CSV
183,890 results for "vulnerability" Page 136
CVE-2005-1598

SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) that modifies the internal $pid variable.

May 16, 2005 9 affected product(s) NVD
7.5
CVSS
13.9%
EPSS
⚡ 34.2
CVE-2005-1681

PHP remote file inclusion vulnerability in common.php in phpATM 1.21, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the include_location parameter to index.php.

May 20, 2005 2 affected product(s) NVD
7.5
CVSS
6.6%
EPSS
⚡ 32
CVE-2005-1677

Unknown vulnerability in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allows remote attackers to bypass restrictions on COM objects.

May 20, 2005 3 affected product(s) NVD
7.5
CVSS
3.6%
EPSS
⚡ 31.1
CVE-2005-1609

Unknown vulnerability in Sun StorEdge 6130 Arrays (SE6130) with serial numbers between 0451AWF00G and 0513AWF00J allows local users and remote attackers to delete data.

May 16, 2005 1 affected product(s) NVD
7.5
CVSS
2.3%
EPSS
⚡ 30.7
CVE-2005-1612

SQL injection vulnerability in read.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to execute arbitrary SQL commands via the TID parameter.

May 16, 2005 1 affected product(s) NVD
7.5
CVSS
2.2%
EPSS
⚡ 30.6
CVE-2005-1615

viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 may allow remote attackers to read sensitive data via the postorder parameter, which is not properly handled by textdb.inc.php, possibly due to a SQL injection vulnerability.

May 16, 2005 4 affected product(s) NVD
7.5
CVSS
2.1%
EPSS
⚡ 30.6
CVE-2005-1629

SQL injection vulnerability in member.php for Photopost PHP Pro allows remote attackers to execute arbitrary SQL commands via the verifykey parameter.

May 17, 2005 8 affected product(s) NVD
7.5
CVSS
2.1%
EPSS
⚡ 30.6
CVE-2005-1602

SQL injection vulnerability in login.asp for Net56 Browser Based File Manager 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the password field.

May 16, 2005 1 affected product(s) NVD
7.5
CVSS
1.7%
EPSS
⚡ 30.5
CVE-2005-1454

SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries.

May 19, 2005 1 affected product(s) NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.5
CVE-2005-1594

SQL injection vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

May 16, 2005 1 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2005-1639

SQL injection vulnerability in Sigmaweb.DLL in Sigma ISP Manager 6.6 allows remote attackers to execute arbitrary SQL commands via the (1) username, (2) password, or (3) domain fields.

May 17, 2005 1 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2005-1642

SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable.

May 17, 2005 1 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2005-1651

Directory traversal vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in the wmm parameter.

May 18, 2005 1 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.4
CVE-2005-1630

Unknown vulnerability in Attachment Mod before 2.3.13, related to a "serious issue with realnames," has unknown impact and attack vectors.

May 17, 2005 9 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2005-1589

The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space and allows local users to cause a denial of service and possibly execute arbitrary code, a similar vulnerability to CVE-2005-1264.

May 17, 2005 1 affected product(s) NVD
7.2
CVSS
1.2%
EPSS
⚡ 29.2
CVE-2005-1264

Raw character devices (raw.c) in the Linux kernel 2.6.x call the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space, a similar vulnerability to CVE-2005-1589.

May 17, 2005 29 affected product(s) NVD
7.2
CVSS
0.5%
EPSS
⚡ 29
CVE-2005-1593

Cross-site scripting (XSS) vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

May 16, 2005 1 affected product(s) NVD
6.8
CVSS
4.2%
EPSS
⚡ 28.5
CVE-2005-1613

Cross-site scripting (XSS) vulnerability in member.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to inject arbitrary web script or HTML via the reverse parameter in a list action.

May 16, 2005 1 affected product(s) NVD
6.8
CVSS
3.7%
EPSS
⚡ 28.3
CVE-2005-1614

Cross-site scripting (XSS) vulnerability in viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the postorder parameter.

May 16, 2005 4 affected product(s) NVD
6.8
CVSS
3.7%
EPSS
⚡ 28.3
CVE-2005-1610

Cross-site scripting (XSS) vulnerability in security.php for Tru-Zone NukeET 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via a base64 encoded Codigo parameter.

May 16, 2005 2 affected product(s) NVD
6.8
CVSS
2.3%
EPSS
⚡ 27.9
← Previous Page 136 of 9195 Next →