CSV
184,060 results for "vulnerability" Page 154
CVE-2005-2852

Unknown vulnerability in CIFS.NLM in Novell Netware 6.5 SP2 and SP3, 5.1, and 6.0 allows remote attackers to cause a denial of service (ABEND) via an incorrect password length, as exploited by the "worm.rbot.ccc" worm.

Sep 8, 2005 4 affected product(s) NVD
5.0
CVSS
40.3%
EPSS
⚡ 32.1
CVE-2005-2846

PHP remote file inclusion vulnerability in lang.php in CMS Made Simple 0.10 and earlier allows remote attackers to execute arbitrary PHP code via the nls[file][vx][vxsfx] parameter.

Sep 8, 2005 1 affected product(s) NVD
7.5
CVSS
6.8%
EPSS
⚡ 32
CVE-2005-1857

Format string vulnerability in simpleproxy before 3.4 allows remote malicious HTTP proxies to execute arbitrary code via format string specifiers in a reply.

Sep 2, 2005 4 affected product(s) NVD
7.5
CVSS
4.3%
EPSS
⚡ 31.3
CVE-2005-2775

php_api.php in phpWebNotes 2.0.0 uses the extract function to modify key variables such as $t_path_core, which leads to a PHP file inclusion vulnerability that allows remote attackers to execute arbitrary PHP code via the t_path_core parameter.

Sep 2, 2005 1 affected product(s) NVD
7.5
CVSS
2.6%
EPSS
⚡ 30.8
CVE-2005-2782

PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs.

Sep 2, 2005 1 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2005-2793

PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter.

Sep 2, 2005 2 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2005-2778

SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL statements via the fid parameter.

Sep 2, 2005 4 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2005-2784

SQL injection vulnerability in the login function for the administration login panel in cosmoshop 8.10.78 allows remote attackers to execute arbitrary SQL commands and bypass authentication via unspecified vectors.

Sep 2, 2005 1 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2005-2838

SQL injection vulnerability in login.php in myBloggie 2.1.3-beta and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.

Sep 7, 2005 3 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2005-2867

SQL injection vulnerability in BlueWhaleCRM allows remote attackers to execute arbitrary SQL commands via the Account ID field.

Sep 8, 2005 2 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2005-2849

Argument injection vulnerability in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to (1) read portions of source code via the -f option to Dig (dig_device.cgi), (2) determine file existence via the -r argument to Tcpdump (tcpdump_device.cgi) or (3) modify files in the cgi-bin directory via the -w argument to Tcpdump.

Sep 8, 2005 2 affected product(s) NVD
6.4
CVSS
1.4%
EPSS
⚡ 26
CVE-2005-2792

Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page parameter.

Sep 2, 2005 2 affected product(s) NVD
5.0
CVSS
11.7%
EPSS
⚡ 23.5
CVE-2005-2848

Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.

Sep 8, 2005 2 affected product(s) NVD
5.0
CVSS
8.8%
EPSS
⚡ 22.6
CVE-2005-2813

Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) characters in the id parameter to the read mod in index.php.

Sep 7, 2005 1 affected product(s) NVD
5.0
CVSS
6.9%
EPSS
⚡ 22.1
CVE-2005-2774

Format string vulnerability in Lithium II mod 1.24 for Quake 2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in the nickname.

Sep 2, 2005 1 affected product(s) NVD
5.0
CVSS
2.8%
EPSS
⚡ 20.8
CVE-2005-2726

Directory traversal vulnerability in Home Ftp Server 1.0.7 allows remote authenticated users to read arbitrary files via "C:\" (Windows drive letter) sequences in commands such as (1) LIST or (2) RETR.

Aug 30, 2005 1 affected product(s) NVD
5.0
CVSS
1.7%
EPSS
⚡ 20.5
CVE-2005-2020

Directory traversal vulnerability in the web server for 3Com Network Supervisor 5.0.2 allows remote attackers to read arbitrary files via ".." sequences in the URL to TCP port 21700.

Sep 8, 2005 1 affected product(s) NVD
5.0
CVSS
1.8%
EPSS
⚡ 20.5
CVE-2005-2786

Directory traversal vulnerability in bestmail_edit.cgi in cosmoshop 8.10.78 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file parameter.

Sep 2, 2005 1 affected product(s) NVD
5.0
CVSS
1.2%
EPSS
⚡ 20.4
CVE-2005-2854

CRLF injection vulnerability in thesitewizard.com chfeedback.pl Feedback Form Perl Script 2.0.1 allows remote attackers to use the script as a mail relay (spam proxy) via CRLF sequences in the (1) name or (2) email fields, which are injected into mail headers.

Sep 8, 2005 1 affected product(s) NVD
5.0
CVSS
1.1%
EPSS
⚡ 20.3
CVE-2005-2811

Untrusted search path vulnerability in Net-SNMP 5.2.1.2 and earlier, on Gentoo Linux, installs certain Perl modules with an insecure DT_RPATH, which could allow local users to gain privileges.

Sep 7, 2005 16 affected product(s) NVD
4.6
CVSS
0.4%
EPSS
⚡ 18.5
← Previous Page 154 of 9203 Next →