CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2005-4420

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Honeycomb Archive Enterprise 3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keyword parameter in search.cfm.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4415

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in TML CMS 0.5 allows remote attackers to inject arbitrary web script or HTML via the form parameter.

    Published: 20 Dec 2005
    6.5
    Medium

    CVE-2005-4424

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the path parameter and a %00 at the end of the filename, as demonstrated by an avatar filename ending with .png%00.

    Published: 20 Dec 2005
    7.8
    High

    CVE-2005-4425

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Kerio WinRoute Firewall before 6.1.3 allows remote attackers to cause a denial of service (crash) via certain RTSP streams.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4396

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/Default.asp in iCMS allows remote attackers to inject arbitrary web script or HTML via the LoginMSG parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4399

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search/index.php in Libertas Enterprise CMS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page_search parameter.

    Published: 20 Dec 2005
    6.5
    Medium

    CVE-2005-4402

    Last Modified: 16 Apr 2026

    Buffer overflow in MailEnable Professional 1.71 and earlier, and Enterprise 1.1 and earlier, allows remote authenticated users to execute arbitrary code via a long IMAP EXAMINE command.

    Published: 20 Dec 2005
    7.5
    High

    CVE-2005-4404

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in default.asp in Media2 CMS Shop 18.x allows remote attackers to execute arbitrary SQL commands via the item parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources.

    Published: 20 Dec 2005
    10
    Critical

    CVE-2005-4414

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Teamwork 3 before alpha 1.7 has unknown impact and attack vectors, related to "a menu security bug."

    Published: 20 Dec 2005
    6.4
    Medium

    CVE-2005-4417

    Last Modified: 16 Apr 2026

    The default configuration of Widcomm Bluetooth for Windows (BTW) 4.0.1.1500 and earlier, as installed on Belkin Bluetooth Software 1.4.2 Build 10 and ANYCOM Blue USB-130-250 Software 4.0.1.1500, and possibly other devices, sets null Authentication and Authorization values, which allows remote attackers to send arbitrary audio and possibly eavesdrop using the microphone via the Hands Free Audio Gateway and Headset profile.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4391

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in damoon allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the q parameter.

    Published: 20 Dec 2005
    7.5
    High

    CVE-2005-4392

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in printer_friendly.cfm in e-publish CMS 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4398

    Last Modified: 16 Apr 2026

    NOTE: the vendor has disputed this issue. Cross-site scripting (XSS) vulnerability in lemoon 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the q parameter. NOTE: the vendor has disputed this issue, saying "Sites are built on top of ASP.NET and you use lemoon core objects to easily manage and render content. The XSS vuln. you are referring to exists in one of our public sites built on lemoon i.e. a custom made site (as all sites are). The problem exists in a UserControl that handles form input and is in no way related to the lemoon core product.

    Published: 20 Dec 2005
    5
    Medium

    CVE-2005-4405

    Last Modified: 16 Apr 2026

    redqueen.cgi in Red Queen 1.02 and earlier allows remote attackers to obtain the full server path via invalid (1) yellowpage_id, (2) skin_id, (3) supplier_id, and (4) module parameters, which leaks the path in an error message.

    Published: 20 Dec 2005
    7.5
    High

    CVE-2005-4406

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 20 Dec 2005
    2.1
    Low

    CVE-2005-4412

    Last Modified: 16 Apr 2026

    Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the session to obtain the password by using a tool to directly access the field.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4413

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in sample scripts in IBM WebSphere Application Server 6 allow remote attackers to inject arbitrary web script or HTML via the (1) E-mail address field to (a) PlantsByWebSphere/login.jsp, (2) message field to (b) TechnologySample/BulletinBoard Script, (3) Email address field to (c) TechnologySamples/Subscription, and the (4) Movie Name, (5) Movie Reviewer, and (6) Movie Review fields to (d) TechnologySamples/MovieReview2_1.

    Published: 20 Dec 2005
    6.5
    Medium

    CVE-2005-4422

    Last Modified: 16 Apr 2026

    Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in data/images/albums.

    Published: 20 Dec 2005
    6.5
    Medium

    CVE-2005-4423

    Last Modified: 16 Apr 2026

    Unrestricted file upload vulnerability in PHPFM before 0.2.3 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension to an accessible directory, as demonstrated using a file with a .php extension, aka "upload phpshell."

    Published: 20 Dec 2005
    7.5
    High

    CVE-2005-4390

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in ContentServ 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the StoryID parameter.

    Published: 20 Dec 2005
    7.5
    High

    CVE-2005-4421

    Last Modified: 16 Apr 2026

    Dev-Editor 3.0 allows remote attackers to access any directory outside the web root whose name is a substring of the web root directory name.

    Published: 20 Dec 2005
    4
    Medium

    CVE-2005-4426

    Last Modified: 16 Apr 2026

    Interpretation conflict in YaBB before 2.1 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer as a result of CVE-2005-3312. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in YaBB.

    Published: 20 Dec 2005
    7.5
    High

    CVE-2005-4370

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in main_content.asp in Acidcat 2.1.13 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter to default.asp.

    Published: 20 Dec 2005
    5
    Medium

    CVE-2005-4371

    Last Modified: 16 Apr 2026

    Acidcat 2.1.13 and earlier stores the database under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a request to databases/acidcat.mdb.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4372

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in account.html in Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 20 Dec 2005
    5
    Medium

    CVE-2005-4376

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Amaxus 3 and earlier allows remote attackers to access arbitrary files via ".." sequences in the change parameter.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4377

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Page.asp in Baseline CMS 1.95 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) PageID and (2) SiteNodeID parameters.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4381

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Caravel CMS 3.0 Beta 1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) fileDN and (2) folderviewer_attrs parameters.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4385

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.htm in Cofax 2.0 RC3 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4388

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.cfm in CONTENS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the near parameter.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4387

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in home.php in contenite 0.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4369

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Acuity CMS 2.6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly strSearchKeywords to browse.asp.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4374

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Allinta 2.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to faq.asp and (2) searchQuery parameter to search.asp.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4379

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to inject arbitrary web script or HTML via the (1) sort_mode parameter to (a) fisheye/list_galleries.php, (b) messages/message_box.php, and (c) users/my.php; the (2) post_id parameter to (d) blogs/view_post.php; the (3) blog_id parameter to (e) blogs/view.php; and the (4) search field to (f) users/my_groups.php.

    Published: 20 Dec 2005
    5
    Medium

    CVE-2005-4368

    Last Modified: 16 Apr 2026

    roundcube webmail Alpha, with a default high verbose level ($rcmail_config['debug_level'] = 1), allows remote attackers to obtain the full path of the application via an invalid_task parameter, which leaks the path in an error message.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4375

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Amaxus 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the change parameter. NOTE: it is possible that this is resultant from CVE-2005-4376.

    Published: 20 Dec 2005
    7.5
    High

    CVE-2005-4380

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to (a) fisheye/list_galleries.php, (b) messages/message_box.php, and (c) users/my.php; the (2) post_id parameter to (d) blogs/view_post.php; and the (3) blog_id parameter to (e) blogs/view.php, which are not properly cleansed by the convert_sortmode function in kernel/BitDb.php.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4383

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.cfm in CitySoft Community Enterprise 4.x allows remote attackers to inject arbitrary web script or HTML via the (1) presentationSite, (2) docPublishYear, (3) docDescription, (4) publishState, (5) docAuthor, (6) docTitle, (7) subTopic, (8) topic, (9) topicRadio, (10) topicOnly, (11) startrow, and (12) sortby parameters.

    Published: 20 Dec 2005
    6.4
    Medium

    CVE-2005-4384

    Last Modified: 16 Apr 2026

    CitySoft Community Enterprise 4.x allows remote attackers to obtain the full path of the server via an invalid (1) fuseaction parameter to index.cfm and (2) documentid parameter to document/docWindow.cfm.

    Published: 20 Dec 2005
    5
    Medium

    CVE-2005-4389

    Last Modified: 16 Apr 2026

    search.cfm in CONTENS 3.0 and earlier allows remote attackers to obtain the full server path via invalid (1) submit.y, (2) bool, (3) itemsperpage, (4) submit, (5) submit.x, (6) criteria, (7) advanced, and (8) intern parameters.

    Published: 20 Dec 2005
    5
    Medium

    CVE-2005-4373

    Last Modified: 16 Apr 2026

    Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to obtain the full path of the application via an invalid mode parameter to community.html, which leaks the path in an error message.

    Published: 20 Dec 2005
    7.5
    High

    CVE-2005-4378

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Page.asp in Baseline CMS 1.95 and earlier allows remote attackers to execute arbitrary SQL commands via the SiteNodeID parameter.

    Published: 20 Dec 2005
    7.5
    High

    CVE-2005-4382

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in CitySoft Community Enterprise 4.x allows remote attackers to execute arbitrary SQL commands via the (1) nodeID, (2) pageID, (3) ID, and (4) parentid parameter to index.cfm; and (5) documentFormatId parameter to document/docWindow.cfm.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4386

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Colony CMS 2.75 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.

    Published: 20 Dec 2005
    4.3
    Medium

    CVE-2005-4354

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Published: 20 Dec 2005
    7.5
    High

    CVE-2005-4356

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in UStore allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Dec 2005
    2.6
    Low

    CVE-2005-4357

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpBB 2.0.18, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary Javascript via a permitted HTML tag with " (quote) characters and active attributes such as onmouseover.

    Published: 20 Dec 2005
    5
    Medium

    CVE-2005-4358

    Last Modified: 16 Apr 2026

    admin/admin_disallow.php in phpBB 2.0.18 allows remote attackers to obtain the installation path via a direct request with a non-empty setmodules parameter, which causes an invalid append_sid function call that leaks the path in an error message.

    Published: 20 Dec 2005
    5
    Medium

    CVE-2005-4362

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in page.php in Komodo CMS 2.1 allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 20 Dec 2005
    5.8
    Medium

    CVE-2005-4363

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the search engine in Komodo CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.

    Published: 20 Dec 2005