Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 596

Количество 372 596

nvd логотип

CVE-2005-1092

больше 21 года назад

Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2005-1091

больше 21 года назад

Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes the max.src file into the source page.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1090

больше 21 года назад

Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arbitrary files.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-1089

больше 21 года назад

Unknown vulnerability in DC++ before 0.674 allows attackers to append data to arbitrary files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1088

больше 21 года назад

Unknown vulnerability in DameWare NT Utilities 4.8 and earlier, and Mini Remote Control 4.8 and earlier, allows local users to gain additional rights.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2005-1087

больше 21 года назад

CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and possibly read files using an injected type command, via CRLF sequences in an HTTP request.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-1086

больше 21 года назад

Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with a long User-Agent header.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-1085

больше 21 года назад

Cross-site scripting (XSS) vulnerability in the control panel in aeDating 3.2 allows remote attackers to inject arbitrary web script or HTML.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-1084

больше 21 года назад

SQL injection vulnerability in sdating.php in aeDating 3.2 allows remote attackers to execute arbitrary SQL commands files via the event parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1083

больше 21 года назад

index.php in aeDating 3.2 allows remote attackers to include arbitrary files via the skin parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1082

больше 21 года назад

Multiple SQL injection vulnerabilities in AzDGDatingPlatinum 1.1.0 allows remote attackers to execute arbitrary SQL commands via (1) the id parameter to view.php or (2) the from parameter to members/index.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1081

больше 21 года назад

Cross-site scripting (XSS) vulnerability in view.php in AzDGDatingPlatinum 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-1080

больше 21 года назад

Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1079

больше 21 года назад

SQL injection vulnerability in index.php for zOOm Media Gallery 2.1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1078

больше 21 года назад

XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1077

больше 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x allow remote attackers to inject arbitrary web script or HTML via (1) cds.php, (2) Guestbook-EN.pl, or (3) phonebook.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-1076

больше 21 года назад

Cross-site scripting (XSS) vulnerability in the discussion board functionality for WebCT Campus Edition 4.1 allows remote attackers to inject arbitrary web script or HTML via the message field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-1075

больше 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in RadScripts RadBids Gold 2 allow remote attackers to inject arbitrary web script or HTML via (1) the farea parameter to faq.php or the (2) cat, (3) order, or (4) area parameters to index.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-1074

больше 21 года назад

SQL injection vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to execute arbitrary SQL commands via the mode parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1073

больше 21 года назад

Directory traversal vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to read arbitrary files via the read parameter.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-1092

Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.

CVSS2: 7.2
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1091

Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes the max.src file into the source page.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1090

Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arbitrary files.

CVSS2: 6.4
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1089

Unknown vulnerability in DC++ before 0.674 allows attackers to append data to arbitrary files.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1088

Unknown vulnerability in DameWare NT Utilities 4.8 and earlier, and Mini Remote Control 4.8 and earlier, allows local users to gain additional rights.

CVSS2: 7.2
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1087

CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and possibly read files using an injected type command, via CRLF sequences in an HTTP request.

CVSS2: 6.4
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1086

Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with a long User-Agent header.

CVSS2: 6.4
6%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1085

Cross-site scripting (XSS) vulnerability in the control panel in aeDating 3.2 allows remote attackers to inject arbitrary web script or HTML.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1084

SQL injection vulnerability in sdating.php in aeDating 3.2 allows remote attackers to execute arbitrary SQL commands files via the event parameter.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1083

index.php in aeDating 3.2 allows remote attackers to include arbitrary files via the skin parameter.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1082

Multiple SQL injection vulnerabilities in AzDGDatingPlatinum 1.1.0 allows remote attackers to execute arbitrary SQL commands via (1) the id parameter to view.php or (2) the from parameter to members/index.php.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1081

Cross-site scripting (XSS) vulnerability in view.php in AzDGDatingPlatinum 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1080

Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.

CVSS2: 5
6%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1079

SQL injection vulnerability in index.php for zOOm Media Gallery 2.1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1078

XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges.

CVSS2: 7.5
5%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1077

Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x allow remote attackers to inject arbitrary web script or HTML via (1) cds.php, (2) Guestbook-EN.pl, or (3) phonebook.php.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1076

Cross-site scripting (XSS) vulnerability in the discussion board functionality for WebCT Campus Edition 4.1 allows remote attackers to inject arbitrary web script or HTML via the message field.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1075

Multiple cross-site scripting (XSS) vulnerabilities in RadScripts RadBids Gold 2 allow remote attackers to inject arbitrary web script or HTML via (1) the farea parameter to faq.php or the (2) cat, (3) order, or (4) area parameters to index.php.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1074

SQL injection vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to execute arbitrary SQL commands via the mode parameter.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1073

Directory traversal vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to read arbitrary files via the read parameter.

CVSS2: 5
8%
Низкий
больше 21 года назад

Уязвимостей на страницу