Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 504

Количество 372 504

nvd логотип

CVE-2005-0863

больше 21 года назад

Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or HTML via (1) the chatter parameter to regulars.php or (2) the chatter, chatter1, chatter2, chatter3, or chatter4 parameters to register.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0862

больше 21 года назад

Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter to (1) poc_loginform.php or (2) phpbb/poc.php, the poc_root_path parameter to (3) phpbb/poc.php, (4) phpnuke/ENGLISH_poc.php, (5) phpnuke/poc.php, or (6) yabbse/poc.php, or (7) the sourcedir parameter to yabbse/poc.php.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-0861

больше 21 года назад

Multiple buffer overflows in DeleGate before 8.11.1 may allow attackers to cause a denial of service or execute arbitrary code, possibly due to "overflows on arrays."

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0860

больше 21 года назад

PHP remote file inclusion vulnerability in TRG News Script 3.0 allows remote attackers to execute arbitrary PHP code via the dir parameter to (1) article.php, (2) authorall.php, (3) comment.php, (4) display.php, or (5) displayall.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0859

больше 21 года назад

PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlines.php or (2) news.php. NOTE: some sources have reported the "dir" parameter as being affected; however, this is likely a cut-and-paste error from the wrong section of the original vulnerability report. Also, the news.php version was later reported to be in 1.12 through 1.14.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-0858

больше 21 года назад

Multiple SQL injection vulnerabilities in CoolForum 0.8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to entete.php or (2) the login parameter to register.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0857

больше 21 года назад

Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the img parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0856

больше 21 года назад

CoolForum 0.8.1 beta and earlier allows remote attackers to manipulate SQL commands via certain requests to (1) alert.php or (2) viewip.php, possibly due to a SQL injection vulnerability.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0855

больше 21 года назад

CoolForum 0.8.1 beta and earlier allows remote attackers to obtain sensitive path information via direct requests to (1) entete.php, (2) profile_accueil.php, (3) profile_mdp.php, (4) profile_notify.php, (5) profile_options.php, (6) profile_perso.php, (7) profile_pm.php, or (8) readannonce.php, which leaks the full pathname in a PHP error message.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2005-0854

больше 21 года назад

betaparticle blog (bp blog), posisbly before version 4, allows remote attackers to bypass authentication and (1) upload files via a direct request to upload.asp or (2) delete files via a direct request to myFiles.asp.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0853

больше 21 года назад

betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive information via a direct request to (1) dbBlogMX.mdb for versions before 3.0, or (2) Blog.mdb for versions 3.0 and later. NOTE: it was later reported that vector 2 also affects versions 6.0 through 9.0.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0852

больше 21 года назад

Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-0851

больше 21 года назад

FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service (infinite loop) via certain file uploads or directory listings.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0850

больше 21 года назад

FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS device name such as CON, NUL, COM1, LPT1, and others.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0849

больше 21 года назад

Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service (crash from invalid memory access) via a malformed join packet with values that cause the server to copy more memory than was actually provided in the packet.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0848

больше 21 года назад

Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service via an empty UDP packet to the server, which cannot detect that a new packet has arrived using the socket ioctl.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0847

больше 21 года назад

Code Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0846

больше 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in the email auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject arbitrary web script or HTML via the (1) message subject or (2) message header field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0845

больше 21 года назад

Directory traversal vulnerability in the Webmail interface in SurgeMail 2.2g3 allows remote authenticated users to write arbitrary files or directories via a .. (dot dot) in the attach_id parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0844

больше 21 года назад

Nortel VPN client 5.01 stores the cleartext password in the memory of the Extranet.exe process, which could allow local users to obtain sensitive information.

CVSS2: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-0863

Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or HTML via (1) the chatter parameter to regulars.php or (2) the chatter, chatter1, chatter2, chatter3, or chatter4 parameters to register.php.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0862

Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter to (1) poc_loginform.php or (2) phpbb/poc.php, the poc_root_path parameter to (3) phpbb/poc.php, (4) phpnuke/ENGLISH_poc.php, (5) phpnuke/poc.php, or (6) yabbse/poc.php, or (7) the sourcedir parameter to yabbse/poc.php.

CVSS2: 7.5
11%
Средний
больше 21 года назад
nvd логотип
CVE-2005-0861

Multiple buffer overflows in DeleGate before 8.11.1 may allow attackers to cause a denial of service or execute arbitrary code, possibly due to "overflows on arrays."

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0860

PHP remote file inclusion vulnerability in TRG News Script 3.0 allows remote attackers to execute arbitrary PHP code via the dir parameter to (1) article.php, (2) authorall.php, (3) comment.php, (4) display.php, or (5) displayall.php.

CVSS2: 7.5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0859

PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlines.php or (2) news.php. NOTE: some sources have reported the "dir" parameter as being affected; however, this is likely a cut-and-paste error from the wrong section of the original vulnerability report. Also, the news.php version was later reported to be in 1.12 through 1.14.

CVSS2: 7.5
11%
Средний
больше 21 года назад
nvd логотип
CVE-2005-0858

Multiple SQL injection vulnerabilities in CoolForum 0.8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to entete.php or (2) the login parameter to register.php.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0857

Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the img parameter.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0856

CoolForum 0.8.1 beta and earlier allows remote attackers to manipulate SQL commands via certain requests to (1) alert.php or (2) viewip.php, possibly due to a SQL injection vulnerability.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0855

CoolForum 0.8.1 beta and earlier allows remote attackers to obtain sensitive path information via direct requests to (1) entete.php, (2) profile_accueil.php, (3) profile_mdp.php, (4) profile_notify.php, (5) profile_options.php, (6) profile_perso.php, (7) profile_pm.php, or (8) readannonce.php, which leaks the full pathname in a PHP error message.

CVSS2: 10
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0854

betaparticle blog (bp blog), posisbly before version 4, allows remote attackers to bypass authentication and (1) upload files via a direct request to upload.asp or (2) delete files via a direct request to myFiles.asp.

CVSS2: 7.5
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0853

betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive information via a direct request to (1) dbBlogMX.mdb for versions before 3.0, or (2) Blog.mdb for versions 3.0 and later. NOTE: it was later reported that vector 2 also affects versions 6.0 through 9.0.

CVSS2: 5
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0852

Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.

CVSS2: 2.1
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0851

FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service (infinite loop) via certain file uploads or directory listings.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0850

FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS device name such as CON, NUL, COM1, LPT1, and others.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0849

Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service (crash from invalid memory access) via a malformed join packet with values that cause the server to copy more memory than was actually provided in the packet.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0848

Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service via an empty UDP packet to the server, which cannot detect that a new packet has arrived using the socket ioctl.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0847

Code Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0846

Multiple cross-site scripting (XSS) vulnerabilities in the email auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject arbitrary web script or HTML via the (1) message subject or (2) message header field.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0845

Directory traversal vulnerability in the Webmail interface in SurgeMail 2.2g3 allows remote authenticated users to write arbitrary files or directories via a .. (dot dot) in the attach_id parameter.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0844

Nortel VPN client 5.01 stores the cleartext password in the memory of the Extranet.exe process, which could allow local users to obtain sensitive information.

CVSS2: 4.6
0%
Низкий
больше 21 года назад

Уязвимостей на страницу