CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2005-1033

    Last Modified: 16 Apr 2026

    CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message.

    Published: 9 Apr 2005
    5
    Medium

    CVE-2005-1034

    Last Modified: 16 Apr 2026

    SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command.

    Published: 9 Apr 2005
    5
    Medium

    CVE-2005-1025

    Last Modified: 16 Apr 2026

    The FTP server in AS/400 4.3, when running in IFS mode, allows remote attackers to obtain sensitive information via a symlink attack using RCMD and the ADDLNK utility, as demonstrated using the QSYS.LIB library.

    Published: 9 Apr 2005
    4.3
    Medium

    CVE-2007-5794

    Last Modified: 23 Apr 2026

    Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.

    Published: 9 Apr 2005
    10
    Critical

    CVE-2005-1009

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a modified computer name and length that leads to a heap-based buffer overflow, or (2) local users to execute arbitrary code via a long Name entry in the configure.cfg file.

    Published: 8 Apr 2005
    4.3
    Medium

    CVE-2005-1012

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Iatek SiteEnable allows remote attackers to inject arbitrary web script or HTML via (1) the contenttype parameter to content.asp, (2) the title, or (3) the description.

    Published: 8 Apr 2005
    5
    Medium

    CVE-2005-1013

    Last Modified: 16 Apr 2026

    The SMTP service in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to cause a denial of service (server crash) via an EHLO command with a Unicode string.

    Published: 8 Apr 2005
    7.5
    High

    CVE-2005-1014

    Last Modified: 16 Apr 2026

    Buffer overflow in the IMAP service for MailEnable Enterprise 1.04 and earlier and Professional 1.54 allows remote attackers to execute arbitrary code via a long AUTHENTICATE command.

    Published: 8 Apr 2005
    10
    Critical

    CVE-2005-1015

    Last Modified: 16 Apr 2026

    Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remote attackers to execute arbitrary code via a long LOGIN command.

    Published: 8 Apr 2005
    4.3
    Medium

    CVE-2005-1016

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in links_add_form.asp for MaxWebPortal 1.33 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript URL in a banner URL.

    Published: 8 Apr 2005
    4.3
    Medium

    CVE-2005-1010

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Comersus Cart 6 allows remote attackers to inject arbitrary web script or HTML via the account username.

    Published: 8 Apr 2005
    4.6
    Medium

    CVE-2005-1094

    Last Modified: 16 Apr 2026

    FTP Now 2.6.14 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.

    Published: 8 Apr 2005
    4.3
    Medium

    CVE-2005-1008

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in posts.asp for ASP-DEv XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via a "javascript:" URL in an IMG tag.

    Published: 8 Apr 2005
    7.5
    High

    CVE-2005-1017

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the Update_Events function in events_functions.asp in MaxWebPortal 1.33 and earlier allows remote attackers to execute arbitrary SQL commands via the EVENT_ID parameter, as demonstrated using events.asp.

    Published: 8 Apr 2005
    4.3
    Medium

    CVE-2005-1072

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PunBB before 1.2.5 allows remote attackers to inject arbitrary web script or HTML.

    Published: 8 Apr 2005
    2.1
    Low

    CVE-2005-0465

    Last Modified: 16 Apr 2026

    gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary files via the -s option.

    Published: 8 Apr 2005
    7.5
    High

    CVE-2005-1011

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in content.asp in SiteEnable allows remote attackers to execute arbitrary SQL commands via the sortby parameter.

    Published: 8 Apr 2005
    7.5
    High

    CVE-2005-1067

    Last Modified: 16 Apr 2026

    Vulnerability in Access_user Class before 1.75 allows local users to gain access as other users via the password "new".

    Published: 8 Apr 2005
    2.1
    Low

    CVE-2005-0464

    Last Modified: 16 Apr 2026

    gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files while in debug mode, which allows local users to read a line from arbitrary files via the -d and -D options, which prints the line as a formatting error.

    Published: 8 Apr 2005
    4.3
    Medium

    CVE-2005-0992

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin before 2.6.2-rc1 allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter.

    Published: 7 Apr 2005
    4.6
    Medium

    CVE-2005-0993

    Last Modified: 16 Apr 2026

    Buffer overflow in nwprint in SCO OpenServer 5.0.7 allows local users to execute arbitrary code via a long command line argument.

    Published: 7 Apr 2005
    5
    Medium

    CVE-2005-0996

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the email or url parameters in the Add function, (2) the min parameter in the viewsdownload function, or (3) the min parameter in the search function.

    Published: 7 Apr 2005
    7.5
    High

    CVE-2005-1003

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php for ProfitCode PayProCart 3.0 allows remote attackers to include arbitrary PHP files via .. (dot dot) sequences in the modID parameter.

    Published: 7 Apr 2005
    4.3
    Medium

    CVE-2005-1006

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in SonicWALL SOHO 5.1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) the user login name, which is not filtered when the administrator views the log file.

    Published: 7 Apr 2005
    7.5
    High

    CVE-2005-1047

    Last Modified: 16 Apr 2026

    Meilad File upload script (up.php) mod for phpBB 2.0.x does not properly limit the types of files that can be uploaded, which allows remote authenticated users to execute arbitrary commands by uploading PHP files, then directly requesting them from the uploads directory.

    Published: 7 Apr 2005
    6.4
    Medium

    CVE-2005-1087

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and possibly read files using an injected type command, via CRLF sequences in an HTTP request.

    Published: 7 Apr 2005
    7.5
    High

    CVE-2005-0994

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in ProductCart 2.7 allow remote attackers to execute arbitrary SQL commands via (1) the Category or resultCnt parameters to advSearch_h.asp, and possibly (2) the offset parameter to tarinasworld_butterflyjournal.asp. NOTE: it is possible that item (2) is the result of a typo or editing error from the original research report.

    Published: 7 Apr 2005
    5
    Medium

    CVE-2005-0998

    Last Modified: 16 Apr 2026

    The Web_Links module for PHP-Nuke 7.6 allows remote attackers to obtain sensitive information via an invalid show parameter, which triggers a division by zero PHP error that leaks the full pathname of the server.

    Published: 7 Apr 2005
    7.5
    High

    CVE-2005-0999

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the Top module for PHP-Nuke 6.x through 7.6 allows remote attackers to execute arbitrary SQL commands via the querylang parameter.

    Published: 7 Apr 2005
    5
    Medium

    CVE-2005-1001

    Last Modified: 16 Apr 2026

    PHP-Nuke 7.6 allows remote attackers to obtain sensitive information via direct requests to (1) the Surveys module with the file parameter set to comments or (2) 3D-Fantasy/theme.php, which leaks the full pathname of the web server in a PHP error message.

    Published: 7 Apr 2005
    5
    Medium

    CVE-2005-1002

    Last Modified: 16 Apr 2026

    logwebftbs2000.exe in Logics Software File Transfer (LOG-FT) allows remote attackers to read arbitrary files via modified (1) VAR_FT_LANG and (2) VAR_FT_TMPL parameters.

    Published: 7 Apr 2005
    4.3
    Medium

    CVE-2005-1004

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in usrdetails.php in ProfitCode PayProCart 3.0 allows remote attackers to inject arbitrary web script or HTML via the sgnuptype parameter.

    Published: 7 Apr 2005
    7.5
    High

    CVE-2005-1005

    Last Modified: 16 Apr 2026

    ProfitCode PayProCart 3.0 allows remote attackers to bypass authentication and gain administrative privileges to the admin control panel, as demonstrated via a direct request to adminshop/index.php with hex-encoded .. sequences in the ftoedit parameter.

    Published: 7 Apr 2005
    4.3
    Medium

    CVE-2005-0995

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ProductCart 2.7 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter to advSearch_h.asp, (2) the redirectUrl parameter to NewCust.asp, (3) the country parameter to storelocator_submit.asp, or (4) the error parameter to techErr.asp. NOTE: it has been reported that storelocator_submit.asp does not exist in ProductCart.

    Published: 7 Apr 2005
    4.3
    Medium

    CVE-2005-1000

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the bid parameter to the EmailStats op in banners.pgp, (2) the ratenum parameter in the TopRated and MostPopular actions in the Web_Links module, (3) the ttitle parameter in the viewlinkdetails, viewlinkeditorial, viewlinkcomments, and ratelink actions in the Web_Links module, or (4) the username parameter in the Your_Account module.

    Published: 7 Apr 2005
    5
    Medium

    CVE-2005-1007

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the LIST functionality in CommuniGate Pro before 4.3c3 allows remote attackers to cause a denial of service (server crash) via certain multipart messages.

    Published: 7 Apr 2005
    4.6
    Medium

    CVE-2005-0351

    Last Modified: 16 Apr 2026

    Buffer overflow in (1) termsh, (2) atcronsh, and (3) auditsh in SCO OpenServer 5.0.6 and 5.0.7 might allow local users to execute arbitrary code via a long HOME environment variable.

    Published: 7 Apr 2005
    7.5
    High

    CVE-2005-0997

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 7.6 allow remote attackers to execute arbitrary SQL commands via (1) the email or url parameters in the Add function, (2) the url parameter in the modifylinkrequestS function, (3) the orderby or min parameters in the viewlink function, (4) the orderby, min, or show parameters in the search function, or (5) the ratenum parameter in the MostPopular function.

    Published: 7 Apr 2005
    5
    Medium

    CVE-2005-0987

    Last Modified: 16 Apr 2026

    Unknown vulnerability in IRC Services NickServ LISTLINKS before 5.0.50 allows remote attackers to obtain the links of a nick.

    Published: 6 Apr 2005
    2.1
    Low

    CVE-2005-0991

    Last Modified: 16 Apr 2026

    RC.BOOT in IBM AIX 5.1, 5.2, and 5.3 does not "use a secure location for temporary files," which allows local users to have an unknown impact, probably by overwriting files.

    Published: 6 Apr 2005
    7.5
    High

    CVE-2005-1029

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to default.asp, (4) itemID parameter to ItemInfo.asp, or (5) Email field to sendpassword.asp.

    Published: 6 Apr 2005
    7.5
    High

    CVE-2005-1096

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to execute arbitrary SQL commands via the UserID parameter.

    Published: 6 Apr 2005
    5
    Medium

    CVE-2005-0986

    Last Modified: 16 Apr 2026

    NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of service (deep recursion and nHTTP.exe process crash) via a long GET request containing UNICODE decimal value 430 characters, which causes the stack to be exhausted. NOTE: IBM has reported that it is unable to replicate this issue.

    Published: 6 Apr 2005
    5
    Medium

    CVE-2005-0989

    Last Modified: 16 Apr 2026

    The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.

    Published: 6 Apr 2005
    Unknown

    CVE-2005-1032

    Last Modified: 7 Nov 2023

    cart.php in LiteCommerce might allow remote attackers to obtain sensitive information via invalid (1) category_id or (2) product_id parameters. NOTE: this issue was originally claimed to be due to SQL injection, but the original researcher is known to be frequently inaccurate with respect to bug type and severity. The vendor has disputed this issue, saying "These reports are credited to malicious person we refused to hire. We have not taken legal action against him only because he is located in India. The vulnerabilites reported can not be reproduced, hence information you provide is contrary to fact." Further investigation by CVE personnel shows that an invalid SQL syntax error could be generated, but it only reveals portions of underlying database structure, which is already available in documentation from the vendor, and it does not appear to lead to path disclosure. Therefore, this issue is not a vulnerability or an exposure, and it probably should be REJECTED

    Published: 6 Apr 2005
    2.1
    Low

    CVE-2005-1038

    Last Modified: 16 Apr 2026

    crontab in Vixie cron 4.1, when running with the -e option, allows local users to read the cron files of other users by changing the file being edited to a symlink. NOTE: there is insufficient information to know whether this is a duplicate of CVE-2001-0235.

    Published: 6 Apr 2005
    7.5
    High

    CVE-2005-0979

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in RUMBA 7.3 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted values in a profile file, as demonstrated using a long SysName field.

    Published: 5 Apr 2005
    7.5
    High

    CVE-2005-0980

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary PHP code by modifying the view parameter to reference a URL on a remote web server that contains the code.

    Published: 5 Apr 2005
    4.3
    Medium

    CVE-2005-0981

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft EPay Pro 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) payment or (2) send parameter.

    Published: 5 Apr 2005
    7.5
    High

    CVE-2005-1035

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Pavuk before 0.9.32 have unknown attack vectors and impact.

    Published: 5 Apr 2005