Vulnerabilities (CVE)

Total 258583 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-1653 1 Woppoware 1 Postmaster 2008-09-05 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to inject arbitrary web script or HTML via the email parameter.
CVE-2005-1652 1 Woppoware 1 Postmaster 2008-09-05 7.5 HIGH N/A
message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to bypass authentication by modifying the email parameter.
CVE-2005-1651 1 Woppoware 1 Postmaster 2008-09-05 7.5 HIGH N/A
Directory traversal vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in the wmm parameter.
CVE-2005-1648 1 Gurgens 1 Gurgens Ultimate Forum 2008-09-05 7.5 HIGH N/A
Gurgens (GASoft) Ultimate Forum 1.0 stores the db/Genid.dat database file under the web document root with insufficient access control, which allows remote attackers to obtain and decrypt usernames and passwords.
CVE-2005-1647 1 Gurgens 1 Gurgens Guest Book 2008-09-05 7.5 HIGH N/A
Gurgens (GASoft) Guest Book 2.1 stores the db/Genid.dat database file under the web document root with insufficient access control, which allows remote attackers to obtain and decrypt usernames and passwords.
CVE-2005-1641 1 The Ignition Project 1 Ignitionserver 2008-09-05 2.1 LOW N/A
mod_channel in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not allow protected operators to access channels that have been locked out by a key, which allows IRC users to cause a denial of service.
CVE-2005-1640 1 The Ignition Project 1 Ignitionserver 2008-09-05 7.5 HIGH N/A
mod_channel.bas in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not properly verify whether a host has the owner privileges required to delete IRC channel access entries, which allows remote attackers to bypass intended restrictions.
CVE-2005-1638 1 Pixel-apes Group 1 Safehtml 2008-09-05 4.3 MEDIUM N/A
The _writeAttrs function in SafeHTML before 1.3.2 does not properly handle quotes in attribute values, which could allow remote attackers to exploit cross-site scripting (XSS) vulnerabilities in applications that rely on SafeHTML for protection.
CVE-2005-1637 1 Npds 1 Npds 2008-09-05 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in NPDS 4.8 and 5.0 allow remote attackers to execute arbitrary SQL commands via the thold parameter to (1) comments.php or (2) pollcomments.php.
CVE-2005-1632 1 Tavis Rudd 1 Cheetah 2008-09-05 7.2 HIGH N/A
Cheetah 0.9.15 and 0.9.16 searches the /tmp directory for modules before using the paths in the PYTHONPATH variable, which allows local users to execute arbitrary code via a malicious module in /tmp/.
CVE-2005-1629 1 Photopost 1 Photopost Php Pro 2008-09-05 7.5 HIGH N/A
SQL injection vulnerability in member.php for Photopost PHP Pro allows remote attackers to execute arbitrary SQL commands via the verifykey parameter.
CVE-2005-1626 1 Pico Server 1 Pico Server 2008-09-05 7.5 HIGH N/A
Multiple buffer overflows in handlers.c for Pico Server (pServ) before 3.3 may allow attackers to execute arbitrary code.
CVE-2005-1625 1 Adobe 1 Acrobat Reader 2008-09-05 5.0 MEDIUM N/A
Stack-based buffer overflow in the UnixAppOpenFilePerform function in Adobe Reader 5.0.9 and 5.0.10 for Unix allows remote attackers to execute arbitrary code via a PDF document with a long /Filespec tag.
CVE-2005-1607 1 Remote Cart 1 Remote Cart 2008-09-05 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in shop.cgi in Remote Cart allows remote attackers to inject arbitrary web script or HTML via the (1) merchant or (2) demo parameters.
CVE-2005-1595 1 Codethat 1 Shoppingcart 2008-09-05 5.0 MEDIUM N/A
CodeThat ShoppingCart 1.3.1 stores config.ini under the web root, which allows remote attackers to obtain sensitive information via a direct request.
CVE-2005-1594 1 Codethat 1 Shoppingcart 2008-09-05 7.5 HIGH N/A
SQL injection vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2005-1593 1 Codethat 1 Shoppingcart 2008-09-05 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CVE-2005-1592 1 Birdblog 1 Birdblog 2008-09-05 7.5 HIGH N/A
Multiple "javascript vulerabilities in BB code" in BirdBlog before 1.3.1 allow remote attackers to inject arbitrary Javascript.
CVE-2005-1590 1 Altiris 2 Client Service, Deployment Solution 2008-09-05 4.6 MEDIUM N/A
The Altiris Client Service for Windows (ACLIENT.EXE) 6.0.88 allows local users to disable password protection and access the administrative interface by finding and showing the "Altiris Client Service" hidden window, disabling the password protection, disabling the "Hide client tray icon box" option, then opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2004-2070.
CVE-2005-1587 1 Open Solution 1 Quick.cart 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to inject arbitrary web script or HTML via the sWord parameter.