CSV
184,096 results for "vulnerability" Page 162
CVE-2005-3405

ATutor 1.4.1 through 1.5.1-pl1 allows remote attackers to execute arbitrary PHP functions via a direct request to forum.inc.php with a modified addslashes parameter with either the (1) asc or (2) desc parameters set, possibly due to an eval injection vulnerability.

Nov 1, 2005 NVD
7.5
CVSS
8.1%
EPSS
⚡ 32.4
CVE-2005-3392

Unspecified vulnerability in PHP before 4.4.1, when using the virtual function on Apache 2, allows remote attackers to bypass safe_mode and open_basedir directives.

Nov 1, 2005 54 affected product(s) NVD
7.5
CVSS
6.9%
EPSS
⚡ 32.1
CVE-2005-3335

PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the t_core_path parameter.

Oct 27, 2005 2 affected product(s) NVD
7.5
CVSS
6.6%
EPSS
⚡ 32
CVE-2005-3388

Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment."

Nov 1, 2005 48 affected product(s) NVD
4.3
CVSS
48.9%
EPSS
⚡ 31.9
CVE-2005-3363

SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows remote attackers to execute arbitrary SQL commands via the forumid parameter in (1) showcat.php and (2) add.php.

Oct 30, 2005 2 affected product(s) NVD
7.5
CVSS
3.5%
EPSS
⚡ 31
CVE-2005-3393

Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.

Nov 1, 2005 4 affected product(s) NVD
7.5
CVSS
3.5%
EPSS
⚡ 31
CVE-2005-3328

PHP remote file inclusion vulnerability in common.php in PunBB 1.1.2 through 1.1.5 allows remote attackers to execute arbitrary code via the pun_root parameter.

Oct 27, 2005 4 affected product(s) NVD
7.5
CVSS
2.6%
EPSS
⚡ 30.8
CVE-2005-3395

SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter.

Nov 1, 2005 1 affected product(s) NVD
7.5
CVSS
2.5%
EPSS
⚡ 30.8
CVE-2005-3326

SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the awayday parameter.

Oct 27, 2005 2 affected product(s) NVD
7.5
CVSS
2.4%
EPSS
⚡ 30.7
CVE-2005-3332

PHP remote file include vulnerability in admin/define.inc.php in Belchior Foundry vCard 2.9 allows remote attackers to execute arbitrary PHP code via the match parameter.

Oct 27, 2005 1 affected product(s) NVD
7.5
CVSS
2.3%
EPSS
⚡ 30.7
CVE-2005-3324

SQL injection vulnerability in chat.php in MWChat 6.8 allows remote attackers to execute arbitrary SQL commands via the username parameter.

Oct 27, 2005 1 affected product(s) NVD
7.5
CVSS
2.0%
EPSS
⚡ 30.6
CVE-2005-3336

SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

Oct 27, 2005 2 affected product(s) NVD
7.5
CVSS
1.9%
EPSS
⚡ 30.6
CVE-2005-3383

SQL injection vulnerability in Techno Dreams Announcement script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.

Oct 30, 2005 NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2005-3384

SQL injection vulnerability in Techno Dreams Guest Book script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.

Oct 30, 2005 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2005-3385

SQL injection vulnerability in Techno Dreams Mailing List script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.

Oct 30, 2005 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2005-3386

SQL injection vulnerability in Techno Dreams Web Directory script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.

Oct 30, 2005 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2005-3333

SQL injection vulnerability in eBASEweb 3.0 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

Oct 27, 2005 1 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2005-3366

PHP file inclusion vulnerability in index.php in PHP iCalendar 2.0a2 through 2.0.1 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the phpicalendar cookie. NOTE: this is not a cross-site scripting (XSS) issue as claimed by the original researcher.

Oct 30, 2005 4 affected product(s) NVD
6.8
CVSS
2.4%
EPSS
⚡ 27.9
CVE-2005-3249

Unspecified vulnerability in the WSP dissector in Ethereal 0.10.1 to 0.10.12 allows remote attackers to cause a denial of service or corrupt memory via unknown vectors that cause Ethereal to free an invalid pointer.

Oct 27, 2005 12 affected product(s) NVD
6.4
CVSS
2.7%
EPSS
⚡ 26.4
CVE-2005-3318

Buffer overflow in the _chm_decompress_block function in CHM lib (chmlib) before 0.37, as used in products such as KchmViewer, allows attackers to execute arbitrary code, a different vulnerability than CVE-2005-2930.

Oct 27, 2005 8 affected product(s) NVD
5.1
CVSS
3.8%
EPSS
⚡ 21.5
← Previous Page 162 of 9205 Next →