4.3
    Medium

    CVE-2005-3959

    Last Modified: 6 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in FreeWebStat 1.0 rev37 allow remote attackers to inject arbitrary web script or HTML via the (1) site, (2) jsref, (3) jsres, and (4) jscolor parameters to pixel.php, which are not sanitized before being included in the logdb.html file, and (5) the search key to stat.php.

    Source:Francesco Ongaro
    Published:1 Dec 2005
    7.5
    High

    CVE-2005-3958

    Last Modified: 7 Jul 2013

    SQL injection vulnerability in index.php in Entergal MX 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) idcat parameter in a showcat action and (2) the action parameter.

    Source:r0t
    Published:1 Dec 2005
    7.5
    High

    CVE-2005-3956

    Last Modified: 7 Jul 2013

    Multiple SQL injection vulnerabilities in index.php in DMANews 0.904 and 0.910 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a comments action and the (2) sortorder and (3) display_num parameters in a news_list action.

    Source:r0t
    Published:1 Dec 2005
    4.3
    Medium

    CVE-2005-3955

    Last Modified: 3 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (2) rss_url parameter to (b) magpie_slashbox.php and (c) simple_smarty.php.

    Source:gb.network
    Published:1 Dec 2005
    4.3
    Medium

    CVE-2005-3954

    Last Modified: 3 Jul 2013

    Cross-site scripting (XSS) vulnerability in blogBuddies 0.3 allows remote attackers to inject arbitrary web script or HTML via the u parameter to index.php.

    Source:gb.network
    Published:1 Dec 2005
    7.5
    High

    CVE-2005-3953

    Last Modified: 5 Jul 2013

    SQL injection vulnerability in Bedeng PSP 1.1 allows remote attackers to execute arbitrary SQL commands via the cwhere parameter to (1) index.php and (2) download.php, or (3) ckode parameter to baca.php.

    Source:r0t
    Published:1 Dec 2005
    7.5
    High

    CVE-2005-3952

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PHP Labs Top Auction allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) type parameters to viewcat.php, or (3) certain search parameters. NOTE: later a disclosure reported the affected version as 1.0.

    Source:ajann
    Published:1 Dec 2005
    5
    Medium

    CVE-2005-3948

    Last Modified: 27 Oct 2016

    Directory traversal vulnerability in main.php in PHPAlbum 0.2.3 and earlier allows remote attackers to read arbitrary files via the (1) cmd and (2) var1 parameters.

    Source:r0t3d3Vil
    Published:1 Dec 2005
    5
    Medium

    CVE-2005-3947

    Last Modified: 7 Jul 2013

    Directory traversal vulnerability in index.php in PHP Upload Center allows remote attackers to read arbitrary files via "../" sequences in the filename parameter.

    Source:liz0
    Published:1 Dec 2005
    7.5
    High

    CVE-2005-3944

    Last Modified: 7 Jul 2013

    SQL injection vulnerability in survey.php in ilyav Survey System 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the SURVEY_ID parameter.

    Source:r0t
    Published:1 Dec 2005
    7.5
    High

    CVE-2005-3943

    Last Modified: 7 Jul 2013

    Multiple SQL injection vulnerabilities in ilyav FAQ System 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) FAQ_ID and (2) action parameters in (a) viewFAQ.php; and (3) CATEGORY_ID parameter in (b) index.php.

    Source:r0t
    Published:1 Dec 2005
    7.5
    High

    CVE-2005-3942

    Last Modified: 7 Jul 2013

    SQL injection vulnerability in knowledgebase-control.php in Orca Knowledgebase 2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter.

    Source:r0t
    Published:1 Dec 2005
    7.5
    High

    CVE-2005-3941

    Last Modified: 7 Jul 2013

    SQL injection vulnerability in blog.php in Orca Blog 1.3b and earlier allows remote attackers to execute arbitrary SQL commands via the msg parameter.

    Source:r0t
    Published:1 Dec 2005
    7.5
    High

    CVE-2005-3940

    Last Modified: 7 Jul 2013

    SQL injection vulnerability in ringmaker.php in Orca Ringmaker 2.3c and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter.

    Source:r0t
    Published:1 Dec 2005
    7.5
    High

    CVE-2005-3939

    Last Modified: 7 Jul 2013

    Multiple SQL injection vulnerabilities in WSN Knowledge Base 1.2.0 and earler allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) perpage, (3) ascdesc, and (4) orderlinks in a displaycat action in (a) index.php; and the (5) id parameter in (b) comments.php and (c) memberlist.php.

    Source:r0t
    Published:1 Dec 2005
    7.5
    High

    CVE-2005-3938

    Last Modified: 7 Jul 2013

    SQL injection vulnerability in Softbiz FAQ Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the id parameter in (1) index.php, (2) faq_qanda.php, (3) refer_friend.php, (4) print_article.php, or (5) add_comment.php.

    Source:r0t
    Published:1 Dec 2005
    7.5
    High

    CVE-2005-3937

    Last Modified: 27 Oct 2016

    SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php.

    Source:AnGrY BoY
    Published:1 Dec 2005
    7.5
    High

    CVE-2005-3935

    Last Modified: 7 Jul 2013

    SQL injection vulnerability in SocketKB 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) node and (2) art_id parameters.

    Source:r0t
    Published:1 Dec 2005
    7.8
    High

    CVE-2005-3934

    Last Modified: 7 Jul 2013

    Buffer overflow in Symantec pcAnywhere 11.0.1, 11.5.1, and all other 32-bit versions allows remote attackers to cause a denial of service (application crash) via unknown attack vectors.

    Source:David Maciejak
    Published:1 Dec 2005
    7.5
    High

    CVE-2005-3933

    Last Modified: 8 Jul 2013

    SQL injection vulnerability in index.php in 88Script's Event Calendar 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter.

    Source:r0t
    Published:1 Dec 2005
    7.5
    High

    CVE-2005-3932

    Last Modified: 8 Jul 2013

    SQL injection vulnerability in okiraku.php in O-Kiraku Nikki 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the day_id parameter.

    Source:r0t
    Published:1 Dec 2005
    7.5
    High

    CVE-2005-3931

    Last Modified: 7 Jul 2013

    SQL injection vulnerability in default.asp in ASP-Rider 1.6 allows remote attackers to execute arbitrary SQL commands via the HTTP referer.

    Published:1 Dec 2005
    7.5
    High

    CVE-2005-3930

    Last Modified: 7 Jul 2013

    SQL injection vulnerability in index.php in N-13 News 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:KingOfSka
    Published:1 Dec 2005
    5
    Medium

    CVE-2005-3929

    Last Modified: 13 Jun 2016

    Directory traversal vulnerability in the create function in xarMLSXML2PHPBackend.php in Xaraya 1.0 allows remote attackers to create directories and overwrite arbitrary files via ".." sequences in the module parameter to index.php.

    Source:rgod
    Published:30 Nov 2005
    4.6
    Medium

    CVE-2005-3928

    Last Modified: 16 Apr 2026

    Buffer overflow in phgrafx in QNX 6.2.1 and 6.3.0 allows local users to execute arbitrary code via a long command line argument.

    Source:p. minervini
    Published:30 Nov 2005
    6.4
    Medium

    CVE-2005-3927

    Last Modified: 6 Jul 2013

    Multiple directory traversal vulnerabilities in GuppY 4.5.9 and earlier allow remote attackers to read and include arbitrary files via (1) the meskin parameter to admin/editorTypetool.php, or the lng parameter to the in admin/inc scripts (2) archbatch.php, (3) dbbatch.php, and (4) nwlmail.php.

    Published:30 Nov 2005
    7.5
    High

    CVE-2005-3926

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in error.php in GuppY 4.5.9 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via the _SERVER[REMOTE_ADDR] parameter, which is injected into a .inc script that is later included by the main script.

    Source:rgod
    Published:30 Nov 2005
    7.5
    High

    CVE-2005-3925

    Last Modified: 6 Jul 2013

    Multiple SQL injection vulnerabilities in Central Manchester CLC Helpdesk Issue Manager 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) detail[], (2) orderdir, and (3) orderby parameters to find.php, and the (4) id parameter to issue.php.

    Source:r0t3d3Vil
    Published:30 Nov 2005
    7.5
    High

    CVE-2005-3924

    Last Modified: 6 Jul 2013

    SQL injection vulnerability in themes/kategorie/index.php in Randshop allows remote attackers to execute arbitrary SQL commands via the (1) kategorieid and (2) katid parameters.

    Source:liz0
    Published:30 Nov 2005
    7.5
    High

    CVE-2005-3920

    Last Modified: 5 Jul 2013

    SQL injection vulnerability in Babe Logger 2 allows remote attackers to execute arbitrary SQL commands via the (1) gal parameter to index.php or (2) id parameter to comments.php.

    Source:r0t
    Published:30 Nov 2005
    4.3
    Medium

    CVE-2005-3919

    Last Modified: 4 Jul 2013

    Cross-site scripting (XSS) vulnerability in PBLang 4.65 allows remote attackers to inject arbitrary web script or HTML via multiple fields in (1) UCP.php and (2) SendPm.php.

    Source:r0xes
    Published:30 Nov 2005
    7.5
    High

    CVE-2005-3918

    Last Modified: 4 Jul 2013

    Multiple SQL injection vulnerabilities in OvBB 0.08a allow remote attackers to execute arbitrary SQL commands via the (1) threadid parameter to thread.php and (2) userid parameter to profile.php. NOTE: the vendor disputes these issues, saying "these reports are completely unsubstantial.

    Source:r0t3d3Vil
    Published:30 Nov 2005
    7.5
    High

    CVE-2005-3916

    Last Modified: 3 Jul 2013

    SQL injection vulnerability in memberlist.php in WSN Forum 1.21 allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action.

    Source:r0t
    Published:30 Nov 2005
    6.4
    Medium

    CVE-2005-3914

    Last Modified: 3 Jul 2013

    Multiple SQL injection vulnerabilities in AFFcommerce 1.1.4 allow remote attackers to execute arbitrary SQL commands via (1) the cl parameter to SubCategory.php and the item_id parameter in (2) ItemInfo.php and (3) ItemReview.php.

    Source:r0t3d3Vil
    Published:30 Nov 2005
    7.5
    High

    CVE-2005-3911

    Last Modified: 7 Jul 2013

    Multiple SQL injection vulnerabilities in calendar.php in BosDates 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) category parameters.

    Source:r0t
    Published:30 Nov 2005
    7.5
    High

    CVE-2005-3909

    Last Modified: 7 Jul 2013

    SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 2.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the sortorder parameter.

    Source:r0t
    Published:30 Nov 2005
    4.3
    Medium

    CVE-2005-3908

    Last Modified: 7 Jul 2013

    Cross-site scripting (XSS) vulnerability in search.php in GhostScripter Amazon Shop 5.0.0, and other versions before 5.0.2, allows remote attackers to inject web script or HTML via the query parameter.

    Source:r0t
    Published:30 Nov 2005
    4.3
    Medium

    CVE-2005-3902

    Last Modified: 3 Jul 2013

    Cross-site scripting (XSS) vulnerability in gui/errordocs/index.php in Virtual Hosting Control System (VHCS) 2.2.0 through 2.4.6.2 allows remote attackers to inject arbitrary web script or HTML via query strings that are included in an error message, as demonstrated using a parameter containing script.

    Source:Moritz Naumann
    Published:29 Nov 2005
    4.3
    Medium

    CVE-2005-3894

    Last Modified: 2 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) hex-encoded values in the QueueID parameter and (2) Action parameters.

    Source:Moritz Naumann
    Published:29 Nov 2005
    7.5
    High

    CVE-2005-3893

    Last Modified: 2 Jul 2013

    Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) user parameter in the Login action, and remote authenticated users via the (2) TicketID and (3) ArticleID parameters of the AgentTicketPlain action.

    Source:Moritz Naumann
    Published:29 Nov 2005
    7.5
    High

    CVE-2005-3884

    Last Modified: 5 Jul 2013

    Multiple SQL injection vulnerabilities in the search action in Zainu 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term and (2) start parameters to index.php.

    Source:r0t
    Published:29 Nov 2005
    7.5
    High

    CVE-2005-3882

    Last Modified: 7 Jul 2013

    SQL injection vulnerability in answer.php in FAQSystems FAQRing Knowledge Base Software 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:r0t
    Published:29 Nov 2005
    7.5
    High

    CVE-2005-3879

    Last Modified: 5 Jul 2013

    Multiple SQL injection vulnerabilities in Softbiz Resource Repository Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sbres_id parameter in (a) details_res.php, (b) refer_friend.php, and (c) report_link.php, and (2) the sbcat_id parameter in (d) showcats.php.

    Source:r0t
    Published:29 Nov 2005
    6.4
    Medium

    CVE-2005-3878

    Last Modified: 6 Jul 2013

    Directory traversal vulnerability in index.php in PHP Doc System 1.5.1 and earlier allows remote attackers to access or include arbitrary files via a .. (dot dot) in the show parameter.

    Source:r0t
    Published:29 Nov 2005
    7.5
    High

    CVE-2005-3877

    Last Modified: 6 Jul 2013

    Multiple SQL injection vulnerabilities in Simple Document Management System (SDMS) 2.0-CVS and earlier allow remote attackers to execute arbitrary SQL commands via the (1) folder_id parameter in list.php and (2) mid parameter in a view action to messages.php.

    Source:r0t
    Published:29 Nov 2005
    7.5
    High

    CVE-2005-3875

    Last Modified: 5 Jul 2013

    Multiple SQL injection vulnerabilities in Enterprise Connector 1.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the messageid parameter in (1) send.php or (2) a delete action in messages.php.

    Source:r0t
    Published:29 Nov 2005
    7.5
    High

    CVE-2005-3874

    Last Modified: 6 Jul 2013

    SQL injection vulnerability in netzbr.php in Netzbrett 1.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the p_entry parameter in an entry command to index.php.

    Source:r0t
    Published:29 Nov 2005
    7.5
    High

    CVE-2005-3873

    Last Modified: 6 Jul 2013

    SQL injection vulnerability in topic.php in ShockBoard 3.0 and 4.0 allows remote attackers to execute arbitrary SQL commands via the offset parameter.

    Source:r0t
    Published:29 Nov 2005
    7.5
    High

    CVE-2005-3872

    Last Modified: 6 Jul 2013

    Multiple SQL injection vulnerabilities in Ugroup 2.6.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) FORUM_ID parameter in forum.php, and the (2) TOPIC_ID, (3) FORUM_ID, and (4) CAT_ID parameters in topic.php.

    Source:r0t
    Published:29 Nov 2005
    7.5
    High

    CVE-2005-3870

    Last Modified: 6 Jul 2013

    Multiple SQL injection vulnerabilities in edmobbs9r.php in edmoBBS 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) table and (2) messageID parameters.

    Source:r0t
    Published:29 Nov 2005