Total
29618 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2005-4082 | 1 Qnx | 1 Qnx | 2025-04-03 | N/A |
The dhcp.client program for QNX 4.25 vmware is setuid, possibly by default, which allows local users to modify the NIC configuration and conduct other attacks. | ||||
CVE-2005-4083 | 1 Phpbb Styles | 1 Extreme Styles Phpbb Module | 2025-04-03 | N/A |
Directory traversal vulnerability in xs_edit.php in the eXtreme Styles phpBB module 2.2.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the edit parameter. | ||||
CVE-2005-4084 | 1 Phpbb Styles | 1 Phpbb Extreme Styles | 2025-04-03 | N/A |
xs_edit.php in the phpBB eXtreme Styles module 2.2.1 and earlier allows remote attackers to obtain the installation path of the application via an invalid viewbackup parameter. | ||||
CVE-2005-4143 | 1 Lyris | 1 List Manager | 2025-04-03 | N/A |
SQL injection vulnerability in Lyris ListManager 5.0 through 8.9a allows remote attackers to execute arbitrary SQL commands via SQL code after a numeric argument to a /read/attachment URL. | ||||
CVE-2005-4144 | 1 Lyris | 1 List Manager | 2025-04-03 | N/A |
Lyris ListManager 5.0 through 8.9a allows remote attackers to add "ORDER BY" columns to SQL queries via unusual whitespace characters in the orderby parameter, such as (1) newlines and (2) 0xFF (ASCII 255) characters, which are interpreted as whitespace. | ||||
CVE-2005-4145 | 1 Lyris Technologies Inc | 1 Listmanager | 2025-04-03 | N/A |
The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with a small search space ("lyris" and up to 5 digits, possibly from the process ID), which allows remote attackers to gain access via a brute force attack. | ||||
CVE-2005-4146 | 1 Lyris Technologies Inc | 1 Listmanager | 2025-04-03 | N/A |
Lyris ListManager before 8.9b allows remote attackers to obtain sensitive information via a request to the TCLHTTPd status module, which provides sensitive server configuration information. | ||||
CVE-2005-4148 | 1 Lyris Technologies Inc | 1 Listmanager | 2025-04-03 | N/A |
Lyris ListManager 8.5, and possibly other versions before 8.8, includes sensitive information in the env hidden variable, which allows remote attackers to obtain information such as the installation path by requesting a non-existent page and reading the env variable from the resulting error message page. | ||||
CVE-2005-4150 | 1 Broadcom | 1 Cleverpath Portal | 2025-04-03 | N/A |
Cross-site scripting (XSS) vulnerability in the portal login page in Computer Associates CleverPath 4.7 allows remote attackers to execute Javascript via unknown vectors. | ||||
CVE-2005-4177 | 1 Cfmagic | 2 Magic Book Personal, Magic Book Professional | 2025-04-03 | N/A |
Cross-site scripting (XSS) vulnerability in book.cfm in Magic Book Personal and Professional 2.0 allows remote attackers to inject arbitrary web script or HTML via the StartRow parameter. | ||||
CVE-2005-4178 | 2 Debian, Dropbear Ssh Project | 2 Debian Linux, Dropbear Ssh | 2025-04-03 | N/A |
Buffer overflow in Dropbear server before 0.47 allows authenticated users to execute arbitrary code via unspecified inputs that cause insufficient memory to be allocated due to an incorrect expression that does not enforce the proper order of operations. | ||||
CVE-2005-4207 | 1 Btgrup | 1 Admin Webcontroller Script | 2025-04-03 | N/A |
SQL injection vulnerability in BTGrup Admin WebController Script allows remote attackers to execute SQL commands via the (1) Username and (2) Password fields. | ||||
CVE-2005-4211 | 1 Coinsoft Technologies | 1 Phpcoin | 2025-04-03 | N/A |
PHP remote file inclusion vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the $_CCFG[_PKG_PATH_DBSE] variable. | ||||
CVE-2005-4212 | 1 Coinsoft Technologies | 1 Phpcoin | 2025-04-03 | N/A |
Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via ".." (dot dot) sequences in the $_CCFG[_PKG_PATH_DBSE] variable. | ||||
CVE-2005-4213 | 1 Coinsoft Technologies | 1 Phpcoin | 2025-04-03 | N/A |
SQL injection vulnerability in mod.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary SQL commands via the phpcoinsessid cookie. | ||||
CVE-2005-4233 | 1 Php Web Scripts | 1 Ad Manager Pro | 2025-04-03 | N/A |
SQL injection vulnerability in advertiser_statistic.php in Ad Manager Pro 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ad_number parameter. | ||||
CVE-2005-4234 | 1 Powerdev | 1 Encapsgallery | 2025-04-03 | N/A |
SQL injection vulnerability in gallery.php in EncapsGallery 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | ||||
CVE-2005-4235 | 1 Whmcompletesolution | 1 Whmcompletesolution | 2025-04-03 | N/A |
Cross-site scripting (XSS) vulnerability in knowledgebase.php in WHMCompleteSolution 2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameters. | ||||
CVE-2005-4236 | 1 Cartkeeper | 1 Ckgold Shopping Cart | 2025-04-03 | N/A |
Cross-site scripting (XSS) vulnerability in search.php in CKGOLD allows remote attackers to inject arbitrary web script or HTML via the search parameters. | ||||
CVE-2005-4238 | 1 Mantis | 1 Mantis | 2025-04-03 | N/A |
Cross-site scripting (XSS) vulnerability in view_filters_page.php in Mantis 1.0.0rc3 and earlier allows remote attackers to inject arbitrary web script or HTML via the target_field parameter. |