7.5
    High

    CVE-2005-4370

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in main_content.asp in Acidcat 2.1.13 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter to default.asp.

    Published:20 Dec 2005
    4.3
    Medium

    CVE-2005-4365

    Last Modified: 16 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in FLIP 0.9.0.1029 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter in text.php and (2) frame parameter in forum.php.

    Source:r0t3d3Vil
    Published:20 Dec 2005
    5.8
    Medium

    CVE-2005-4364

    Last Modified: 16 Jul 2013

    Cross-site scripting (XSS) vulnerability in index.cfm in Hot Banana Web Content Management Suite 5.3 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.

    Source:r0t3d3Vil
    Published:20 Dec 2005
    5.8
    Medium

    CVE-2005-4363

    Last Modified: 17 Jul 2013

    Cross-site scripting (XSS) vulnerability in the search engine in Komodo CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.

    Source:r0t3d3Vil
    Published:20 Dec 2005
    4.3
    Medium

    CVE-2005-4361

    Last Modified: 17 Jul 2013

    Cross-site scripting (XSS) vulnerability in search.html in Magnolia Content Management Suite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Source:r0t3d3Vil
    Published:20 Dec 2005
    7.8
    High

    CVE-2005-4360

    Last Modified: 11 Jul 2017

    The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrary code via multiple requests to ".dll" followed by arguments such as "~0" through "~9", which causes ntdll.dll to produce a return value that is not correctly handled by IIS, as demonstrated using "/_vti_bin/.dll/*/~0". NOTE: the consequence was originally believed to be only a denial of service (application crash and reboot).

    Source:Kozan
    Published:20 Dec 2005
    7.5
    High

    CVE-2005-4334

    Last Modified: 28 Jul 2013

    SQL injection vulnerability in ZixForum 1.12 allows remote attackers to execute arbitrary SQL commands via the H_ID parameter to (1) zixforum/forum.asp, as used in (2) Headforums.asp and (3) Subject.asp.

    Source:Tran Viet Phuong
    Published:17 Dec 2005
    4.3
    Medium

    CVE-2005-4333

    Last Modified: 17 Aug 2017

    Multiple cross-site scripting (XSS) vulnerabilities in Binary Board System (BBS) 0.2.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) inreplyto, (2) article, and (3) board parameters to reply.pl, (4) branch, (5) board, and (6) stats.pl parameters to (b) stats.pl, and (7) board parameter to (c) toc.pl.

    Source:r0t3d3Vil
    Published:17 Dec 2005
    7.5
    High

    CVE-2005-4331

    Last Modified: 16 Jul 2013

    SQL injection vulnerability in merchant.ihtml in iHTML Merchant Version 2 Pro allows remote attackers to execute arbitrary SQL commands via the (1) step, (2) id, and (3) pid parameters.

    Source:r0t3d3Vil
    Published:17 Dec 2005
    7.5
    High

    CVE-2005-4330

    Last Modified: 16 Jul 2013

    SQL injection vulnerability in browse.ihtml in iHTML Merchant Mall allows remote attackers to execute arbitrary SQL commands via the (1) id, (2) store, and (3) step parameters.

    Source:r0t3d3Vil
    Published:17 Dec 2005
    7.5
    High

    CVE-2005-4329

    Last Modified: 16 Jul 2013

    SQL injection vulnerability in pafiledb.php in PHP Arena paFileDB Extreme Edition RC 5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) newsid and (2) id parameter.

    Source:r0t3d3Vil
    Published:17 Dec 2005
    4.3
    Medium

    CVE-2005-4328

    Last Modified: 16 Jul 2013

    Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the ID parameter.

    Source:r0t3d3Vil
    Published:17 Dec 2005
    4.3
    Medium

    CVE-2005-4327

    Last Modified: 16 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Michael Arndt WebCal 1.11-3.04 allow remote attackers to inject arbitrary web script or HTML via the (1) function, (2) year, and (3) date parameters to webcal.cgi, (4) new calendar entries, and (5) notes for entries.

    Source:Stan Bubrouski
    Published:17 Dec 2005
    5
    Medium

    CVE-2005-4319

    Last Modified: 10 Nov 2016

    Directory traversal vulnerability in index2.php in Limbo CMS 1.0.4.2 and earlier allows remote attackers to include arbitrary PHP files via ".." sequences in the option parameter.

    Source:rgod
    Published:17 Dec 2005
    7.5
    High

    CVE-2005-4318

    Last Modified: 22 Nov 2017

    SQL injection vulnerability in index.php in Limbo CMS 1.0.4.2 and earlier, with register_globals off, allows remote attackers to execute arbitrary SQL commands via the _SERVER[REMOTE_ADDR] parameter, which modifies the underlying $_SERVER variable.

    Source:rgod
    Published:17 Dec 2005
    6.8
    Medium

    CVE-2005-4317

    Last Modified: 15 Jul 2013

    Limbo CMS 1.0.4.2 and earlier, with register_globals off, does not protect the $_SERVER variable from external modification, which allows remote attackers to use the _SERVER[REMOTE_ADDR] parameter to (1) conduct cross-site scripting (XSS) attacks in the stats module or (2) execute arbitrary code via an eval injection attack in the wrapper option in index2.php.

    Source:rgod
    Published:17 Dec 2005
    7.8
    High

    CVE-2005-4316

    Last Modified: 7 Mar 2013

    HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via a "Rose Attack" that involves sending a subset of small IP fragments that do not form a complete, larger packet.

    Source:Coolio
    Published:17 Dec 2005
    4.3
    Medium

    CVE-2005-4314

    Last Modified: 15 Jul 2013

    Cross-site scripting (XSS) vulnerability in ppcal.cgi in PPCal Shopping Cart 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) stop and (2) user parameters.

    Source:r0t3d3Vil
    Published:17 Dec 2005
    4.3
    Medium

    CVE-2005-4311

    Last Modified: 15 Jul 2013

    Cross-site scripting (XSS) vulnerability in DCForum 6.25 and earlier, and possibly DCForum+ 1.x, allows remote attackers to inject arbitrary web script or HTML via (1) the page parameter in dcboard.php and (2) unspecified search parameters.

    Source:r0t3d3Vil
    Published:17 Dec 2005
    4.3
    Medium

    CVE-2005-4307

    Last Modified: 16 Jul 2013

    Cross-site scripting (XSS) vulnerability in ScareCrow 2.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the forum parameter to (1) forum.cgi and (2) post.cgi, or (3) the user parameter to profile.cgi.

    Source:r0t3d3Vil
    Published:17 Dec 2005
    4.3
    Medium

    CVE-2005-4306

    Last Modified: 15 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in SiteNet BBS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) pg, (2) tid, (3) cid, and (4) fid parameters to netboardr.cgi, or (5) cid parameter to search.cgi.

    Source:r0t3d3Vil
    Published:17 Dec 2005
    7.5
    High

    CVE-2005-4303

    Last Modified: 15 Jul 2013

    SQL injection vulnerability in index.php for ezDatabase 2.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the db_id parameter.

    Source:r0t3d3Vil
    Published:17 Dec 2005
    5
    Medium

    CVE-2005-4302

    Last Modified: 15 Jul 2013

    Directory traversal vulnerability in index.php in ezDatabase 2.1.2 and earlier allows remote attackers to include arbitrary local files via ".." sequences in the p parameter.

    Source:r0t3d3Vil
    Published:17 Dec 2005
    4.3
    Medium

    CVE-2005-4299

    Last Modified: 15 Jul 2013

    Cross-site scripting (XSS) vulnerability in atl.cgi in Atlant Pro 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) before and (2) ct parameters.

    Source:r0t3d3Vil
    Published:16 Dec 2005
    4.3
    Medium

    CVE-2005-4298

    Last Modified: 15 Jul 2013

    Cross-site scripting (XSS) vulnerability in atl.cgi in AtlantForum 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) sch_allsubct, (2) before, and (3) ct parameters.

    Source:r0t3d3Vil
    Published:16 Dec 2005
    7.8
    High

    CVE-2005-4296

    Last Modified: 14 Jul 2013

    AppServ Open Project 2.5.3 allows remote attackers to cause a denial of service via a large HTTP request.

    Source:Rozor
    Published:16 Dec 2005
    4.3
    Medium

    CVE-2005-4293

    Last Modified: 15 Jul 2013

    Cross-site scripting (XSS) vulnerability in cp-app.cgi in ClickCartPro (CCP) 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the affl parameter.

    Source:r0t3d3Vil
    Published:16 Dec 2005
    4.3
    Medium

    CVE-2005-4291

    Last Modified: 15 Jul 2013

    Cross-site scripting (XSS) vulnerability in cart.cgi in ECTOOLS Onlineshop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) product, (2) category, and (3) uid parameters.

    Source:r0t3d3Vil
    Published:16 Dec 2005
    4.3
    Medium

    CVE-2005-4290

    Last Modified: 15 Jul 2013

    Cross-site scripting (XSS) vulnerability in index.cgi in ECW-Cart 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) kword, (2) max, (3) min, (4) comp, and (5) f parameters.

    Source:r0t3d3Vil
    Published:16 Dec 2005
    4.3
    Medium

    CVE-2005-4289

    Last Modified: 15 Jul 2013

    Cross-site scripting (XSS) vulnerability in EDCstore.pl in eDatCat 0.3 allows remote attackers to inject arbitrary web script or HTML via the user_action parameter.

    Source:r0t3d3Vil
    Published:16 Dec 2005
    4.3
    Medium

    CVE-2005-4288

    Last Modified: 15 Jul 2013

    Cross-site scripting (XSS) vulnerability in index.php in MarmaraWeb E-commerce allows remote attackers to inject arbitrary web script or HTML via the page parameter to index.php. NOTE: this might be resultant from CVE-2005-4287.

    Source:B3g0k
    Published:16 Dec 2005
    7.5
    High

    CVE-2005-4287

    Last Modified: 15 Jul 2013

    PHP remote file include vulnerability in MarmaraWeb E-commerce allows remote attackers to execute arbitrary code via the page parameter to index.php.

    Source:B3g0k
    Published:16 Dec 2005
    4.3
    Medium

    CVE-2005-4285

    Last Modified: 15 Jul 2013

    Cross-site scripting (XSS) vulnerability in pdestore.cgi in Dick Copits PDEstore 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the search module parameter or the (2) product and (3) cart_id parameters.

    Source:r0t3d3Vil
    Published:16 Dec 2005
    7.8
    High

    CVE-2005-4276

    Last Modified: 15 Jul 2013

    Westell Versalink 327W allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD). NOTE: the provenance of this issue is unknown; the details are obtained solely from third party information.

    Source:Justin M. Wray
    Published:16 Dec 2005
    7.8
    High

    CVE-2005-4275

    Last Modified: 15 Jul 2013

    Scientific Atlanta DPX2100 Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD), as demonstrated using hping2. NOTE: the provenance of this issue is unknown; the details are obtained solely from third party information.

    Source:Justin M. Wray
    Published:16 Dec 2005
    7.5
    High

    CVE-2005-4270

    Last Modified: 16 Apr 2026

    Buffer overflow in Watchfire AppScan QA 5.0.609 and 5.0.134 allows remote web servers to execute arbitrary code via an HTTP 401 response with a WWW-Authenticate header containing a long Realm field.

    Source:Mariano Nuñez
    Published:15 Dec 2005
    7.5
    High

    CVE-2005-4267

    Last Modified: 25 May 2017

    Stack-based buffer overflow in Qualcomm WorldMail 3.0 allows remote attackers to execute arbitrary code via a long IMAP command that ends with a "}" character, as demonstrated using long (1) LIST, (2) LSUB, (3) SEARCH TEXT, (4) STATUS INBOX, (5) AUTHENTICATE, (6) FETCH, (7) SELECT, and (8) COPY commands.

    Source:muts
    Published:21 Dec 2005
    7.5
    High

    CVE-2005-4263

    Last Modified: 14 Jul 2013

    SQL injection vulnerability in the News module in Envolution allows remote attackers to execute arbitrary SQL commands via the (1) startrow and (2) catid parameter.

    Source:X1ngBox
    Published:15 Dec 2005
    4.3
    Medium

    CVE-2005-4262

    Last Modified: 14 Jul 2013

    Cross-site scripting (XSS) vulnerability in the News module in Envolution allows remote attackers to inject arbitrary web script or HTML via the (1) startrow and (2) catid parameter. NOTE: this issue might be resultant from the SQL injection problem (CVE-2005-4263).

    Source:X1ngBox
    Published:15 Dec 2005
    4.3
    Medium

    CVE-2005-4260

    Last Modified: 14 Nov 2017

    Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and later allows remote attackers to perform cross-site scripting (XSS) attacks by replacing the ">" in the tag with a "<", which bypasses the regular expressions that sanitize the data, but is automatically corrected by many web browsers. NOTE: it could be argued that this vulnerability is due to a design limitation of many web browsers; if so, then this should not be treated as a vulnerability in PHP-Nuke.

    Source:Maksymilian Arciemowicz
    Published:15 Dec 2005
    7.5
    High

    CVE-2005-4259

    Last Modified: 14 Jul 2013

    Multiple SQL injection vulnerabilities in ASPBB 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) TID parameter in topic.asp, (2) FORUM_ID parameter in forum.asp, and (3) PROFILE_ID parameter in profile.asp. NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID.

    Source:Dj_Eyes
    Published:15 Dec 2005
    4.3
    Medium

    CVE-2005-4256

    Last Modified: 14 Jul 2013

    Cross-site scripting (XSS) vulnerability in forum.asp in ASP-DEV XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via the forum_title parameter. NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID. In addition, its accuracy is in question because "forum_title" does not appear to be specified in the source code for XM Forum RC3. It is possible, but not certain, that this is CVE-2004-2211.

    Source:Dj_Eyes
    Published:15 Dec 2005
    4.3
    Medium

    CVE-2005-4255

    Last Modified: 14 Jul 2013

    Cross-site scripting (XSS) vulnerability in TextSearch in WikkaWiki 1.1.6.0 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded phrase parameter.

    Source:r0t
    Published:15 Dec 2005
    7.5
    High

    CVE-2005-4254

    Last Modified: 4 Oct 2017

    SQL injection vulnerability in view_Results.php in DreamLevels DreamPoll 3.0 final allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:r0t3d3Vil
    Published:15 Dec 2005
    7.5
    High

    CVE-2005-4251

    Last Modified: 14 Jul 2013

    Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and the (4) album parameter to index.php.

    Source:r0t
    Published:14 Dec 2005
    5
    Medium

    CVE-2005-4250

    Last Modified: 14 Jul 2013

    Directory traversal vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to read arbitrary files via the language parameter.

    Source:r0t
    Published:14 Dec 2005
    4.3
    Medium

    CVE-2005-4247

    Last Modified: 13 Jul 2013

    Cross-site scripting (XSS) vulnerability in index.php in Plogger Beta 2 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter.

    Source:r0t
    Published:14 Dec 2005
    7.5
    High

    CVE-2005-4246

    Last Modified: 13 Jul 2013

    SQL injection vulnerability in Plogger Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php and (2) page parameter.

    Source:r0t
    Published:14 Dec 2005
    4.3
    Medium

    CVE-2005-4245

    Last Modified: 13 Jul 2013

    Cross-site scripting (XSS) vulnerability in search.php in Snipe Gallery 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.

    Source:r0t
    Published:14 Dec 2005
    7.5
    High

    CVE-2005-4244

    Last Modified: 13 Jul 2013

    SQL injection vulnerability in Snipe Gallery 3.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) gallery_id parameter to view.php and (2) image_id parameter to image.php.

    Source:r0t
    Published:14 Dec 2005