CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2005-2191

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Comersus shopping cart allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to comersus_backoffice_listAssignedPricesToCustomer.asp or (2) message parameter to comersus_backoffice_message.asp.

    Published: 10 Jul 2005
    7.5
    High

    CVE-2005-2178

    Last Modified: 16 Apr 2026

    probe.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the olddat parameter. NOTE: it is unclear which product or vendor this program is associated with, if any.

    Published: 10 Jul 2005
    1.9
    Low

    CVE-2005-2186

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in McAfee IntruShield Security Management System allow remote authenticated users to inject arbitrary web script or HTML via the (1) thirdMenuName or (2) resourceName parameter to SystemEvent.jsp.

    Published: 10 Jul 2005
    5
    Medium

    CVE-2005-2192

    Last Modified: 16 Apr 2026

    SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.

    Published: 10 Jul 2005
    5
    Medium

    CVE-2005-2179

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter.

    Published: 10 Jul 2005
    4.6
    Medium

    CVE-2005-2187

    Last Modified: 16 Apr 2026

    McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true, as demonstrated using the (1) fullAccess or (2) fullAccessRight parameter in reports-column-center.jsp, or (3) fullAccess parameter to SystemEvent.jsp.

    Published: 10 Jul 2005
    7.5
    High

    CVE-2005-2188

    Last Modified: 16 Apr 2026

    McAfee IntruShield Security Management System obtains the user ID from the URL, which allows remote attackers to guess the Manager account and possibly gain privileges via a brute force attack.

    Published: 10 Jul 2005
    7.5
    High

    CVE-2005-2193

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote attackers to execute arbitrary SQL statements via the temp array, which is not initialized before it is used and prevents the attacker-supplied portions of the array from being properly escaped.

    Published: 10 Jul 2005
    2.1
    Low

    CVE-2005-2180

    Last Modified: 16 Apr 2026

    gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local users to overwrite arbitrary files.

    Published: 10 Jul 2005
    7.5
    High

    CVE-2005-2185

    Last Modified: 16 Apr 2026

    eRoom does not set an expiration for Cookies, which allows remote attackers to capture cookies and conduct replay attacks.

    Published: 10 Jul 2005
    5
    Medium

    CVE-2005-2175

    Last Modified: 16 Apr 2026

    The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.

    Published: 9 Jul 2005
    6.4
    Medium

    CVE-2005-2176

    Last Modified: 16 Apr 2026

    Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.

    Published: 9 Jul 2005
    5
    Medium

    CVE-2005-2173

    Last Modified: 16 Apr 2026

    The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.

    Published: 8 Jul 2005
    2.6
    Low

    CVE-2005-2174

    Last Modified: 16 Apr 2026

    Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete.

    Published: 8 Jul 2005
    Unknown

    CVE-2005-1912

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-1841. Reason: This candidate is a duplicate of CVE-2005-1841. Notes: this duplicate occurred as a result of separate assignments by multiple CNAs, one to the researcher and one to the vendor. All CVE users should reference CVE-2005-1841 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 Jul 2005
    2.1
    Low

    CVE-2005-1841

    Last Modified: 16 Apr 2026

    The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary files with the permissions as specified in a user's umask, which could allow local users to read PDF documents of that user if the umask allows it.

    Published: 7 Jul 2005
    1.2
    Low

    CVE-2005-2666

    Last Modified: 16 Apr 2026

    SSH, as implemented in OpenSSH before 4.0 and possibly other implementations, stores hostnames, IP addresses, and keys in plaintext in the known_hosts file, which makes it easier for an attacker that has compromised an SSH user's account to generate a list of additional targets that are more likely to have the same password or key.

    Published: 7 Jul 2005
    7.5
    High

    CVE-2005-2152

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Geeklog before 1.3.11 allows remote attackers to execute arbitrary SQL commands via user comments for an article.

    Published: 6 Jul 2005
    7.5
    High

    CVE-2005-2154

    Last Modified: 16 Apr 2026

    PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and possibly execute arbitrary local files via the inc parameter.

    Published: 6 Jul 2005
    7.5
    High

    CVE-2005-2155

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.

    Published: 6 Jul 2005
    7.5
    High

    CVE-2005-2156

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter.

    Published: 6 Jul 2005
    5
    Medium

    CVE-2005-2157

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter.

    Published: 6 Jul 2005
    7.5
    High

    CVE-2005-2153

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable.

    Published: 6 Jul 2005
    4.3
    Medium

    CVE-2005-2161

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote attackers to inject arbitrary web script or HTML via nested [url] tags.

    Published: 6 Jul 2005
    5
    Medium

    CVE-2005-2162

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter.

    Published: 6 Jul 2005
    4.3
    Medium

    CVE-2005-2163

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 6 Jul 2005
    7.5
    High

    CVE-2005-2164

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Covide Groupware-CRM allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

    Published: 6 Jul 2005
    7.5
    High

    CVE-2005-2165

    Last Modified: 16 Apr 2026

    read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters.

    Published: 6 Jul 2005
    5
    Medium

    CVE-2005-2166

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 6 Jul 2005
    5.5
    Medium

    CVE-2005-1916

    Last Modified: 16 Apr 2026

    linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.

    Published: 6 Jul 2005
    5
    Medium

    CVE-2005-2159

    Last Modified: 16 Apr 2026

    mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request.

    Published: 6 Jul 2005
    5
    Medium

    CVE-2005-2168

    Last Modified: 16 Apr 2026

    delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter.

    Published: 6 Jul 2005
    6.4
    Medium

    CVE-2005-2147

    Last Modified: 16 Apr 2026

    Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts.

    Published: 6 Jul 2005
    7.5
    High

    CVE-2005-2148

    Last Modified: 16 Apr 2026

    Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which causes the get_request_var function to return the wrong value in the $_REQUEST variable, which is cleansed while the original malicious $_GET value remains unmodified, as demonstrated in (1) graph_image.php and (2) graph.php.

    Published: 6 Jul 2005
    5
    Medium

    CVE-2005-2151

    Last Modified: 16 Apr 2026

    spf.c in Courier Mail Server does not properly handle DNS failures when looking up Sender Policy Framework (SPF) records, which could allow attackers to cause memory corruption.

    Published: 6 Jul 2005
    7.5
    High

    CVE-2005-2158

    Last Modified: 16 Apr 2026

    A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vulnerability that was originally identified by CVE-2003-0845.

    Published: 6 Jul 2005
    7.5
    High

    CVE-2005-2160

    Last Modified: 16 Apr 2026

    IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.

    Published: 6 Jul 2005
    5
    Medium

    CVE-2005-2169

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in source.php in Quick & Dirty PHPSource Printer 1.1 and earlier allows remote attackers to read arbitrary files via ".../...//" sequences in the file parameter, which are reduced to "../" when PHPSource Printer uses a regular expression to remove "../" sequences.

    Published: 6 Jul 2005
    10
    Critical

    CVE-2005-2149

    Last Modified: 16 Apr 2026

    config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.

    Published: 6 Jul 2005
    4.3
    Medium

    CVE-2005-2167

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter.

    Published: 6 Jul 2005
    7.5
    High

    CVE-2005-2096

    Last Modified: 16 Apr 2026

    zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.

    Published: 6 Jul 2005
    2.1
    Low

    CVE-2005-1917

    Last Modified: 16 Apr 2026

    kpopper 1.0 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the .popper-new temporary file.

    Published: 5 Jul 2005
    5
    Medium

    CVE-2005-2137

    Last Modified: 16 Apr 2026

    Unknown vulnerability in NateOn Messenger 3.0 allows remote attackers to list arbitrary directories via unknown attack vectors.

    Published: 5 Jul 2005
    4.3
    Medium

    CVE-2005-2138

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the onMouseOver event of an "A" tag in a review message.

    Published: 5 Jul 2005
    5
    Medium

    CVE-2005-2139

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in user_check.php for Pavsta Auto Site allows remote attackers to execute arbitrary PHP code via the sitepath parameter.

    Published: 5 Jul 2005
    5
    Medium

    CVE-2005-2140

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in default.asp for FSboard 2.0 allows remote attackers to read arbitrary files via ".." sequences in the filename parameter.

    Published: 5 Jul 2005
    5
    Medium

    CVE-2005-2143

    Last Modified: 16 Apr 2026

    Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page.

    Published: 5 Jul 2005
    4.6
    Medium

    CVE-2005-2146

    Last Modified: 16 Apr 2026

    SSH Tectia Server 4.3.1 and earlier, and SSH Secure Shell for Windows Servers, uses insecure permissions when generating the Secure Shell host identification key, which allows local users to access the key and spoof the server.

    Published: 5 Jul 2005
    2.1
    Low

    CVE-2005-2144

    Last Modified: 16 Apr 2026

    Prevx Pro 2005 1.0 allows local users to bypass file protection and modify files by using MapViewOfFile to perform memory mapping on the file.

    Published: 5 Jul 2005
    Unknown

    CVE-2005-2133

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-1915. Reason: This candidate is a duplicate of CVE-2005-1915. Notes: All CVE users should reference CVE-2005-1915 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Jul 2005