusual HTML messages" or (2) "certain malformed headers" such as Content-Type.

CVSS2: 5
2%
Низкий
около 21 года назад

Уязвимостей на страницу