CSV
184,048 results for "vulnerability" Page 147
CVE-2005-2428 Exploit

Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.

Aug 3, 2005 3 affected product(s) NVD
5.0
CVSS
73.0%
EPSS
⚡ 51.9
CVE-2005-1850

Certain contributed scripts for ekg Gadu Gadu client 1.5 and earlier create temporary files insecurely, with unknown impact and attack vectors, a different vulnerability than CVE-2005-1916.

Jul 19, 2005 11 affected product(s) NVD
10.0
CVSS
1.5%
EPSS
⚡ 40.5
CVE-2005-2409

Format string vulnerability in util.c in nbsmtp 0.99 and earlier, while running in debug mode, allows remote attackers to execute arbitrary code via format string specifiers that are not properly handled in a syslog call.

Aug 1, 2005 1 affected product(s) NVD
7.5
CVSS
9.9%
EPSS
⚡ 33
CVE-2005-2410

Format string vulnerability in the nm_info_handler function in Network Manager may allow remote attackers to execute arbitrary code via format string specifiers in a Wireless Access Point identifier, which is not properly handled in a syslog call.

Aug 1, 2005 1 affected product(s) NVD
7.5
CVSS
3.5%
EPSS
⚡ 31.1
CVE-2005-2321

PHP remote file inclusion vulnerability in CaLogic 1.2.2 allows remote attackers to execute arbitrary code via the CLPATH parameter to (1) cl_minical.php, (2) clmcpreload.php, (3) mcconfig.php, or (4) mcpi-demo.php.

Jul 19, 2005 1 affected product(s) NVD
7.5
CVSS
2.6%
EPSS
⚡ 30.8
CVE-2005-2383

SQL injection vulnerability in auth.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the user parameter in an HTTP POST request.

Jul 26, 2005 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2005-2404

SQL injection vulnerability in sendcard.php in Sendcard 3.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.

Jul 27, 2005 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2005-2432

SQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2) admin.

Aug 3, 2005 1 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2005-2307

netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function, aka "Network Connection Manager Vulnerability."

Jul 19, 2005 13 affected product(s) NVD
5.0
CVSS
25.6%
EPSS
⚡ 27.7
CVE-2005-2371

Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter. NOTE: this issue was probably fixed by REP06 in CPU Jan 2006, in which case it overlaps CVE-2006-0289.

Jul 26, 2005 4 affected product(s) NVD
5.0
CVSS
22.3%
EPSS
⚡ 26.7
CVE-2005-2330

Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote attackers to read arbitrary files via (1) .. sequences or (2) a full pathname in the readme_file parameter.

Jul 20, 2005 1 affected product(s) NVD
5.0
CVSS
9.6%
EPSS
⚡ 22.9
CVE-2005-2378

Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat parameters to rwservlet. NOTE: vector 2 is probably the same as CVE-2006-0289, and fixed in Jan 2006 CPU.

Jul 26, 2005 1 affected product(s) NVD
5.0
CVSS
9.1%
EPSS
⚡ 22.7
CVE-2005-2384

Directory traversal vulnerability in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460, allows remote attackers to write arbitrary files via an ACE archive containing filenames with (1) .. or (2) absolute pathnames.

Jul 27, 2005 3 affected product(s) NVD
5.0
CVSS
3.5%
EPSS
⚡ 21
CVE-2005-2411

Cross-Site Request Forgery (CSRF) vulnerability in tDiary 2.1.1, and tDiary 2.0.1 and earlier, allows remote attackers to conduct actions as another user, and execute commands on the server, via a URL that is activated by the user.

Aug 1, 2005 2 affected product(s) NVD
5.1
CVSS
1.9%
EPSS
⚡ 21
CVE-2005-2412

PHP remote file inclusion vulnerability in block.php in PHP FirstPost allows remote attackers to execute arbitrary PHP code via the Include parameter.

Aug 3, 2005 1 affected product(s) NVD
5.0
CVSS
2.6%
EPSS
⚡ 20.8
CVE-2005-1691

Directory traversal vulnerability in Internet Graphics Server in SAP before 6.40 Patch 11 allows remote attackers to read arbitrary files via ".." sequences in an HTTP GET request.

Jul 26, 2005 1 affected product(s) NVD
5.0
CVSS
1.5%
EPSS
⚡ 20.5
CVE-2005-2413

PHP remote file inclusion vulnerability in apa_phpinclude.inc.php in Atomic Photo Album (APA) allows remote attackers to execute arbitrary PHP code via the apa_module_basedir parameter.

Aug 3, 2005 10 affected product(s) NVD
5.0
CVSS
1.6%
EPSS
⚡ 20.5
CVE-2005-2319

PHP remote file include vulnerability in Yawp library 1.0.6 and earlier, as used in YaWiki and possibly other products, allows remote attackers to include arbitrary files via the _Yawp[conf_path] parameter.

Jul 19, 2005 7 affected product(s) NVD
5.0
CVSS
1.4%
EPSS
⚡ 20.4
CVE-2005-2328

PHP remote file inclusion vulnerability in im.php in Laffer 0.3.2.6 and 0.3.2.7 allows remote attackers to execute arbitrary PHP code via the CFG_PATH variable.

Jul 20, 2005 2 affected product(s) NVD
5.0
CVSS
1.4%
EPSS
⚡ 20.4
CVE-2005-2331

PHP remote file inclusion vulnerability in display.php in MooseGallery allows remote attackers to execute arbitrary PHP code via the type parameter.

Jul 20, 2005 2 affected product(s) NVD
5.0
CVSS
1.4%
EPSS
⚡ 20.4
← Previous Page 147 of 9203 Next →