6.5
    Medium

    CVE-2005-4093

    Last Modified: 11 Jul 2013

    Check Point VPN-1 SecureClient NG with Application Intelligence R56, NG FP1, 4.0, and 4.1 allows remote attackers to bypass security policies by modifying the local copy of the local.scv policy file after it has been downloaded from the VPN Endpoint.

    Source:Viktor Steinmann
    Published:8 Dec 2005
    4.3
    Medium

    CVE-2005-4091

    Last Modified: 10 Jul 2013

    Cross-site scripting (XSS) vulnerability in 1search.cgi in 1-Script 1-Search 1.8 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Source:r0t
    Published:8 Dec 2005
    7.5
    High

    CVE-2005-4087

    Last Modified: 13 Jun 2016

    PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier allows remote attackers to execute arbitrary PHP code via a URL in the beanFiles array parameter.

    Source:rgod
    Published:8 Dec 2005
    5
    Medium

    CVE-2005-4086

    Last Modified: 13 Jun 2016

    Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the beanFiles array parameter.

    Source:rgod
    Published:8 Dec 2005
    7.5
    High

    CVE-2005-4085

    Last Modified: 10 Mar 2011

    Buffer overflow in BlueCoat (a) WinProxy before 6.1a and (b) the web console access functionality in ProxyAV before 2.4.2.3 allows remote attackers to execute arbitrary code via a long Host: header.

    Source:Metasploit
    Published:31 Dec 2005
    7.5
    High

    CVE-2005-4081

    Last Modified: 9 Jul 2013

    Multiple SQL injection vulnerabilities in Alisveristr E-commerce allow remote attackers to bypass authentication and possibly execute arbitrary SQL commands via the username and password parameters in (1) the user login and (2) administrator login pages.

    Source:B3g0k
    Published:8 Dec 2005
    4.3
    Medium

    CVE-2005-4080

    Last Modified: 11 Jul 2013

    Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet Explorer, which ignores the characters.

    Source:SEC Consult
    Published:8 Dec 2005
    4.6
    Medium

    CVE-2005-4076

    Last Modified: 22 Nov 2017

    Buffer overflow in Appfluent Technology Database IDS 2.0 allows local users to execute arbitrary code via a long APPFLUENT_HOME environment variable.

    Source:c0ntex
    Published:8 Dec 2005
    4.3
    Medium

    CVE-2005-4075

    Last Modified: 12 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in CF_Nuke 4.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) newsid parameter in the news sector, and (3) cat parameter in the links sector.

    Source:r0t
    Published:8 Dec 2005
    5
    Medium

    CVE-2005-4074

    Last Modified: 12 Jul 2013

    Directory traversal vulnerability in index.cfm in CF_Nuke 4.6 and earlier, when Sandbox Security is disabled, allows remote attackers to include arbitrary local .cfm files via a .. (dot dot) in the (1) sector or (2) page parameters.

    Source:r0t
    Published:8 Dec 2005
    7.5
    High

    CVE-2005-4073

    Last Modified: 12 Jul 2013

    SQL injection vulnerability in view_archive.cfm in CFMagic Magic List Pro 2.5 allows remote attackers to execute arbitrary SQL commands via the ListID parameter.

    Source:r0t
    Published:8 Dec 2005
    7.5
    High

    CVE-2005-4071

    Last Modified: 12 Jul 2013

    Multiple SQL injection vulnerabilities in CFMagic Magic Forum Personal 2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ForumID parameter in view_forum.cfm, and (2) ForumID, (3) Thread, and (4) ThreadID parameters in view_thread.cfm.

    Source:r0t
    Published:8 Dec 2005
    7.5
    High

    CVE-2005-4065

    Last Modified: 10 Jul 2013

    SQL injection vulnerability in the search module in Edgewall Trac before 0.9.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Source:anonymous
    Published:7 Dec 2005
    7.5
    High

    CVE-2005-4064

    Last Modified: 11 Jul 2013

    Multiple SQL injection vulnerabilities in A-FAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) faqid parameter to faqDspItem.asp and (2) catcode parameter to faqDsp.asp.

    Source:r0t
    Published:7 Dec 2005
    4.3
    Medium

    CVE-2005-4063

    Last Modified: 11 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in NetAuctionHelp 3.0 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) L, (2) sort, (3) category, (4) categoryname parameters to search.asp.

    Source:r0t
    Published:7 Dec 2005
    4.3
    Medium

    CVE-2005-4060

    Last Modified: 11 Jul 2013

    Cross-site scripting (XSS) vulnerability in search.asp in rwAuction Pro 4.0 and 5.0 allows remote attackers to inject arbitrary web script or HTML via the searchtxt parameter.

    Source:r0t
    Published:7 Dec 2005
    7.5
    High

    CVE-2005-4055

    Last Modified: 11 Jul 2013

    SQL injection vulnerability in index.php in Cars Portal 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) page and (2) car parameters.

    Source:r0t
    Published:7 Dec 2005
    7.5
    High

    CVE-2005-4054

    Last Modified: 11 Jul 2013

    SQL injection vulnerability in index.php in PluggedOut Blog 1.9.5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) categoryid, (2) entryid, (3) year, (4) month, and (5) day parameter.

    Source:r0t
    Published:7 Dec 2005
    4.3
    Medium

    CVE-2005-4053

    Last Modified: 26 Dec 2013

    Cross-site scripting (XSS) vulnerability in coWiki 0.3.4 allows remote attackers to inject arbitrary web script or HTML via the q parameter, as demonstrated using 26.html.

    Source:MustLive
    Published:7 Dec 2005
    7.5
    High

    CVE-2005-4049

    Last Modified: 10 Jul 2013

    Multiple SQL injection vulnerabilities in Blog System 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the cat parameter in index.php and (2) the note parameter in blog.php.

    Source:r0t3d3Vil
    Published:7 Dec 2005
    4.3
    Medium

    CVE-2005-4047

    Last Modified: 11 Jul 2013

    Cross-site scripting (XSS) vulnerability in kb.asp in IISWorks ASPKnowledgeBase 2.0 allows remote attackers to inject arbitrary web script or HTML via the a parameter.

    Source:r0t
    Published:7 Dec 2005
    7.5
    High

    CVE-2005-4043

    Last Modified: 10 Jul 2013

    SQL injection vulnerability in view.php in Hobosworld HobSR 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) arrange and (2) p parameters.

    Source:r0t3d3Vil
    Published:6 Dec 2005
    7.8
    High

    CVE-2005-4039

    Last Modified: 10 Jul 2013

    Directory traversal vulnerability in arhiva.php in Web4Future Portal Solutions News Portal allows remote attackers to read arbitrary files via the dir parameter.

    Source:r0t
    Published:6 Dec 2005
    7.5
    High

    CVE-2005-4037

    Last Modified: 10 Jul 2013

    SQL injection vulnerability in functions.php in Web4Future Affiliate Manager PRO 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter.

    Source:r0t
    Published:6 Dec 2005
    7.5
    High

    CVE-2005-4035

    Last Modified: 10 Jul 2013

    Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prod, and (2) brid parameters to (a) view.php; the (3) the bid parameter to (b) viewbrands.php; and the (4) grp and (5) cat parameters to index.php.

    Source:r0t3d3Vil
    Published:6 Dec 2005
    7.5
    High

    CVE-2005-4034

    Last Modified: 10 Jul 2013

    Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) pg, and (3) sortb parameters to (a) index.php; (4) cid parameter to (b) gift.php and (c) fq.php; and (5) cat parameter to (d) articles.php.

    Source:r0t
    Published:6 Dec 2005
    4.3
    Medium

    CVE-2005-4032

    Last Modified: 9 Jul 2013

    Cross-site scripting (XSS) vulnerability in search.cgi in Easy Search System 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Source:r0t
    Published:6 Dec 2005
    7.5
    High

    CVE-2005-4019

    Last Modified: 10 Jul 2013

    SQL injection vulnerability in index.php in Relative Real Estate Systems 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the mls parameter.

    Source:r0t3d3Vil
    Published:5 Dec 2005
    7.5
    High

    CVE-2005-4018

    Last Modified: 10 Jul 2013

    SQL injection vulnerability in ls.php in Landshop Real Estate Commerce System 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) start, (2) search_order, (3) search_type, (4) search_area, and (5) keyword parameters.

    Source:r0t3d3Vil
    Published:5 Dec 2005
    7.5
    High

    CVE-2005-4016

    Last Modified: 9 Jul 2013

    SQL injection vulnerability in Widget Property 1.1.19 allows remote attackers to execute arbitrary SQL commands via the (1) property_id, (2) zip_code, (3) property_type_id, (4) price, and (5) city_id parameters to property.php.

    Source:r0t3d3Vil
    Published:5 Dec 2005
    7.5
    High

    CVE-2005-4011

    Last Modified: 5 Sept 2013

    SQL injection vulnerability in calendar.php in Codewalkers ltwCalendar (aka PHP Event Calendar) 4.2, 4.1.3, and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Silitix
    Published:5 Dec 2005
    7.5
    High

    CVE-2005-4005

    Last Modified: 22 Nov 2016

    SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to obtain path information and possibly execute arbitrary SQL commands via the srch_text parameter in a Search and Sort option to messages.php.

    Source:Nolan West
    Published:5 Dec 2005
    7.5
    High

    CVE-2005-4003

    Last Modified: 8 Jul 2013

    Multiple SQL injection vulnerabilities in Absolute Shopping Package Solutions (ASPS) Shopping Cart Professional 2.9d and earlier, and Lite 2.1 and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) srch_product_name parameter to adv_search.asp and (2) b_search parameter to bsearch.asp. NOTE: the original disclosure was specifically only for an XSS issue, but the CVE description was for SQL injection. Since the original disclosure, SQL injection vectors have been reported. This CVE might be REJECTed or significantly altered pending additional information.

    Source:r0t3d3Vil
    Published:5 Dec 2005
    7.5
    High

    CVE-2005-4001

    Last Modified: 9 Jul 2013

    Multiple SQL injection vulnerabilities in phpYellowTM Pro Edition and Lite Edition 5.33 allow remote attackers to execute arbitrary SQL commands via the (1) haystack parameter to search_result.php or (2) ckey parameter to print_me.php.

    Source:r0t3d3Vil
    Published:5 Dec 2005
    4.3
    Medium

    CVE-2005-4000

    Last Modified: 9 Jul 2013

    Cross-site scripting (XSS) vulnerability in archive.asp in SiteBeater News System 4.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the sKeywords parameter.

    Source:r0t3d3Vil
    Published:5 Dec 2005
    4.3
    Medium

    CVE-2005-3998

    Last Modified: 9 Jul 2013

    Cross-site scripting (XSS) vulnerability in search.asp in Solupress News 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.

    Source:r0t3d3Vil
    Published:5 Dec 2005
    5.1
    Medium

    CVE-2005-3996

    Last Modified: 13 Jun 2016

    SQL injection vulnerability in admin/password_forgotten.php in Zen Cart 1.2.6d and earlier allows remote attackers to execute arbitrary SQL commands via the admin_email parameter.

    Source:rgod
    Published:5 Dec 2005
    5.1
    Medium

    CVE-2005-3995

    Last Modified: 13 Jun 2016

    Format string vulnerability in the dosyslog function in the OBEX server (obexsrv.c) for Sobexsrv before 1.0.0-pre4, when the syslog (-S) function is enabled, allows remote attackers to execute arbitrary code via format string specifiers in file name arguments to OBEX commands.

    Source:Kevin Finisterre
    Published:5 Dec 2005
    7.5
    High

    CVE-2005-3992

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in WinEggDropShell remote access trojan (RAT) 1.7 allow remote attackers to execute arbitrary code via (1) a long GET request to the HTTP server, or a long (2) USER or (3) PASS command to the FTP server.

    Source:Sowhat
    Published:4 Dec 2005
    4.3
    Medium

    CVE-2005-3991

    Last Modified: 8 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyChat 0.14.6 allow remote attackers to inject arbitrary web script or HTML via the medium parameter to (1) start_page.css.php and (2) style.css.php; or the From parameter to users_popupL.php.

    Source:Louis Wang
    Published:4 Dec 2005
    7.5
    High

    CVE-2005-3988

    Last Modified: 8 Jul 2013

    SQL injection vulnerability in article.php in Pineapple Technologies Lore 1.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:r0t
    Published:4 Dec 2005
    7.5
    High

    CVE-2005-3986

    Last Modified: 8 Jul 2013

    Multiple SQL injection vulnerabilities in Instant Photo Gallery 1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter in portfolio.php and (2) cid parameter in content.php.

    Source:r0t
    Published:4 Dec 2005
    5
    Medium

    CVE-2005-3982

    Last Modified: 9 Dec 2016

    CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response splitting attacks via the ret parameter, which is used to redirect URL requests.

    Source:lwang
    Published:4 Dec 2005
    4.9
    Medium

    CVE-2005-3981

    Last Modified: 8 Jul 2013

    NOTE: this issue has been disputed by third parties. Microsoft Windows XP, 2000, and 2003 allows local users to kill a writable process by using the CreateRemoteThread function with certain arguments on a process that has been opened using the OpenProcess function, possibly involving an invalid address for the start routine. NOTE: followup posts have disputed this issue, saying that if a user already has privileges to write to a process, then other functions could be called or the process could be terminated using PROCESS_TERMINATE

    Source:Nima Salehi
    Published:4 Dec 2005
    7.5
    High

    CVE-2005-3980

    Last Modified: 8 Jul 2013

    SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the group parameter.

    Source:David Maciejak
    Published:4 Dec 2005
    7.5
    High

    CVE-2005-3978

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter in (a) ViewCat.php and (b) gallery.php, and the (2) ItemNum parameter in (c) ViewItem.php.

    Source:laurent gaffié
    Published:3 Dec 2005
    4.3
    Medium

    CVE-2005-3972

    Last Modified: 8 Jul 2013

    Cross-site scripting (XSS) vulnerability in extremesearch.php in Extreme Search Corporate Edition 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Source:r0t
    Published:3 Dec 2005
    7.5
    High

    CVE-2005-3968

    Last Modified: 8 Jul 2013

    SQL injection vulnerability in auth.inc.php in PHPX 3.5.9 and earlier allows remote attackers to execute arbitrary SQL commands, bypass authentication, and upload arbitrary PHP code via the username parameter.

    Source:rgod
    Published:3 Dec 2005
    4.3
    Medium

    CVE-2005-3966

    Last Modified: 8 Jul 2013

    Cross-site scripting (XSS) vulnerability in search.jsp in Java Search Engine (JSE) 0.9.34 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Source:r0t
    Published:3 Dec 2005
    7.5
    High

    CVE-2005-3963

    Last Modified: 8 Jul 2013

    SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd parameter in a cookie.

    Source:Siegfried
    Published:2 Dec 2005