Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 383 548

Количество 383 548

nvd логотип

CVE-2005-0276

больше 21 года назад

Multiple format string vulnerabilities in the FTP service in 3Com 3CDaemon 2.0 revision 10 allow remote attackers to cause a denial of service (application crash) via format string specifiers in (1) the username, (2) cd, (3) delete, (4) rename, (5) rmdir, (6) literal, (7) stat, or (8) CWD commands.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0275

больше 21 года назад

TFTP in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) via a GET request containing an MS-DOS device name.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0274

больше 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) si, (3) page, or (4) ppuser parameters.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0273

больше 21 года назад

Multiple SQL injection vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) ppuser parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0272

больше 21 года назад

ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review file with multiple extensions, which bypasses the intended restrictions.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0271

больше 21 года назад

Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) product parameter to addfav.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0270

больше 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to inject arbitrary web script or HTML via the (1) si parameter to showcat.php, (2) cat or (3) page parameter to showproduct.php, or (4) report parameter to reportproduct.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0269

больше 21 года назад

The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2005-0268

больше 21 года назад

Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url_avatar field.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0267

больше 21 года назад

index.php in FlatNuke 2.5.1 allows remote attackers to create an administrator account via carriage returns and #10 in the url_avatar field, which is interpreted as a sensitive directive.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0266

больше 21 года назад

Cross-site scripting (XSS) vulnerability in index.php in SugarCRM 1.X allows remote attackers to inject arbitrary web script or HTML via the (1) return_module, (2) return_action, (3) name, (4) module, or (5) record parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0265

больше 21 года назад

Multiple SQL injection vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to execute arbitrary SQL commands via the (1) parent or (2) sortposted parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0264

больше 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) expand or (2) order parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0263

больше 21 года назад

Buffer overflow in netpmon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -O argument.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2005-0262

больше 21 года назад

Buffer overflow in ipl_varyon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -d argument.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2005-0261

больше 21 года назад

lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-0260

больше 21 года назад

Stack-based buffer overflow in the Discovery Service for BrightStor ARCserve Backup 11.1 and earlier allows remote attackers to execute arbitrary code via a long packet to UDP port 41524, which is not properly handled in a recvfrom call.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2005-0259

больше 21 года назад

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-0258

больше 21 года назад

Directory traversal vulnerability in (1) usercp_register.php and (2) usercp_avatar.php for phpBB 2.0.11, and possibly other versions, with gallery avatars enabled, allows remote attackers to delete (unlink) arbitrary files via "/../" sequences in the avatarselect parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0256

больше 21 года назад

The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-0276

Multiple format string vulnerabilities in the FTP service in 3Com 3CDaemon 2.0 revision 10 allow remote attackers to cause a denial of service (application crash) via format string specifiers in (1) the username, (2) cd, (3) delete, (4) rename, (5) rmdir, (6) literal, (7) stat, or (8) CWD commands.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0275

TFTP in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) via a GET request containing an MS-DOS device name.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0274

Multiple cross-site scripting (XSS) vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) si, (3) page, or (4) ppuser parameters.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0273

Multiple SQL injection vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) ppuser parameter.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0272

ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review file with multiple extensions, which bypasses the intended restrictions.

CVSS2: 7.5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0271

Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) product parameter to addfav.php.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0270

Multiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to inject arbitrary web script or HTML via the (1) si parameter to showcat.php, (2) cat or (3) page parameter to showproduct.php, or (4) report parameter to reportproduct.php.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0269

The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters.

CVSS3: 9.8
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0268

Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url_avatar field.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0267

index.php in FlatNuke 2.5.1 allows remote attackers to create an administrator account via carriage returns and #10 in the url_avatar field, which is interpreted as a sensitive directive.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0266

Cross-site scripting (XSS) vulnerability in index.php in SugarCRM 1.X allows remote attackers to inject arbitrary web script or HTML via the (1) return_module, (2) return_action, (3) name, (4) module, or (5) record parameter.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0265

Multiple SQL injection vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to execute arbitrary SQL commands via the (1) parent or (2) sortposted parameter.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0264

Multiple cross-site scripting (XSS) vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) expand or (2) order parameter.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0263

Buffer overflow in netpmon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -O argument.

CVSS2: 7.2
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0262

Buffer overflow in ipl_varyon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -d argument.

CVSS2: 7.2
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0261

lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0260

Stack-based buffer overflow in the Discovery Service for BrightStor ARCserve Backup 11.1 and earlier allows remote attackers to execute arbitrary code via a long packet to UDP port 41524, which is not properly handled in a recvfrom call.

CVSS2: 10
70%
Средний
больше 21 года назад
nvd логотип
CVE-2005-0259

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

CVSS2: 6.4
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0258

Directory traversal vulnerability in (1) usercp_register.php and (2) usercp_avatar.php for phpBB 2.0.11, and possibly other versions, with gallery avatars enabled, allows remote attackers to delete (unlink) arbitrary files via "/../" sequences in the avatarselect parameter.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0256

The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command.

CVSS2: 5
5%
Низкий
больше 21 года назад

Уязвимостей на страницу