Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 383 548

Количество 383 548

nvd логотип

CVE-2005-3308

почти 21 год назад

Multiple cross-site scripting (XSS) vulnerabilities in Zomplog 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) comment parameter in detail.php, (3) the username parameter in get.php, and (4) the search parameter in index.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-3307

почти 21 год назад

Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".." sequences in the (1) user parameter in a profile operation or (2) quale parameter in a newtopic operation.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-3306

почти 21 год назад

Cross-site scripting (XSS) vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the user parameter in a profile operation, a different vulnerability than CVE-2005-2814. NOTE: it is possible that this XSS is a resultant vulnerability of CVE-2005-3307.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-3305

почти 21 год назад

Multiple SQL injection vulnerabilities in Nuked Klan 1.7 allow remote attackers to execute arbitrary SQL commands via the (1) forum_id or (2) thread_id parameter in the Forum file, (3) the link_id in the Links file, (4) the artid parameter in the Sections file, and (5) the dl_id parameter in the Download file.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3304

почти 21 год назад

Multiple SQL injection vulnerabilities in PHP-Nuke 7.8 allow remote attackers to modify SQL queries and execute arbitrary PHP code via (1) the username parameter in the Your Account page, (2) the url parameter in the Downloads module, and (3) the description parameter in the Web_Links module.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3303

почти 21 год назад

The FSG unpacker (fsg.c) in Clam AntiVirus (ClamAV) 0.80 through 0.87 allows remote attackers to cause "memory corruption" and execute arbitrary code via a crafted FSG 1.33 file.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3302

почти 21 год назад

Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2005-3301

почти 21 год назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-3300

почти 21 год назад

The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform safety checks on values in the _FILES array for uploaded files, which allows remote attackers to include arbitrary files by using direct requests to library scripts that do not use grab_globals.php, then modifying certain configuration values for the theme.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-3299

почти 21 год назад

PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2005-3298

почти 21 год назад

Multiple buffer overflows in OpenWBEM on SuSE Linux 9 allow remote attackers to execute arbitrary code via unknown vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3297

почти 21 год назад

Multiple integer overflows in OpenWBEM on SuSE Linux 9 allow remote attackers to execute arbitrary code via unknown vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3296

почти 21 год назад

The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2005-3295

почти 21 год назад

Unspecified vulnerability in HP-UX B.11.23 on Itanium platforms allows local users to cause a denial of service due to a "specific stack size."

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-3294

почти 21 год назад

Typsoft FTP Server 1.11, with "Sub Directory Include" enabled, allows remote attackers to cause a denial of service (crash) by sending multiple RETR commands. NOTE: it was later reported that 1.10 is also affected.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-3293

почти 21 год назад

Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2) list directory contents via a trailing null character.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-3292

почти 21 год назад

Multiple cross-site scripting (XSS) vulnerabilities in Xeobook 0.93 allow remote attackers to inject arbitrary web script or HTML via Javascript events in tages such as <b>.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-3291

почти 21 год назад

Stani's Python Editor (SPE) 0.7.5 is installed with world-writable permissions, which allows local users to gain privileges by modifying executable files.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2005-3290

почти 21 год назад

SQL injection vulnerability in Accelerated Mortgage Manager allows remote attackers to execute arbitrary SQL commands via the password field.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3289

почти 21 год назад

LSCFG in IBM AIX 5.2 and 5.3 does not create temporary files securely, which allows local users to corrupt /etc/passwd and possibly other system files via the trace file.

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-3308

Multiple cross-site scripting (XSS) vulnerabilities in Zomplog 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) comment parameter in detail.php, (3) the username parameter in get.php, and (4) the search parameter in index.php.

CVSS2: 4.3
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3307

Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".." sequences in the (1) user parameter in a profile operation or (2) quale parameter in a newtopic operation.

CVSS2: 5
3%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3306

Cross-site scripting (XSS) vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the user parameter in a profile operation, a different vulnerability than CVE-2005-2814. NOTE: it is possible that this XSS is a resultant vulnerability of CVE-2005-3307.

CVSS2: 4.3
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3305

Multiple SQL injection vulnerabilities in Nuked Klan 1.7 allow remote attackers to execute arbitrary SQL commands via the (1) forum_id or (2) thread_id parameter in the Forum file, (3) the link_id in the Links file, (4) the artid parameter in the Sections file, and (5) the dl_id parameter in the Download file.

CVSS2: 7.5
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3304

Multiple SQL injection vulnerabilities in PHP-Nuke 7.8 allow remote attackers to modify SQL queries and execute arbitrary PHP code via (1) the username parameter in the Your Account page, (2) the url parameter in the Downloads module, and (3) the description parameter in the Web_Links module.

CVSS2: 7.5
6%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3303

The FSG unpacker (fsg.c) in Clam AntiVirus (ClamAV) 0.80 through 0.87 allows remote attackers to cause "memory corruption" and execute arbitrary code via a crafted FSG 1.33 file.

CVSS2: 7.5
7%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3302

Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.

CVSS3: 7.3
4%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3301

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.

CVSS2: 4.3
6%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3300

The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform safety checks on values in the _FILES array for uploaded files, which allows remote attackers to include arbitrary files by using direct requests to library scripts that do not use grab_globals.php, then modifying certain configuration values for the theme.

CVSS2: 5
3%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3299

PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.

CVSS2: 5
16%
Средний
почти 21 год назад
nvd логотип
CVE-2005-3298

Multiple buffer overflows in OpenWBEM on SuSE Linux 9 allow remote attackers to execute arbitrary code via unknown vectors.

CVSS2: 7.5
4%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3297

Multiple integer overflows in OpenWBEM on SuSE Linux 9 allow remote attackers to execute arbitrary code via unknown vectors.

CVSS2: 7.5
4%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3296

The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.

CVSS2: 10
6%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3295

Unspecified vulnerability in HP-UX B.11.23 on Itanium platforms allows local users to cause a denial of service due to a "specific stack size."

CVSS2: 2.1
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3294

Typsoft FTP Server 1.11, with "Sub Directory Include" enabled, allows remote attackers to cause a denial of service (crash) by sending multiple RETR commands. NOTE: it was later reported that 1.10 is also affected.

CVSS2: 5
8%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3293

Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2) list directory contents via a trailing null character.

CVSS2: 5
3%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3292

Multiple cross-site scripting (XSS) vulnerabilities in Xeobook 0.93 allow remote attackers to inject arbitrary web script or HTML via Javascript events in tages such as <b>.

CVSS2: 4.3
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3291

Stani's Python Editor (SPE) 0.7.5 is installed with world-writable permissions, which allows local users to gain privileges by modifying executable files.

CVSS2: 4.6
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3290

SQL injection vulnerability in Accelerated Mortgage Manager allows remote attackers to execute arbitrary SQL commands via the password field.

CVSS2: 7.5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-3289

LSCFG in IBM AIX 5.2 and 5.3 does not create temporary files securely, which allows local users to corrupt /etc/passwd and possibly other system files via the trace file.

CVSS2: 2.1
0%
Низкий
почти 21 год назад

Уязвимостей на страницу