7.5
    High

    CVE-2005-3868

    Last Modified: 27 Oct 2016

    Multiple SQL injection vulnerabilities in K-Search 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term, (2) id, (3) stat, and (4) source parameters to index.php, and (5) through the image parameters with an add request.

    Source:Sangteamtham
    Published:29 Nov 2005
    7.5
    High

    CVE-2005-3865

    Last Modified: 5 Jul 2013

    SQL injection vulnerability in index.php in AllWeb search 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameter.

    Source:r0t
    Published:29 Nov 2005
    7.5
    High

    CVE-2005-3864

    Last Modified: 5 Jul 2013

    SQL injection vulnerability in index.php in SourceWell 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the cnt parameter. NOTE: various reports indicate that the affected version is 1.1.3, but as of 2005-11-29, the most recent version appears to be 1.1.2.

    Source:r0t
    Published:29 Nov 2005
    7.5
    High

    CVE-2005-3862

    Last Modified: 5 Jul 2013

    Buffer overflow in unalz before 0.53 allows remote attackers to execute arbitrary code via long file names in ALZ archives.

    Source:Ulf Harnhammar
    Published:29 Nov 2005
    7.5
    High

    CVE-2005-3861

    Last Modified: 4 Jul 2013

    PHP remote file inclusion vulnerability in content.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.

    Source:[GB]
    Published:29 Nov 2005
    7.5
    High

    CVE-2005-3860

    Last Modified: 4 Jul 2013

    PHP remote file inclusion vulnerability in athena.php in Oliver May Athena PHP Website Administration 0.1a allows remote attackers to execute arbitrary PHP code via a URL in the athena_dir parameter.

    Source:[GB]
    Published:29 Nov 2005
    7.5
    High

    CVE-2005-3859

    Last Modified: 5 Jul 2013

    PHP remote file inclusion vulnerability in q-news.php in Q-News 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.

    Source:[GB]
    Published:29 Nov 2005
    4.9
    Medium

    CVE-2005-3857

    Last Modified: 6 Sept 2016

    The time_out_leases function in locks.c for Linux kernel before 2.6.15-rc3 allows local users to cause a denial of service (kernel log message consumption) by causing a large number of broken leases, which is recorded to the log using the printk function.

    Source:Avi Kivity
    Published:13 Nov 2005
    7.5
    High

    CVE-2005-3855

    Last Modified: 3 Jul 2013

    SQL injection vulnerability in process.php in 1-2-3 music store allows remote attackers to execute arbitrary SQL commands via the AlbumID parameter.

    Source:r0t
    Published:27 Nov 2005
    7.5
    High

    CVE-2005-3853

    Last Modified: 31 Jul 2013

    SQL injection vulnerability in snews.php in sNews 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category parameters to index.php.

    Source:joffer
    Published:27 Nov 2005
    4.3
    Medium

    CVE-2005-3849

    Last Modified: 3 Jul 2013

    Cross-site scripting (XSS) vulnerability in the Search module in PmWiki up to 2.0.12 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Source:Moritz Naumann
    Published:27 Nov 2005
    7.5
    High

    CVE-2005-3846

    Last Modified: 7 Jul 2013

    SQL injection vulnerability in news.php in Fantastic News 2.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Source:r0t3d3Vil
    Published:26 Nov 2005
    7.5
    High

    CVE-2005-3845

    Last Modified: 23 Jul 2013

    SQL injection vulnerability in invoices.php in EZ Invoice Inc 2.0 allows remote attackers to execute arbitrary SQL commands via the i parameter. NOTE: the vendor has stated "EZ Invoice, Inc has a patah available. Please email [email protected] and EZI will email you the patch to fix this small issue."

    Source:r0t3d3Vil
    Published:26 Nov 2005
    7.5
    High

    CVE-2005-3844

    Last Modified: 5 Jul 2013

    SQL injection vulnerability in phpWordPress PHP News and Article Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) poll and (2) category parameters to index.php, and (3) the ctg parameter in an archive action.

    Source:r0t
    Published:26 Nov 2005
    7.5
    High

    CVE-2005-3838

    Last Modified: 4 Jul 2013

    Multiple SQL injection vulnerabilities in search.php in IsolSoft Support Center 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) lorder, (2) Priority, (3) Status, (4) Category, (5) searchvalue, and (6) field parameter.

    Source:r0t3d3Vil
    Published:26 Nov 2005
    4.3
    Medium

    CVE-2005-3834

    Last Modified: 3 Jul 2013

    Cross-site scripting (XSS) vulnerability in search.php in Tunez 1.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchFor parameter.

    Source:r0t3d3Vil
    Published:26 Nov 2005
    7.5
    High

    CVE-2005-3833

    Last Modified: 3 Jul 2013

    SQL injection vulnerability in songinfo.php in Tunez 1.21 and earlier allows remote attackers to execute arbitrary SQL commands via the song_id parameter.

    Source:r0t3d3Vil
    Published:26 Nov 2005
    7.5
    High

    CVE-2005-3827

    Last Modified: 4 Jul 2013

    SQL injection vulnerability in product_cat in AgileBill 1.4.92 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:r0t
    Published:26 Nov 2005
    7.5
    High

    CVE-2005-3826

    Last Modified: 3 Jul 2013

    Multiple SQL injection vulnerabilities in Ezyhelpdesk 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) edit_id, (2) faq_id, and (3) c_id parameters in a query string, and (4) the search engine, possibly involving the search_string parameter.

    Source:r0t
    Published:26 Nov 2005
    7.5
    High

    CVE-2005-3825

    Last Modified: 4 Jul 2013

    SQL injection vulnerability in index.php in Comdev Vote Caster 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the campaign_id parameter in a result action.

    Source:r0t
    Published:26 Nov 2005
    7.5
    High

    CVE-2005-3819

    Last Modified: 4 Oct 2017

    Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass authentication via the (1) user_name and (2) date parameter in the HelpDesk module.

    Source:Christopher Kunz
    Published:26 Nov 2005
    4.3
    Medium

    CVE-2005-3818

    Last Modified: 4 Oct 2017

    Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) various input fields, including the contact, lead, and first or last name fields, (2) the record parameter in a DetailView action in the Leads module for index.php, (3) the $_SERVER['PHP_SELF'] variable, which is used in multiple locations such as index.php, and (4) aggregated RSS feeds in the RSS aggregation module.

    Source:Christopher Kunz
    Published:26 Nov 2005
    7.5
    High

    CVE-2005-3817

    Last Modified: 4 Jul 2013

    Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2) sbres_id parameter in review.php, (3) cid parameter in browsecats.php, (4) h_id parameter in email.php, and (5) an unspecified parameter to the search module.

    Source:r0t
    Published:26 Nov 2005
    7.5
    High

    CVE-2005-3816

    Last Modified: 3 Jul 2013

    Multiple SQL injection vulnerabilities in forum.php in freeForum 1.1 and earlier and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter or (2) thread parameter in thread mode.

    Source:r0t3d3Vil
    Published:26 Nov 2005
    7.5
    High

    CVE-2005-3815

    Last Modified: 4 Jul 2013

    SQL injection vulnerability in forum.php in Orca Forum 4.3b and earlier allows remote attackers to execute arbitrary SQL commands via the msg parameter.

    Source:r0t3d3Vil
    Published:26 Nov 2005
    4
    Medium

    CVE-2005-3813

    Last Modified: 3 Jul 2013

    IMAP service (meimaps.exe) of MailEnable Professional 1.7 and Enterprise 1.1 allows remote authenticated attackers to cause a denial of service (application crash) by using RENAME with a non-existent mailbox, a different vulnerability than CVE-2005-3690.

    Source:Josh Zlatin-Amishav
    Published:26 Nov 2005
    6.8
    Medium

    CVE-2005-3812

    Last Modified: 30 Oct 2016

    freeFTPd 1.0.10 allows remote authenticated users to cause a denial of service (null dereference and crash) via a PORT command with missing arguments.

    Source:Stefan Lochbihler
    Published:26 Nov 2005
    5
    Medium

    CVE-2005-3811

    Last Modified: 29 Sept 2016

    Directory traversal vulnerability in admin/main.php in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to overwrite arbitrary files with session information via the sid parameter.

    Source:rgod
    Published:25 Nov 2005
    4.9
    Medium

    CVE-2005-3808

    Last Modified: 6 Sept 2016

    Integer overflow in the invalidate_inode_pages2_range function in mm/truncate.c in Linux kernel 2.6.11 to 2.6.14 allows local users to cause a denial of service (hang) via 64-bit mmap calls that are not properly handled on a 32-bit system.

    Source:Oleg Drokin
    Published:25 Nov 2005
    4.9
    Medium

    CVE-2005-3807

    Last Modified: 6 Sept 2016

    Memory leak in the VFS file lease handling in locks.c in Linux kernels 2.6.10 to 2.6.15 allows local users to cause a denial of service (memory exhaustion) via certain Samba activities that cause an fasync entry to be re-allocated by the fcntl_setlease function after the fasync queue has already been cleaned by the locks_delete_lock function.

    Source:J. Bruce Fields
    Published:25 Nov 2005
    7.5
    High

    CVE-2005-3797

    Last Modified: 1 Jul 2013

    PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary PHP code via the config[basepath] parameter.

    Source:Robin Verton
    Published:24 Nov 2005
    7.5
    High

    CVE-2005-3792

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in the Search module in PHP-Nuke 7.8, and possibly other versions before 7.9 with patch 3.1, allows remote attackers to execute arbitrary SQL commands, as demonstrated via the query parameter in a stories type.

    Source:anonymous
    Published:24 Nov 2005
    4.3
    Medium

    CVE-2005-3790

    Last Modified: 1 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in act_newsletter.php in phpwcms 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) i and (2) text parameters.

    Source:Stefan Lochbihler
    Published:24 Nov 2005
    5
    Medium

    CVE-2005-3789

    Last Modified: 22 Dec 2016

    Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) form_lang parameter in login.php and (2) the imgdir parameter in random_image.php.

    Source:Stefan Lochbihler
    Published:24 Nov 2005
    5
    Medium

    CVE-2005-3774

    Last Modified: 16 Apr 2026

    Cisco PIX 6.3 and 7.0 allows remote attackers to cause a denial of service (blocked new connections) via spoofed TCP packets that cause the PIX to create embryonic connections that that would not produce a valid connection with the end system, including (1) SYN packets with invalid checksums, which do not result in a RST; or, from an external interface, (2) one byte of "meaningless data," or (3) a TTL that is one less than needed to reach the internal destination.

    Source:Janis Vizulis
    Published:23 Nov 2005
    4.3
    Medium

    CVE-2005-3770

    Last Modified: 2 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in PHP-Post (PHPp) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the subject in a post, or the user parameter to (2) profile.php and (3) mail.php.

    Source:trueend5
    Published:23 Nov 2005
    7.5
    High

    CVE-2005-3769

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in files.php in PHP Download Manager 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:ksa_ksa82
    Published:23 Nov 2005
    7.5
    High

    CVE-2005-3757

    Last Modified: 16 Apr 2026

    The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to obtain sensitive information and execute arbitrary code via dangerous Java class methods in select attribute of xsl:value-of tags in XSLT style sheets, such as (1) system-property, (2) sys:getProperty, and (3) run:exec.

    Source:H D Moore
    Published:22 Nov 2005
    7.5
    High

    CVE-2005-3748

    Last Modified: 2 Jul 2013

    SQL injection vulnerability in the Search module in Tru-Zone Nuke ET 3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the query parameter.

    Source:Lostmon
    Published:22 Nov 2005
    5
    Medium

    CVE-2005-3747

    Last Modified: 7 Mar 2012

    Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters. NOTE: this might be the same issue as CVE-2006-2758.

    Source:LiquidWorm
    Published:22 Nov 2005
    7.5
    High

    CVE-2005-3746

    Last Modified: 2 Jul 2013

    SQL injection vulnerability in thread.php in APBoard allows remote attackers to execute arbitrary SQL commands via the start parameter.

    Source:ksa_ksa82
    Published:22 Nov 2005
    4.3
    Medium

    CVE-2005-3745

    Last Modified: 2 Jul 2013

    Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.

    Source:Irene Abezgauz
    Published:21 Nov 2005
    7.5
    High

    CVE-2005-3743

    Last Modified: 2 Jul 2013

    SQL injection vulnerability in results.php in SimplePoll allows remote attackers to execute arbitrary SQL commands via the pollid parameter.

    Source:stranger-killer
    Published:22 Nov 2005
    4.3
    Medium

    CVE-2005-3742

    Last Modified: 2 Jul 2013

    Cross-site scripting (XSS) vulnerability in popup.php in Advanced Poll 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the poll_ident parameter.

    Source:[GB]
    Published:22 Nov 2005
    2.6
    Low

    CVE-2005-3738

    Last Modified: 13 Jun 2016

    globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content.html.php for remote PHP file inclusion.

    Source:rgod
    Published:22 Nov 2005
    5.1
    Medium

    CVE-2005-3737

    Last Modified: 22 Jul 2013

    Buffer overflow in the SVG importer (style.cpp) of inkscape 0.41 through 0.42.2 might allow remote attackers to execute arbitrary code via a SVG file with long CSS style property values.

    Source:Joxean Koret
    Published:22 Nov 2005
    4.3
    Medium

    CVE-2005-3730

    Last Modified: 2 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in HTTPTranslatorServlet in Idetix Software Systems Revize CMS allow remote attackers to inject arbitrary web script or HTML via the (1) resourcetype, (2) objectmap, and (3) redirect parameters, possibly involving setWebSpace.jsp.

    Source:Lostmon
    Published:21 Nov 2005
    5
    Medium

    CVE-2005-3728

    Last Modified: 17 Nov 2017

    Idetix Software Systems Revize CMS stores conf/revize.xml under the web document root with insufficient access control, which allows remote attackers to obtain sensitive configuration information.

    Source:Lostmon
    Published:21 Nov 2005
    7.5
    High

    CVE-2005-3727

    Last Modified: 17 Nov 2017

    SQL injection vulnerability in debug/query_results.jsp in Idetix Software Systems Revize CMS allows remote attackers to execute arbitrary SQL commands via the query parameter.

    Source:Lostmon
    Published:21 Nov 2005
    7.5
    High

    CVE-2005-3696

    Last Modified: 13 Jun 2016

    SQL injection vulnerability in Arki-DB 1.0 and 2.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a view action (view.php) to index.php.

    Source:Devil-00
    Published:20 Nov 2005