CSV
184,029 results for "vulnerability" Page 143
CVE-2005-2086 Exploit

PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.

Jul 5, 2005 1 affected product(s) NVD
7.5
CVSS
85.4%
EPSS
⚡ 65.6
CVE-2005-1921 Exploit

Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.

Jul 5, 2005 6 affected product(s) NVD
7.5
CVSS
79.1%
EPSS
⚡ 63.7
CVE-2005-1250

SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for IpSwitch WhatsUp Professional 2005 SP1 allows remote attackers to execute arbitrary SQL commands via the (1) User Name field (sUserName parameter) or (2) Password (sPassword parameter).

Jun 22, 2005 1 affected product(s) NVD
7.5
CVSS
20.9%
EPSS
⚡ 36.3
CVE-2005-1526

PHP remote file inclusion vulnerability in config_settings.php in Cacti before 0.8.6e allows remote attackers to execute arbitrary PHP code via the config[include_path] parameter.

Jun 22, 2005 20 affected product(s) NVD
7.5
CVSS
16.6%
EPSS
⚡ 35
CVE-2005-2108

SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.

Jul 5, 2005 7 affected product(s) NVD
7.5
CVSS
9.3%
EPSS
⚡ 32.8
CVE-2005-2155

PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.

Jul 6, 2005 1 affected product(s) NVD
7.5
CVSS
3.4%
EPSS
⚡ 31
CVE-2005-2154

PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and possibly execute arbitrary local files via the inc parameter.

Jul 6, 2005 3 affected product(s) NVD
7.5
CVSS
2.4%
EPSS
⚡ 30.7
CVE-2005-2028

SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.

Jun 21, 2005 1 affected product(s) NVD
7.5
CVSS
2.1%
EPSS
⚡ 30.6
CVE-2005-1525

SQL injection vulnerability in config_settings.php for Cacti before 0.8.6e allows remote attackers to execute arbitrary SQL commands via the id parameter.

Jun 22, 2005 20 affected product(s) NVD
7.5
CVSS
1.9%
EPSS
⚡ 30.6
CVE-2005-2080

Unknown vulnerability in Remote Agent for Windows Servers (RAWS) in VERITAS Backup Exec 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for NetWare, allows remote attackers to gain privileges by copying the handle for the server.

Jun 29, 2005 17 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.5
CVE-2005-2113

SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger.getPost method.

Jul 5, 2005 15 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2005-2152

SQL injection vulnerability in Geeklog before 1.3.11 allows remote attackers to execute arbitrary SQL commands via user comments for an article.

Jul 6, 2005 19 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2005-2153

SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable.

Jul 6, 2005 3 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2005-2066

SQL injection vulnerability in comment_post.asp in ASP Nuke 0.80 allows remote attackers to execute arbitrary SQL statements via the TaskID parameter.

Jun 29, 2005 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2005-2067

SQL injection vulnerability in article.asp in unknown versions of aspnuke allows remote attackers to execute arbitrary SQL commands via the articleid parameter.

Jun 29, 2005 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2005-2135

SQL injection vulnerability in verify.asp in EtoShop Dynamic Biz Website Builder (QuickWeb) 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) T1 or (2) T2 parameters.

Jul 5, 2005 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2005-2156

SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter.

Jul 6, 2005 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2005-1524

PHP file inclusion vulnerability in top_graph_header.php in Cacti 0.8.6d and possibly earlier versions allows remote attackers to execute arbitrary PHP code via the config[library_path] parameter.

Jun 22, 2005 20 affected product(s) NVD
5.0
CVSS
15.9%
EPSS
⚡ 24.8
CVE-2005-2033

Directory traversal vulnerability in folderview.asp for Blue-Collar Productions i-Gallery 3.3 allows remote attackers to read arbitrary files and directories via the folder parameter.

Jun 20, 2005 1 affected product(s) NVD
5.0
CVSS
7.5%
EPSS
⚡ 22.2
CVE-2005-2106

Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.

Jul 5, 2005 6 affected product(s) NVD
5.0
CVSS
3.2%
EPSS
⚡ 21
← Previous Page 143 of 9202 Next →