| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2005-1662 | 0.00 | — | 0.02 | May 18, 2005 | Directory traversal vulnerability in Jeuce Personal Web Server 2.13 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | |||
| CVE-2005-1663 | 0.00 | — | 0.02 | May 18, 2005 | Jeuce Personal Web Server 2.13 allows remote attackers to cause a denial of service (server crash) via a GET request beginning with "://". | |||
| CVE-2005-1664 | 0.02 | — | 0.19 | May 18, 2005 | The __VIEWSTATE functionality in Microsoft ASP.NET 1.x allows remote attackers to conduct replay attacks to (1) apply a ViewState generated from one view to a different view, (2) reuse ViewState information after the application's state has changed, or (3) use the ViewState to… | |||
| CVE-2005-1665 | 0.03 | — | 0.40 | May 18, 2005 | The __VIEWSTATE functionality in Microsoft ASP.NET 1.x, when not cryptographically signed, allows remote attackers to cause a denial of service (CPU consumption) via deeply nested markup. | |||
| CVE-2005-1666 | 0.05 | — | 0.10 | May 18, 2005 | Multiple buffer overflows in Orenosv HTTP/FTP Server 0.8.1 allow remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary code via long arguments to FTP commands such as MKD, RMD, or DELE, which are processed by the (1)… | |||
| CVE-2005-1667 | 0.03 | — | 0.03 | May 18, 2005 | DataTrac Activity Console 1.1 allows remote attackers to cause a denial of service via a long HTTP GET request. | |||
| CVE-2005-1668 | 0.00 | — | 0.02 | May 18, 2005 | YusASP Web Asset Manager 1.0 allows remote attackers to gain privileges via a direct request to assetmanager.asp. | |||
| CVE-2005-1264 | 0.00 | — | 0.01 | May 17, 2005 | Raw character devices (raw.c) in the Linux kernel 2.6.x call the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space, a similar vulnerability to CVE-2005-1589. | |||
| CVE-2005-1307 | 0.03 | — | 0.04 | May 17, 2005 | The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled… | |||
| CVE-2005-1589 | 0.03 | — | 0.01 | May 17, 2005 | The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space… | |||
| CVE-2005-1626 | — | 0.00 | — | 0.02 | May 17, 2005 | Multiple buffer overflows in handlers.c for Pico Server (pServ) before 3.3 may allow attackers to execute arbitrary code. | ||
| CVE-2005-1627 | 0.00 | — | 0.00 | May 17, 2005 | Unknown vulnerability in Viewglob before 2.0.1, related to "a potential security issue with the Viewglob display and ssh X forwarding," has unknown impact. | |||
| CVE-2005-1628 | 0.04 | — | 0.11 | May 17, 2005 | apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter. | |||
| CVE-2005-1629 | 0.03 | — | 0.02 | May 17, 2005 | SQL injection vulnerability in member.php for Photopost PHP Pro allows remote attackers to execute arbitrary SQL commands via the verifykey parameter. | |||
| CVE-2005-1630 | 0.00 | — | 0.01 | May 17, 2005 | Unknown vulnerability in Attachment Mod before 2.3.13, related to a "serious issue with realnames," has unknown impact and attack vectors. | |||
| CVE-2005-1631 | 0.00 | — | 0.01 | May 17, 2005 | booby.php in Booby 1.0.0 and earlier allows remote attackers to view private bookmarks by guessing item IDs. | |||
| CVE-2005-1632 | 0.00 | — | 0.00 | May 17, 2005 | Cheetah 0.9.15 and 0.9.16 searches the /tmp directory for modules before using the paths in the PYTHONPATH variable, which allows local users to execute arbitrary code via a malicious module in /tmp/. | |||
| CVE-2005-1633 | 0.03 | — | 0.02 | May 17, 2005 | Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) anzahl_beitraege parameter to jgs_portal.php, 2) year parameter to (jgs_portal_statistik.php, 3) year parameter to… | |||
| CVE-2005-1634 | 0.00 | — | 0.01 | May 17, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) anzahl_beitraege parameter to jgs_portal.php, (2) year parameter to jgs_portal_statistik.php, (3) year parameter… | |||
| CVE-2005-1635 | 0.00 | — | 0.01 | May 17, 2005 | JGS-XA JGS-Portal 3.0.2 and earlier allows remote attackers to obtain the full server path via direct requests to (1) jgs_portal_ref.php, (2) jgs_portal_land.php, (3) jgs_portal_log.php, (4) jgs_portal_global_sponsor.php, (5) jgs_portal_global.php, (6) jgs_portal_system.php, (7)… | |||
| CVE-2005-1636 | 0.00 | — | 0.01 | May 17, 2005 | mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file's contents. | |||
| CVE-2005-1637 | 0.03 | — | 0.01 | May 17, 2005 | Multiple SQL injection vulnerabilities in NPDS 4.8 and 5.0 allow remote attackers to execute arbitrary SQL commands via the thold parameter to (1) comments.php or (2) pollcomments.php. | |||
| CVE-2005-1638 | 0.00 | — | 0.01 | May 17, 2005 | The _writeAttrs function in SafeHTML before 1.3.2 does not properly handle quotes in attribute values, which could allow remote attackers to exploit cross-site scripting (XSS) vulnerabilities in applications that rely on SafeHTML for protection. | |||
| CVE-2005-1639 | 0.00 | — | 0.01 | May 17, 2005 | SQL injection vulnerability in Sigmaweb.DLL in Sigma ISP Manager 6.6 allows remote attackers to execute arbitrary SQL commands via the (1) username, (2) password, or (3) domain fields. | |||
| CVE-2005-1640 | 0.00 | — | 0.02 | May 17, 2005 | mod_channel.bas in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not properly verify whether a host has the owner privileges required to delete IRC channel access entries, which allows remote attackers to bypass intended restrictions. | |||
| CVE-2005-1641 | 0.00 | — | 0.00 | May 17, 2005 | mod_channel in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not allow protected operators to access channels that have been locked out by a key, which allows IRC users to cause a denial of service. | |||
| CVE-2005-1642 | 0.03 | — | 0.01 | May 17, 2005 | SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable. | |||
| CVE-2005-1643 | 0.00 | — | 0.02 | May 17, 2005 | The ZCom_BitStream::Deserialize function in Zoidcom 1.0 beta 4 and earlier allows remote attackers to cause a denial of service via a crafted UDP packet with a large size value, which causes a memory allocation error or an out-of-bounds read. | |||
| CVE-2005-1193 | 0.06 | — | 0.16 | May 16, 2005 | The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts, allow remote attackers to execute arbitrary script via a BBcode tag with a (1) javascript:, (2) applet:, (3) about:, (4)… | |||
| CVE-2005-1248 | 0.01 | — | 0.05 | May 16, 2005 | Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a crafted MPEG4 file. | |||
| CVE-2005-1365 | 0.04 | — | 0.12 | May 16, 2005 | Pico Server (pServ) 3.2 and earlier allows remote attackers to execute arbitrary commands via a URL with multiple leading "/" (slash) characters and ".." sequences. | |||
| CVE-2005-1366 | 0.03 | — | 0.07 | May 16, 2005 | Pico Server (pServ) 3.2 and earlier allows remote attackers to obtain the source code for CGI scripts via "dirname/../cgi-bin" in a URL. | |||
| CVE-2005-1367 | 0.00 | — | 0.01 | May 16, 2005 | Pico Server (pServ) 3.2 and earlier allows local users to read arbitrary files as the pServ user via a symlink to a file outside of the web document root. | |||
| CVE-2005-1590 | 0.03 | — | 0.01 | May 16, 2005 | The Altiris Client Service for Windows (ACLIENT.EXE) 6.0.88 allows local users to disable password protection and access the administrative interface by finding and showing the "Altiris Client Service" hidden window, disabling the password protection, disabling the "Hide client… | |||
| CVE-2005-1591 | 0.00 | — | 0.01 | May 16, 2005 | Unknown vulnerability in NIS+ on Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (rpc.nisd disabled and NIS+ unavailable) via unknown vectors. | |||
| CVE-2005-1592 | 0.00 | — | 0.01 | May 16, 2005 | Multiple "javascript vulerabilities in BB code" in BirdBlog before 1.3.1 allow remote attackers to inject arbitrary Javascript. | |||
| CVE-2005-1593 | 0.03 | — | 0.04 | May 16, 2005 | Cross-site scripting (XSS) vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |||
| CVE-2005-1594 | 0.03 | — | 0.01 | May 16, 2005 | SQL injection vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||
| CVE-2005-1595 | 0.00 | — | 0.02 | May 16, 2005 | CodeThat ShoppingCart 1.3.1 stores config.ini under the web root, which allows remote attackers to obtain sensitive information via a direct request. | |||
| CVE-2005-1596 | 0.00 | — | 0.07 | May 16, 2005 | index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter. | |||
| CVE-2005-1597 | 0.03 | — | 0.02 | May 16, 2005 | Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlite parameter. | |||
| CVE-2005-1598 | 0.04 | — | 0.14 | May 16, 2005 | SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) that modifies the internal $pid variable. | |||
| CVE-2005-1599 | 0.00 | — | 0.01 | May 16, 2005 | Cross-site scripting (XSS) vulnerability in Kryloff Technologies Subject Search Server (SSServer) 1.1 allows remote attackers to inject arbitrary web script or HTML via the "Search For" field. | |||
| CVE-2005-1600 | 0.00 | — | 0.01 | May 16, 2005 | A "mathematical flaw" in the implementation of the El Gamal signature algorithm for LibTomCrypt 1.0 to 1.0.2 allows attackers to generate valid signatures without having the private key. | |||
| CVE-2005-1601 | 0.00 | — | 0.01 | May 16, 2005 | MRO Maximo Self Service 4 and 5 stores certain information under the web document root using file extensions that are not processed by Tomcat, which allows remote attackers to obtain sensitive information via a direct request for the file, such as MXServer.properties. | |||
| CVE-2005-1602 | — | 0.00 | — | 0.02 | May 16, 2005 | SQL injection vulnerability in login.asp for Net56 Browser Based File Manager 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the password field. | ||
| CVE-2005-1603 | 0.03 | — | 0.03 | May 16, 2005 | NiteEnterprises Remote File Manager 1.0 allows remote attackers to cause a denial of service (crash) via a crafted string to TCP port 7080. | |||
| CVE-2005-1604 | 0.04 | — | 0.05 | May 16, 2005 | PHP Advanced Transfer Manager (phpATM) 1.21 allows remote attackers to upload arbitrary files via filenames containing multiple file extensions, as demonstrated using a filename ending in "php.ns", which allows execution of arbitrary PHP code. | |||
| CVE-2005-1605 | 0.00 | — | 0.02 | May 16, 2005 | Cross-site scripting (XSS) vulnerability in the guestbook for SiteStudio 1.6 allows remote attackers to inject arbitrary web script or HTML via the name field to (1) psoft.guestbook.GuestBookServ in Standalone Site Studio or (2) E-Guest_sign.pl in Integrated Site Studio with… | |||
| CVE-2005-1606 | 0.03 | — | 0.01 | May 16, 2005 | H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges. |
- CVE-2005-1662May 18, 2005risk 0.00cvss —epss 0.02
Directory traversal vulnerability in Jeuce Personal Web Server 2.13 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
- CVE-2005-1663May 18, 2005risk 0.00cvss —epss 0.02
Jeuce Personal Web Server 2.13 allows remote attackers to cause a denial of service (server crash) via a GET request beginning with "://".
- CVE-2005-1664May 18, 2005risk 0.02cvss —epss 0.19
The __VIEWSTATE functionality in Microsoft ASP.NET 1.x allows remote attackers to conduct replay attacks to (1) apply a ViewState generated from one view to a different view, (2) reuse ViewState information after the application's state has changed, or (3) use the ViewState to…
- CVE-2005-1665May 18, 2005risk 0.03cvss —epss 0.40
The __VIEWSTATE functionality in Microsoft ASP.NET 1.x, when not cryptographically signed, allows remote attackers to cause a denial of service (CPU consumption) via deeply nested markup.
- CVE-2005-1666May 18, 2005risk 0.05cvss —epss 0.10
Multiple buffer overflows in Orenosv HTTP/FTP Server 0.8.1 allow remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary code via long arguments to FTP commands such as MKD, RMD, or DELE, which are processed by the (1)…
- CVE-2005-1667May 18, 2005risk 0.03cvss —epss 0.03
DataTrac Activity Console 1.1 allows remote attackers to cause a denial of service via a long HTTP GET request.
- CVE-2005-1668May 18, 2005risk 0.00cvss —epss 0.02
YusASP Web Asset Manager 1.0 allows remote attackers to gain privileges via a direct request to assetmanager.asp.
- CVE-2005-1264May 17, 2005risk 0.00cvss —epss 0.01
Raw character devices (raw.c) in the Linux kernel 2.6.x call the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space, a similar vulnerability to CVE-2005-1589.
- CVE-2005-1307May 17, 2005risk 0.03cvss —epss 0.04
The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled…
- CVE-2005-1589May 17, 2005risk 0.03cvss —epss 0.01
The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space…
- CVE-2005-1626May 17, 2005risk 0.00cvss —epss 0.02
Multiple buffer overflows in handlers.c for Pico Server (pServ) before 3.3 may allow attackers to execute arbitrary code.
- CVE-2005-1627May 17, 2005risk 0.00cvss —epss 0.00
Unknown vulnerability in Viewglob before 2.0.1, related to "a potential security issue with the Viewglob display and ssh X forwarding," has unknown impact.
- CVE-2005-1628May 17, 2005risk 0.04cvss —epss 0.11
apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.
- CVE-2005-1629May 17, 2005risk 0.03cvss —epss 0.02
SQL injection vulnerability in member.php for Photopost PHP Pro allows remote attackers to execute arbitrary SQL commands via the verifykey parameter.
- CVE-2005-1630May 17, 2005risk 0.00cvss —epss 0.01
Unknown vulnerability in Attachment Mod before 2.3.13, related to a "serious issue with realnames," has unknown impact and attack vectors.
- CVE-2005-1631May 17, 2005risk 0.00cvss —epss 0.01
booby.php in Booby 1.0.0 and earlier allows remote attackers to view private bookmarks by guessing item IDs.
- CVE-2005-1632May 17, 2005risk 0.00cvss —epss 0.00
Cheetah 0.9.15 and 0.9.16 searches the /tmp directory for modules before using the paths in the PYTHONPATH variable, which allows local users to execute arbitrary code via a malicious module in /tmp/.
- CVE-2005-1633May 17, 2005risk 0.03cvss —epss 0.02
Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) anzahl_beitraege parameter to jgs_portal.php, 2) year parameter to (jgs_portal_statistik.php, 3) year parameter to…
- CVE-2005-1634May 17, 2005risk 0.00cvss —epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) anzahl_beitraege parameter to jgs_portal.php, (2) year parameter to jgs_portal_statistik.php, (3) year parameter…
- CVE-2005-1635May 17, 2005risk 0.00cvss —epss 0.01
JGS-XA JGS-Portal 3.0.2 and earlier allows remote attackers to obtain the full server path via direct requests to (1) jgs_portal_ref.php, (2) jgs_portal_land.php, (3) jgs_portal_log.php, (4) jgs_portal_global_sponsor.php, (5) jgs_portal_global.php, (6) jgs_portal_system.php, (7)…
- CVE-2005-1636May 17, 2005risk 0.00cvss —epss 0.01
mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file's contents.
- CVE-2005-1637May 17, 2005risk 0.03cvss —epss 0.01
Multiple SQL injection vulnerabilities in NPDS 4.8 and 5.0 allow remote attackers to execute arbitrary SQL commands via the thold parameter to (1) comments.php or (2) pollcomments.php.
- CVE-2005-1638May 17, 2005risk 0.00cvss —epss 0.01
The _writeAttrs function in SafeHTML before 1.3.2 does not properly handle quotes in attribute values, which could allow remote attackers to exploit cross-site scripting (XSS) vulnerabilities in applications that rely on SafeHTML for protection.
- CVE-2005-1639May 17, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in Sigmaweb.DLL in Sigma ISP Manager 6.6 allows remote attackers to execute arbitrary SQL commands via the (1) username, (2) password, or (3) domain fields.
- CVE-2005-1640May 17, 2005risk 0.00cvss —epss 0.02
mod_channel.bas in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not properly verify whether a host has the owner privileges required to delete IRC channel access entries, which allows remote attackers to bypass intended restrictions.
- CVE-2005-1641May 17, 2005risk 0.00cvss —epss 0.00
mod_channel in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not allow protected operators to access channels that have been locked out by a key, which allows IRC users to cause a denial of service.
- CVE-2005-1642May 17, 2005risk 0.03cvss —epss 0.01
SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable.
- CVE-2005-1643May 17, 2005risk 0.00cvss —epss 0.02
The ZCom_BitStream::Deserialize function in Zoidcom 1.0 beta 4 and earlier allows remote attackers to cause a denial of service via a crafted UDP packet with a large size value, which causes a memory allocation error or an out-of-bounds read.
- CVE-2005-1193May 16, 2005risk 0.06cvss —epss 0.16
The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts, allow remote attackers to execute arbitrary script via a BBcode tag with a (1) javascript:, (2) applet:, (3) about:, (4)…
- CVE-2005-1248May 16, 2005risk 0.01cvss —epss 0.05
Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a crafted MPEG4 file.
- CVE-2005-1365May 16, 2005risk 0.04cvss —epss 0.12
Pico Server (pServ) 3.2 and earlier allows remote attackers to execute arbitrary commands via a URL with multiple leading "/" (slash) characters and ".." sequences.
- CVE-2005-1366May 16, 2005risk 0.03cvss —epss 0.07
Pico Server (pServ) 3.2 and earlier allows remote attackers to obtain the source code for CGI scripts via "dirname/../cgi-bin" in a URL.
- CVE-2005-1367May 16, 2005risk 0.00cvss —epss 0.01
Pico Server (pServ) 3.2 and earlier allows local users to read arbitrary files as the pServ user via a symlink to a file outside of the web document root.
- CVE-2005-1590May 16, 2005risk 0.03cvss —epss 0.01
The Altiris Client Service for Windows (ACLIENT.EXE) 6.0.88 allows local users to disable password protection and access the administrative interface by finding and showing the "Altiris Client Service" hidden window, disabling the password protection, disabling the "Hide client…
- CVE-2005-1591May 16, 2005risk 0.00cvss —epss 0.01
Unknown vulnerability in NIS+ on Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (rpc.nisd disabled and NIS+ unavailable) via unknown vectors.
- CVE-2005-1592May 16, 2005risk 0.00cvss —epss 0.01
Multiple "javascript vulerabilities in BB code" in BirdBlog before 1.3.1 allow remote attackers to inject arbitrary Javascript.
- CVE-2005-1593May 16, 2005risk 0.03cvss —epss 0.04
Cross-site scripting (XSS) vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
- CVE-2005-1594May 16, 2005risk 0.03cvss —epss 0.01
SQL injection vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2005-1595May 16, 2005risk 0.00cvss —epss 0.02
CodeThat ShoppingCart 1.3.1 stores config.ini under the web root, which allows remote attackers to obtain sensitive information via a direct request.
- CVE-2005-1596May 16, 2005risk 0.00cvss —epss 0.07
index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter.
- CVE-2005-1597May 16, 2005risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlite parameter.
- CVE-2005-1598May 16, 2005risk 0.04cvss —epss 0.14
SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) that modifies the internal $pid variable.
- CVE-2005-1599May 16, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Kryloff Technologies Subject Search Server (SSServer) 1.1 allows remote attackers to inject arbitrary web script or HTML via the "Search For" field.
- CVE-2005-1600May 16, 2005risk 0.00cvss —epss 0.01
A "mathematical flaw" in the implementation of the El Gamal signature algorithm for LibTomCrypt 1.0 to 1.0.2 allows attackers to generate valid signatures without having the private key.
- CVE-2005-1601May 16, 2005risk 0.00cvss —epss 0.01
MRO Maximo Self Service 4 and 5 stores certain information under the web document root using file extensions that are not processed by Tomcat, which allows remote attackers to obtain sensitive information via a direct request for the file, such as MXServer.properties.
- CVE-2005-1602May 16, 2005risk 0.00cvss —epss 0.02
SQL injection vulnerability in login.asp for Net56 Browser Based File Manager 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the password field.
- CVE-2005-1603May 16, 2005risk 0.03cvss —epss 0.03
NiteEnterprises Remote File Manager 1.0 allows remote attackers to cause a denial of service (crash) via a crafted string to TCP port 7080.
- CVE-2005-1604May 16, 2005risk 0.04cvss —epss 0.05
PHP Advanced Transfer Manager (phpATM) 1.21 allows remote attackers to upload arbitrary files via filenames containing multiple file extensions, as demonstrated using a filename ending in "php.ns", which allows execution of arbitrary PHP code.
- CVE-2005-1605May 16, 2005risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in the guestbook for SiteStudio 1.6 allows remote attackers to inject arbitrary web script or HTML via the name field to (1) psoft.guestbook.GuestBookServ in Standalone Site Studio or (2) E-Guest_sign.pl in Integrated Site Studio with…
- CVE-2005-1606May 16, 2005risk 0.03cvss —epss 0.01
H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.