Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 855

Количество 372 855

nvd логотип

CVE-2005-1979

почти 21 год назад

Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2005-1978

почти 21 год назад

COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-1976

больше 20 лет назад

Novell NetMail 3.5.2a, 3.5.2b, and 3.5.2c, when running on Linux, sets the owner and group ID to 500 for certain files, which could allow users or groups with that ID to execute arbitrary code or cause a denial of service by modifying those files.

CVSS2: 1.7
EPSS: Низкий
nvd логотип

CVE-2005-1975

около 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Annuaire 1Two 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter to index.php, or the (2) site_id, (3) nom, (4) email, or (5) commentaire parameters in commentaires.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-1974

около 21 года назад

Unspecified vulnerability in Java 2 Platform, Standard Edition (J2SE) 5.0 and 5.0 Update 1 and J2SE 1.4.2 up to 1.4.2_07, as used in multiple products and platforms including (1) HP-UX and (2) APC PowerChute, allows applications to assign permissions to themselves and gain privileges.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2005-1973

около 21 года назад

Java Web Start in Java 2 Platform Standard Edition (J2SE) 5.0 and 5.0 Update 1 allows applications to assign permissions to themselves and gain privileges.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2005-1972

около 21 года назад

Multiple SQL injection vulnerabilities in InteractivePHP FusionBB .11 Beta and earlier allow remote attackers to execute arbitrary SQL commands via (1) the username, which is not properly handled by the insertUser function, or (2) the bb_session_id value in a cookie.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1971

около 21 года назад

Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1970

около 21 года назад

Symantec pcAnywhere 10.5x and 11.x before 11.5, with "Launch with Windows" enabled, allows local users with physical access to execute arbitrary commands via the Caller Properties feature.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2005-1969

около 21 года назад

Cross-site scripting (XSS) vulnerability in Pragma Systems Telnetserver 6.0 allows remote attackers to inject arbitrary web script or HTML, and hide activities in log files, via a "<!--" (HTML comment) in a session.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-1968

около 21 года назад

Cross-site scripting (XSS) vulnerability in ProductCart Ecommerce before 2.7 allows remote attackers to inject arbitrary web script or HTML via the error parameter to techErr.asp.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-1967

около 21 года назад

Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1966

около 21 года назад

The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the etrace_host parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1965

около 21 года назад

PHP remote file inclusion vulnerability in siteframe.php for Broadpool Siteframe allows remote attackers to execute arbitrary code via a URL in the LOCAL_PATH parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1964

около 21 года назад

PHP remote file inclusion vulnerability in utilit.php for Ovidentia Portal allows remote attackers to execute arbitrary PHP code via the babInstallPath parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1963

около 21 года назад

Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which leaks the information in a PHP error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1962

около 21 года назад

Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3 allows remote attackers to inject arbitrary web script or HTML via the (1) errorcode parameter to index.php or (2) certain fields to clients.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-1961

около 21 года назад

Unknown vulnerability in ObjectWeb Consortium C-JDBC before 1.3.1 allows local users to bypass intended access restrictions and obtain the cache results from another user.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2005-1960

около 21 года назад

The getemails function in C.J. Steele Tattle allows remote attackers to execute arbitrary commands via shell metacharacters in certain log entries, as demonstrated using shell metacharacters in an FTP username.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1959

около 21 года назад

jammail.pl in jamchen JamMail 1.8 allows remote attackers to execute arbitrary commands via shell metacharacters in the mail parameter.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-1979

Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.

CVSS2: 5
33%
Средний
почти 21 год назад
nvd логотип
CVE-2005-1978

COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.

CVSS2: 7.5
53%
Средний
почти 21 год назад
nvd логотип
CVE-2005-1976

Novell NetMail 3.5.2a, 3.5.2b, and 3.5.2c, when running on Linux, sets the owner and group ID to 500 for certain files, which could allow users or groups with that ID to execute arbitrary code or cause a denial of service by modifying those files.

CVSS2: 1.7
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1975

Multiple cross-site scripting (XSS) vulnerabilities in Annuaire 1Two 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter to index.php, or the (2) site_id, (3) nom, (4) email, or (5) commentaire parameters in commentaires.php.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1974

Unspecified vulnerability in Java 2 Platform, Standard Edition (J2SE) 5.0 and 5.0 Update 1 and J2SE 1.4.2 up to 1.4.2_07, as used in multiple products and platforms including (1) HP-UX and (2) APC PowerChute, allows applications to assign permissions to themselves and gain privileges.

CVSS2: 5.1
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1973

Java Web Start in Java 2 Platform Standard Edition (J2SE) 5.0 and 5.0 Update 1 allows applications to assign permissions to themselves and gain privileges.

CVSS2: 5.1
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1972

Multiple SQL injection vulnerabilities in InteractivePHP FusionBB .11 Beta and earlier allow remote attackers to execute arbitrary SQL commands via (1) the username, which is not properly handled by the insertUser function, or (2) the bb_session_id value in a cookie.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1971

Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1970

Symantec pcAnywhere 10.5x and 11.x before 11.5, with "Launch with Windows" enabled, allows local users with physical access to execute arbitrary commands via the Caller Properties feature.

CVSS2: 7.2
0%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1969

Cross-site scripting (XSS) vulnerability in Pragma Systems Telnetserver 6.0 allows remote attackers to inject arbitrary web script or HTML, and hide activities in log files, via a "<!--" (HTML comment) in a session.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1968

Cross-site scripting (XSS) vulnerability in ProductCart Ecommerce before 2.7 allows remote attackers to inject arbitrary web script or HTML via the error parameter to techErr.asp.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1967

Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1966

The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the etrace_host parameter.

CVSS2: 7.5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1965

PHP remote file inclusion vulnerability in siteframe.php for Broadpool Siteframe allows remote attackers to execute arbitrary code via a URL in the LOCAL_PATH parameter.

CVSS2: 7.5
4%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1964

PHP remote file inclusion vulnerability in utilit.php for Ovidentia Portal allows remote attackers to execute arbitrary PHP code via the babInstallPath parameter.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1963

Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which leaks the information in a PHP error message.

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1962

Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3 allows remote attackers to inject arbitrary web script or HTML via the (1) errorcode parameter to index.php or (2) certain fields to clients.php.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1961

Unknown vulnerability in ObjectWeb Consortium C-JDBC before 1.3.1 allows local users to bypass intended access restrictions and obtain the cache results from another user.

CVSS2: 4.6
0%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1960

The getemails function in C.J. Steele Tattle allows remote attackers to execute arbitrary commands via shell metacharacters in certain log entries, as demonstrated using shell metacharacters in an FTP username.

CVSS2: 7.5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1959

jammail.pl in jamchen JamMail 1.8 allows remote attackers to execute arbitrary commands via shell metacharacters in the mail parameter.

CVSS2: 7.5
3%
Низкий
около 21 года назад

Уязвимостей на страницу