4.3
    Medium

    CVE-2005-4502

    Last Modified: 21 Jul 2013

    Cross-site scripting (XSS) vulnerability in httprint v202, and possibly other versions before v301, allows remote attackers to inject arbitrary web script or HTML via the Server field in an HTTP response, which is not sanitized before being displayed to the user.

    Source:Mariano Nunez Di Croce
    Published:22 Dec 2005
    7.5
    High

    CVE-2005-4500

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in MusicBox 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) show and (2) type parameter. NOTE: the provenance of this information is unknown, although it was later rediscovered.

    Source:Linux_Drox
    Published:22 Dec 2005
    4.3
    Medium

    CVE-2005-4497

    Last Modified: 21 Jul 2013

    Cross-site scripting (XSS) vulnerability in Tangora Portal CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter in a search page, as demonstrated using (1) page1631.aspx and (2) page496.aspx.

    Source:r0t3d3Vil
    Published:22 Dec 2005
    4.3
    Medium

    CVE-2005-4496

    Last Modified: 21 Jul 2013

    Cross-site scripting (XSS) vulnerability in search in SyntaxCMS 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.

    Source:r0t3d3Vil
    Published:22 Dec 2005
    4.3
    Medium

    CVE-2005-4491

    Last Modified: 18 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Sitekit CMS 6.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) query string, (2) textonly, (3) locID, and (4) lang parameters to (a) Default.aspx, and the (6) ClickFrom parameter to (b) Request-call-back.html and (c) registration-form.html. NOTE: the vendor states "This issue was resolved by a minor update to Sitekit CMS v6.6, sanitising the html code and eradicating related security issues."

    Source:r0t3d3Vil
    Published:22 Dec 2005
    4.3
    Medium

    CVE-2005-4490

    Last Modified: 18 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in SCOOP! 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword and (2) invalid parameter to articleSearch.asp; (3) username and (4) invalid parameter to lostPassword.asp; (5) Username, (6) Password, and (7) invalid parameter to account_login.asp; (8) area, (9) articleZoneID, (10) r, and (11) invalid parameters to category.asp; and invalid parameters to (12) articleZone.asp, (13) prePurchaserRegistration.asp, and (14) requestDemo.asp.

    Source:r0t3d3Vil
    Published:22 Dec 2005
    4.3
    Medium

    CVE-2005-4489

    Last Modified: 18 Jul 2013

    Cross-site scripting (XSS) vulnerability in Scoop 1.1 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) type and (2) count parameters, and (3) the query string in a story.

    Source:r0t3d3Vil
    Published:22 Dec 2005
    4.3
    Medium

    CVE-2005-4488

    Last Modified: 18 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in index.tpl in Redakto WCMS 3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) iid, (2) iid2, (3) r, (4) cart, (5) str, (6) nf, and (7) a parameters.

    Source:r0t3d3Vil
    Published:22 Dec 2005
    7.5
    High

    CVE-2005-4486

    Last Modified: 19 Jul 2013

    SQL injection vulnerability in Quantum Art QP7.Enterprise (formerly Q-Publishing) allows remote attackers to execute arbitrary SQL commands via the p_news_id parameter to (1) news_and_events_new.asp and (2) news.asp. NOTE: on 20060227, the vendor disputed the accuracy of this report, saying that the p_news_id, news_and_events_new.asp, and news.asp are not specifically part of their product, although they could be dynamically generated through use of the product. Some investigation by CVE suggests evidence that the news_and_events_new.asp page has at least a forced invalid SQL syntax error, but this could not be repeated for news.asp

    Source:r0t3d3Vil
    Published:22 Dec 2005
    4.3
    Medium

    CVE-2005-4485

    Last Modified: 18 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) forums.asp, (2) search_employees.asp, (3) cat.asp, and (4) links.asp; (5) projectid parameter to pmprojects.asp, (6) ret_page parameter to login.asp, and (7) skin_number parameter to default.asp.

    Source:r0t
    Published:22 Dec 2005
    4.3
    Medium

    CVE-2005-4484

    Last Modified: 18 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in IntranetApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ret_page parameter to login.asp or the (2) do_search and (3) search parameters to content.asp.

    Source:r0t
    Published:22 Dec 2005
    4.3
    Medium

    CVE-2005-4483

    Last Modified: 18 Jul 2013

    Cross-site scripting (XSS) vulnerability in login.asp in SiteEnable 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter.

    Source:r0t
    Published:22 Dec 2005
    6.8
    Medium

    CVE-2005-4482

    Last Modified: 18 Jul 2013

    Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter.

    Source:r0t
    Published:22 Dec 2005
    7.5
    High

    CVE-2005-4479

    Last Modified: 24 Jan 2017

    SQL injection vulnerability in article.php in phpSlash 0.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the story_id parameter.

    Source:r0t3d3Vil
    Published:22 Dec 2005
    7.5
    High

    CVE-2005-4478

    Last Modified: 19 Jul 2013

    Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menuid parameter to (a) index.php and (b) guestbook.php, and the (2) forumid and (3) reporeid_print parameters to (c) print.php.

    Source:r0t3d3Vil
    Published:22 Dec 2005
    6.8
    Medium

    CVE-2005-4477

    Last Modified: 18 Jul 2013

    Cross-site scripting (XSS) vulnerability in papaya CMS 4.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the bab[searchfor] parameter.

    Source:r0t3d3Vil
    Published:22 Dec 2005
    6.8
    Medium

    CVE-2005-4476

    Last Modified: 18 Jul 2013

    Cross-site scripting (XSS) vulnerability in store/search/results.html in OpenEdit 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) oe-action and (2) page parameters.

    Source:r0t3d3Vil
    Published:22 Dec 2005
    7.5
    High

    CVE-2005-4468

    Last Modified: 13 Jun 2016

    PHP remote file include vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to execute arbitrary code via a URL in the PGV_BASE_DIRECTORY parameter.

    Source:rgod
    Published:22 Dec 2005
    5
    Medium

    CVE-2005-4467

    Last Modified: 13 Jun 2016

    Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the PGV_BASE_DIRECTORY parameter.

    Source:rgod
    Published:22 Dec 2005
    7.5
    High

    CVE-2005-4466

    Last Modified: 18 Jul 2013

    Heap-based buffer overflow in the SIPParser function in i3sipmsg.dll in Interaction SIP Proxy before 3.0.011 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a REGISTER request with a SPI version number that contains a large number of space or tab characters.

    Source:Behrang Fouladi
    Published:22 Dec 2005
    7.5
    High

    CVE-2005-4462

    Last Modified: 18 Jul 2013

    PHP remote file include vulnerability in usermods.php in Tolva PHP website system 0.1.0 allows remote attackers to execute arbitrary code via a URL in the ROOT parameter.

    Source:xbefordx
    Published:21 Dec 2005
    7.5
    High

    CVE-2005-4461

    Last Modified: 28 Jul 2013

    SQL injection vulnerability in index.php in Beehive Forum 0.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_sess parameter.

    Source:trueend5
    Published:21 Dec 2005
    5.1
    Medium

    CVE-2005-4460

    Last Modified: 18 Jul 2013

    Cross-site scripting (XSS) vulnerability in Beehive Forum 0.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Description, and (3) Comment fields to (a) links.php and (b) links_add.php.

    Source:Alireza Hassani
    Published:21 Dec 2005
    7.8
    High

    CVE-2005-4456

    Last Modified: 25 May 2017

    Multiple buffer overflows in MailEnable Professional 1.71 and Enterprise 1.1 before patch ME-10009 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) LIST, (2) LSUB, and (3) UID FETCH commands. NOTE: it is possible that these are alternate vectors for the issue described in CVE-2005-4402.

    Source:muts
    Published:21 Dec 2005
    4.3
    Medium

    CVE-2005-4454

    Last Modified: 18 Jul 2013

    Validate-before-filter vulnerability in cleanhtml.pl 1.129 in LiveJournal CVS before Dec 7 2005, when the cleancss option is enabled, allows remote attackers to conduct cross-site scripting (XSS) attacks via a "\" (backslash) within a "javascript" scheme in a style property (such as "javas\cript"), which bypasses the "javascript" check before the "\" is stripped and then rendered in web browsers that allow scripting in style sheets.

    Source:Andrew Farmer
    Published:21 Dec 2005
    4
    Medium

    CVE-2005-4449

    Last Modified: 18 Jan 2018

    verify.php in FlatNuke 2.5.6 allows remote authenticated administrators to modify arbitrary PHP files by setting the file parameter to an arbitrary file and injecting the code into the body parameter. NOTE: if a FlatNuke administrator is normally assumed to be able to modify arbitrary content, then this issue does not cross privilege boundaries and would not be a vulnerability.

    Source:rgod
    Published:21 Dec 2005
    4.3
    Medium

    CVE-2005-4435

    Last Modified: 18 Jul 2013

    Cross-site scripting (XSS) vulnerability in index.php AbleDesign D-Man 3.x allows remote attackers to inject arbitrary web script or HTML via the title parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:$um$id
    Published:21 Dec 2005
    4.3
    Medium

    CVE-2005-4432

    Last Modified: 23 Jan 2017

    Cross-site scripting (XSS) vulnerability in index.php in PlaySMS 0.8 allows remote attackers to inject arbitrary web script or HTML via the err parameter.

    Source:mohajali2k4
    Published:21 Dec 2005
    7.5
    High

    CVE-2005-4430

    Last Modified: 23 Jul 2013

    SQL injection vulnerability in LogicBill 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) __mode and (2) __id parameters to helpdesk.php.

    Source:r0t3d3Vil
    Published:21 Dec 2005
    7.5
    High

    CVE-2005-4429

    Last Modified: 23 Jul 2013

    SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php.

    Source:r0t3d3Vil
    Published:21 Dec 2005
    7.5
    High

    CVE-2005-4427

    Last Modified: 21 Jul 2013

    Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to attachment_send.php, (2) the $addy variable in email_parser.php, (3) $address variable in email_parser.php, (4) $a_address variable in structs.php, (5) kbid parameter to cer_KnowledgebaseHandler.class.php, (6) queues[] parameter to addresses_export.php, (7) $thread variable to display.php, (8) ticket parameter to display_ticket_thread.php.

    Source:A. Ramos
    Published:20 Dec 2005
    6.5
    Medium

    CVE-2005-4423

    Last Modified: 29 Jun 2013

    Unrestricted file upload vulnerability in PHPFM before 0.2.3 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension to an accessible directory, as demonstrated using a file with a .php extension, aka "upload phpshell."

    Source:rUnViRuS
    Published:20 Dec 2005
    7.5
    High

    CVE-2005-4419

    Last Modified: 18 Jul 2013

    Multiple SQL injection vulnerabilities in CategoryResults.cfm in Honeycomb Archive and Honeycomb Archive Enterprise 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) series, (2) cat_parent, (3) cat, and (4) div parameters.

    Source:r0t3d3Vil
    Published:20 Dec 2005
    6.4
    Medium

    CVE-2005-4417

    Last Modified: 16 Apr 2026

    The default configuration of Widcomm Bluetooth for Windows (BTW) 4.0.1.1500 and earlier, as installed on Belkin Bluetooth Software 1.4.2 Build 10 and ANYCOM Blue USB-130-250 Software 4.0.1.1500, and possibly other devices, sets null Authentication and Authorization values, which allows remote attackers to send arbitrary audio and possibly eavesdrop using the microphone via the Hands Free Audio Gateway and Headset profile.

    Source:Kevin Finisterre
    Published:20 Dec 2005
    7.5
    High

    CVE-2005-4416

    Last Modified: 15 Jul 2013

    SQL injection vulnerability in index.php in TML CMS 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:X1ngBox
    Published:20 Dec 2005
    4.3
    Medium

    CVE-2005-4415

    Last Modified: 15 Jul 2013

    Cross-site scripting (XSS) vulnerability in index.php in TML CMS 0.5 allows remote attackers to inject arbitrary web script or HTML via the form parameter.

    Source:X1ngBox
    Published:20 Dec 2005
    7.5
    High

    CVE-2005-4411

    Last Modified: 22 Nov 2017

    Buffer overflow in Mercury Mail Transport System 4.01b allows remote attackers to execute arbitrary code via a long request to TCP port 105.

    Source:kingcope
    Published:20 Dec 2005
    7.5
    High

    CVE-2005-4408

    Last Modified: 17 Jul 2013

    Multiple SQL injection vulnerabilities in Miraserver 1.0 RC4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) id parameter to newsitem.php, and (3) cat parameter to article.php.

    Source:r0t
    Published:20 Dec 2005
    7.5
    High

    CVE-2005-4403

    Last Modified: 17 Jul 2013

    SQL injection vulnerability in index.php in Marwel 2.7 and earlier allows remote attackers to execute arbitrary SQL commands via the show parameter.

    Source:r0t
    Published:20 Dec 2005
    6.5
    Medium

    CVE-2005-4402

    Last Modified: 25 May 2017

    Buffer overflow in MailEnable Professional 1.71 and earlier, and Enterprise 1.1 and earlier, allows remote authenticated users to execute arbitrary code via a long IMAP EXAMINE command.

    Source:muts
    Published:20 Dec 2005
    4.3
    Medium

    CVE-2005-4400

    Last Modified: 16 Jul 2013

    Cross-site scripting (XSS) vulnerability in downloads/portal_ent in Liferay Portal Enterprise 3.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) _77_struts_action, (2) p_p_mode, and (3) p_p_state parameters.

    Source:r0t3d3Vil
    Published:20 Dec 2005
    4.3
    Medium

    CVE-2005-4399

    Last Modified: 16 Jul 2013

    Cross-site scripting (XSS) vulnerability in search/index.php in Libertas Enterprise CMS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page_search parameter.

    Source:r0t3d3Vil
    Published:20 Dec 2005
    7.5
    High

    CVE-2005-4390

    Last Modified: 17 Jul 2013

    SQL injection vulnerability in index.php in ContentServ 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the StoryID parameter.

    Source:r0t
    Published:20 Dec 2005
    4.3
    Medium

    CVE-2005-4385

    Last Modified: 16 Jul 2013

    Cross-site scripting (XSS) vulnerability in search.htm in Cofax 2.0 RC3 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter.

    Source:r0t3d3Vil
    Published:20 Dec 2005
    4.3
    Medium

    CVE-2005-4381

    Last Modified: 16 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Caravel CMS 3.0 Beta 1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) fileDN and (2) folderviewer_attrs parameters.

    Source:r0t3d3Vil
    Published:20 Dec 2005
    7.5
    High

    CVE-2005-4380

    Last Modified: 17 Jul 2013

    Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to (a) fisheye/list_galleries.php, (b) messages/message_box.php, and (c) users/my.php; the (2) post_id parameter to (d) blogs/view_post.php; and the (3) blog_id parameter to (e) blogs/view.php, which are not properly cleansed by the convert_sortmode function in kernel/BitDb.php.

    Source:r0t
    Published:20 Dec 2005
    7.5
    High

    CVE-2005-4378

    Last Modified: 17 Jul 2013

    SQL injection vulnerability in Page.asp in Baseline CMS 1.95 and earlier allows remote attackers to execute arbitrary SQL commands via the SiteNodeID parameter.

    Source:r0t
    Published:20 Dec 2005
    4.3
    Medium

    CVE-2005-4375

    Last Modified: 16 Jul 2013

    Cross-site scripting (XSS) vulnerability in Amaxus 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the change parameter. NOTE: it is possible that this is resultant from CVE-2005-4376.

    Source:r0t3d3Vil
    Published:20 Dec 2005
    4.3
    Medium

    CVE-2005-4374

    Last Modified: 16 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Allinta 2.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to faq.asp and (2) searchQuery parameter to search.asp.

    Source:r0t3d3Vil
    Published:20 Dec 2005
    5
    Medium

    CVE-2005-4371

    Last Modified: 24 Nov 2016

    Acidcat 2.1.13 and earlier stores the database under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a request to databases/acidcat.mdb.

    Published:20 Dec 2005