CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2005-4255

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in TextSearch in WikkaWiki 1.1.6.0 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded phrase parameter.

    Published: 15 Dec 2005
    7.5
    High

    CVE-2005-4259

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in ASPBB 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) TID parameter in topic.asp, (2) FORUM_ID parameter in forum.asp, and (3) PROFILE_ID parameter in profile.asp. NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID.

    Published: 15 Dec 2005
    4.3
    Medium

    CVE-2005-4262

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the News module in Envolution allows remote attackers to inject arbitrary web script or HTML via the (1) startrow and (2) catid parameter. NOTE: this issue might be resultant from the SQL injection problem (CVE-2005-4263).

    Published: 15 Dec 2005
    7.5
    High

    CVE-2005-4266

    Last Modified: 16 Apr 2026

    WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the random value.

    Published: 15 Dec 2005
    7.5
    High

    CVE-2005-4263

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the News module in Envolution allows remote attackers to execute arbitrary SQL commands via the (1) startrow and (2) catid parameter.

    Published: 15 Dec 2005
    Unknown

    CVE-2005-4265

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-4209. Reason: This candidate is a duplicate of CVE-2005-4209. Notes: All CVE users should reference CVE-2005-4209 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 Dec 2005
    7.8
    High

    CVE-2005-4257

    Last Modified: 16 Apr 2026

    Linksys WRT54GS and BEFW11S4 allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LAND). NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID.

    Published: 15 Dec 2005
    7.5
    High

    CVE-2005-4254

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in view_Results.php in DreamLevels DreamPoll 3.0 final allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 15 Dec 2005
    4.3
    Medium

    CVE-2005-4256

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in forum.asp in ASP-DEV XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via the forum_title parameter. NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID. In addition, its accuracy is in question because "forum_title" does not appear to be specified in the source code for XM Forum RC3. It is possible, but not certain, that this is CVE-2004-2211.

    Published: 15 Dec 2005
    7.8
    High

    CVE-2005-4258

    Last Modified: 16 Apr 2026

    Unspecified Cisco Catalyst Switches allow remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD). NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID.

    Published: 15 Dec 2005
    7.8
    High

    CVE-2005-4261

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Positive Software Corporation CP+ (cpplus) before 2.5.5 allows attackers to have unknown impact and attack vectors, related to "a possible security flaw caused by a bug in Perl." NOTE: unless CP+ includes its own copy of Perl with CVE-2005-3962, this is a different vulnerability than CVE-2005-3962; however, there is insufficient information to be sure.

    Published: 15 Dec 2005
    7.5
    High

    CVE-2005-4264

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in PHP Support Tickets 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields, and (3) id parameter.

    Published: 15 Dec 2005
    7.5
    High

    CVE-2005-4243

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in QuickPayPro 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) popupid parameter in popups.edit.php; (2) so, (3) sb, and (4) nr parameters in customer.tickets.view.php; (5) subrackingid parameter in subscribers.tracking.edit.php; (6) delete parameter in design.php; (7) trackingid parameter in tracking.details.php; and (8) customerid parameter in sales.view.php.

    Published: 15 Dec 2005
    4.3
    Medium

    CVE-2005-4260

    Last Modified: 16 Apr 2026

    Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and later allows remote attackers to perform cross-site scripting (XSS) attacks by replacing the ">" in the tag with a "<", which bypasses the regular expressions that sanitize the data, but is automatically corrected by many web browsers. NOTE: it could be argued that this vulnerability is due to a design limitation of many web browsers; if so, then this should not be treated as a vulnerability in PHP-Nuke.

    Published: 15 Dec 2005
    7.8
    High

    CVE-2005-1928

    Last Modified: 16 Apr 2026

    Trend Micro ServerProtect EarthAgent for Windows Management Console 5.58 and possibly earlier versions, when running with Trend Micro Control Manager 2.5 and 3.0, and Damage Cleanup Server 1.1, allows remote attackers to cause a denial of service (CPU consumption) via a flood of crafted packets with a certain "magic value" to port 5005, which also leads to a memory leak.

    Published: 14 Dec 2005
    7.5
    High

    CVE-2005-1929

    Last Modified: 16 Apr 2026

    Multiple heap-based buffer overflows in (1) isaNVWRequest.dll and (2) relay.dll in Trend Micro ServerProtect Management Console 5.58 and earlier, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, allow remote attackers to execute arbitrary code via "wrapped" length values in Chunked transfer requests. NOTE: the original report suggests that the relay.dll issue is related to a problem in which a Microsoft Foundation Classes (MFC) static library returns invalid values under heavy load. As such, this might not be a vulnerability in Trend Micro's product.

    Published: 14 Dec 2005
    7.2
    High

    CVE-2005-3360

    Last Modified: 16 Apr 2026

    The installation of Trend Micro PC-Cillin Internet Security 2005 12.00 build 1244, and probably previous versions, uses insecure default ACLs, which allows local users to cause a denial of service (disabled service) and gain system privileges by modifying or moving critical program files.

    Published: 14 Dec 2005
    5
    Medium

    CVE-2005-1930

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the Crystal Report component (rptserver.asp) in Trend Micro ServerProtect Management Console 5.58, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, and possibly earlier versions, allows remote attackers to read arbitrary files via the IMAGE parameter.

    Published: 14 Dec 2005
    4.3
    Medium

    CVE-2005-4242

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Horde Turba H3 2.0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the address book and (2) contact data.

    Published: 14 Dec 2005
    5.1
    Medium

    CVE-2005-2829

    Last Modified: 16 Apr 2026

    Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."

    Published: 14 Dec 2005
    5
    Medium

    CVE-2005-2830

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."

    Published: 14 Dec 2005
    Unknown

    CVE-2005-3703

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2272. Reason: This candidate is a duplicate of CVE-2005-2272. It was reserved when another candidate was already public. Notes: All CVE users should reference CVE-2005-2272 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 14 Dec 2005
    7.5
    High

    CVE-2005-4211

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the $_CCFG[_PKG_PATH_DBSE] variable.

    Published: 14 Dec 2005
    5
    Medium

    CVE-2005-4212

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via ".." (dot dot) sequences in the $_CCFG[_PKG_PATH_DBSE] variable.

    Published: 14 Dec 2005
    7.5
    High

    CVE-2005-4213

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in mod.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary SQL commands via the phpcoinsessid cookie.

    Published: 14 Dec 2005
    5
    Medium

    CVE-2005-4214

    Last Modified: 16 Apr 2026

    phpCOIN 1.2.2 allows remote attackers to obtain the installation path via a direct request to config.php, which leaks the path in an error message because the _CCFG['_PKG_PATH_DBSE'] variable is not defined.

    Published: 14 Dec 2005
    7.8
    High

    CVE-2005-4215

    Last Modified: 16 Apr 2026

    Motorola SB5100E Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LAND).

    Published: 14 Dec 2005
    7.8
    High

    CVE-2005-4220

    Last Modified: 16 Apr 2026

    Netgear RP114, and possibly other versions and devices, allows remote attackers to cause a denial of service via a SYN flood attack between one system on the internal interface and another on the external interface, which temporarily stops routing between the interfaces, as demonstrated using nmap.

    Published: 14 Dec 2005
    7.5
    High

    CVE-2005-4221

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in link.php in Arab Portal System 2 Beta 2 allows remote attackers to execute arbitrary SQL commands via the (1) PHPSESSID (session ID) or (2) REQUEST_URI (query string).

    Published: 14 Dec 2005
    4.3
    Medium

    CVE-2005-4222

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in guestbook.cgi in Lars Ellingsen Guestserver 4.13 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified message fields.

    Published: 14 Dec 2005
    7.5
    High

    CVE-2005-4223

    Last Modified: 16 Apr 2026

    Multiple "potential" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in editnews.php, (2) the catid and question parameters in faq.php, (3) the poster parameter in postnews.php, (4) the tempid parameter in templates.php, and (5) the userid and groupid parameters in users.php.

    Published: 14 Dec 2005
    7.5
    High

    CVE-2005-4228

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since, (2) sort_by, and (3) items_number parameters to comments.php, (4) the search parameter to category.php, and (5) image_id parameter to picture.php. NOTE: it was later reported that the comments.php/sort_by vector also affects 1.7.2 and earlier.

    Published: 14 Dec 2005
    7.5
    High

    CVE-2005-4234

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in gallery.php in EncapsGallery 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 14 Dec 2005
    4.3
    Medium

    CVE-2005-4235

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in knowledgebase.php in WHMCompleteSolution 2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameters.

    Published: 14 Dec 2005
    4.3
    Medium

    CVE-2005-4236

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in CKGOLD allows remote attackers to inject arbitrary web script or HTML via the search parameters.

    Published: 14 Dec 2005
    4.3
    Medium

    CVE-2005-4239

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Search/DisplayResults.php in PHP JackKnife 2.21 and earlier allows remote attackers to inject arbitrary web script or HTML via URL-encoded values in the sKeywords parameter.

    Published: 14 Dec 2005
    7.5
    High

    CVE-2005-4240

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.php in VCD-db 0.98 and earlier allows remote attackers to execute arbitrary SQL commands via the by parameter.

    Published: 14 Dec 2005
    4.3
    Medium

    CVE-2005-4241

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the category page in VCD-db 0.98 and earlier allows remote attackers to inject arbitrary web script or HTML via the batch parameter.

    Published: 14 Dec 2005
    7.5
    High

    CVE-2005-4244

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Snipe Gallery 3.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) gallery_id parameter to view.php and (2) image_id parameter to image.php.

    Published: 14 Dec 2005
    4.3
    Medium

    CVE-2005-4247

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Plogger Beta 2 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter.

    Published: 14 Dec 2005
    5
    Medium

    CVE-2005-4250

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to read arbitrary files via the language parameter.

    Published: 14 Dec 2005
    7.5
    High

    CVE-2005-4251

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and the (4) album parameter to index.php.

    Published: 14 Dec 2005
    4.3
    Medium

    CVE-2005-4252

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters.

    Published: 14 Dec 2005
    7.5
    High

    CVE-2005-4246

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Plogger Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php and (2) page parameter.

    Published: 14 Dec 2005
    7.5
    High

    CVE-2005-4217

    Last Modified: 16 Apr 2026

    Perl in Apple Mac OS X Server 10.3.9 does not properly drop privileges when using the "$<" variable to set uid, which allows attackers to gain privileges.

    Published: 14 Dec 2005
    7.5
    High

    CVE-2005-4225

    Last Modified: 16 Apr 2026

    Multiple "potential" SQL injection vulnerabilities in myBloggie 2.1.3 beta might allow remote attackers to execute arbitrary SQL commands via (1) the category parameter in add.php, (2) the cat_desc parameter in addcat.php, (3) the level and user parameters in adduser.php, (4) the post_id parameter in del.php, (5) the cat_id parameter in delcat.php, (6) the comment_id parameter in delcomment.php, (7) the id parameter in deluser.php, (8) the post_id and category parameter in edit.php, (9) the cat_id and cat_desc parameters in editcat.php, and (10) the id, level, and user parameters in edituser.php. NOTE: the username/login.php vector is already identified by CVE-2005-2838.

    Published: 14 Dec 2005
    7.5
    High

    CVE-2005-4230

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in poll.php in Link Up Gold 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the number parameter.

    Published: 14 Dec 2005
    7.5
    High

    CVE-2005-2831

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.

    Published: 14 Dec 2005
    7.8
    High

    CVE-2005-4216

    Last Modified: 16 Apr 2026

    The Administration Service (FMSAdmin.exe) in Macromedia Flash Media Server 2.0 r1145 allows remote attackers to cause a denial of service (application crash) via a malformed request with a single character to port 1111.

    Published: 14 Dec 2005
    7.5
    High

    CVE-2005-4218

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in forum.php in PHPWebThings 1.4 allows remote attackers to execute arbitrary SQL commands via the msg parameter, a different vulnerability than CVE-2005-3585.

    Published: 14 Dec 2005