4.3
    Medium

    CVE-2005-3695

    Last Modified: 2 Jul 2013

    Cross-site scripting (XSS) vulnerability in admin/config/confMgr.php in LiteSpeed Web Server 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the m parameter.

    Source:Gama Sec
    Published:20 Nov 2005
    7.8
    High

    CVE-2005-3694

    Last Modified: 7 Jul 2013

    centericq 4.20.0-r3 with "Enable peer-to-peer communications" set allows remote attackers to cause a denial of service (segmentation fault and crash) via short zero-length packets, and possibly packets of length 1 or 2, as demonstrated using Nessus.

    Source:Wernfried Haas
    Published:20 Nov 2005
    7.5
    High

    CVE-2005-3686

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.inc.php in Unclassified NewsBoard before 1.5.3 Patch 4 allows remote attackers to execute arbitrary SQL commands via the (1) DateFrom or (2) DateUntil parameter to forum.php.

    Source:rgod
    Published:19 Nov 2005
    4.3
    Medium

    CVE-2005-3685

    Last Modified: 2 Jul 2013

    Cross-site scripting (XSS) vulnerability in shopadmin.asp in VP-ASP Shopping Cart 5.50 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter.

    Source:ConcorDHacK
    Published:19 Nov 2005
    7.5
    High

    CVE-2005-3684

    Last Modified: 30 Oct 2016

    Multiple buffer overflows in freeFTPd 1.0.8, without logging enabled, allow remote authenticated attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via long (1) MKD and (2) DELE commands.

    Source:Expanders
    Published:19 Nov 2005
    7.5
    High

    CVE-2005-3683

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in freeFTPd before 1.0.9 with Logging enabled, allows remote attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via a long USER command.

    Source:Metasploit
    Published:19 Nov 2005
    7.5
    High

    CVE-2005-3682

    Last Modified: 1 Jul 2013

    Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (1) the AuthID parameter in ForumAuthDetails.php, and the TopicID parameter in (2) ForumTopicDetails.php and (3) ForumReply.php.

    Source:HACKERS PAL
    Published:18 Nov 2005
    7.5
    High

    CVE-2005-3681

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in viewcat.php in XOOPS WF-Downloads module 2.05 allows remote attackers to execute arbitrary SQL commands via the list parameter.

    Source:rgod
    Published:18 Nov 2005
    7.5
    High

    CVE-2005-3679

    Last Modified: 1 Jul 2013

    SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username field in the admin control panel.

    Source:bhs_team
    Published:18 Nov 2005
    7.5
    High

    CVE-2005-3676

    Last Modified: 1 Jul 2013

    SQL injection vulnerability in download.php in PhpWebThings 1.4.4 allows remote attackers to execute arbitrary SQL commands via the file parameter.

    Source:A.1.M
    Published:18 Nov 2005
    2.6
    Low

    CVE-2005-3649

    Last Modified: 16 Apr 2026

    jumpto.php in Moodle 1.5.2 allows remote attackers to redirect users to other sites via the jump parameter.

    Source:rgod
    Published:17 Nov 2005
    7.8
    High

    CVE-2005-3644

    Last Modified: 16 Apr 2026

    PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a DCE RPC request that specifies a large output buffer size, a variant of CVE-2006-6296, and a different vulnerability than CVE-2005-2120.

    Source:Winny Thomas
    Published:17 Nov 2005
    10
    Critical

    CVE-2005-3640

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the IMAP Groupware Mail server of Floosietek FTGate (FTGate4) 4.1 allow remote attackers to execute arbitrary code via long arguments to various IMAP commands, as demonstrated with the EXAMINE command.

    Source:Luca Ercoli
    Published:16 Nov 2005
    7.5
    High

    CVE-2005-3639

    Last Modified: 1 Jul 2013

    PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to access or include arbitrary files via the file parameter, possibly due to a directory traversal vulnerability.

    Source:HACKERS PAL
    Published:16 Nov 2005
    4.3
    Medium

    CVE-2005-3638

    Last Modified: 1 Jul 2013

    Cross-site scripting (XSS) vulnerabilities in Ekinboard 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in profile.php and (2) titles of posts.

    Source:trueend5
    Published:16 Nov 2005
    4.3
    Medium

    CVE-2005-3636

    Last Modified: 30 Jun 2013

    Cross-site scripting (XSS) vulnerability in SAP Web Application Server (WAS) 6.10 allows remote attackers to inject arbitrary web script or HTML via Error Pages.

    Source:Leandro Meiners
    Published:16 Nov 2005
    4.3
    Medium

    CVE-2005-3635

    Last Modified: 30 Jun 2013

    Multiple cross-site scripting (XSS) vulnerabilities in SAP Web Application Server (WAS) 6.10 through 7.00 allow remote attackers to inject arbitrary web script or HTML via (1) the sap-syscmd in sap-syscmd and (2) the BspApplication field in the SYSTEM PUBLIC test application.

    Source:Leandro Meiners
    Published:16 Nov 2005
    5
    Medium

    CVE-2005-3634

    Last Modified: 30 Jun 2013

    frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.

    Source:Leandro Meiners
    Published:16 Nov 2005
    7.5
    High

    CVE-2005-3591

    Last Modified: 16 Apr 2026

    Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the ActionDefineFunction ActionScript call in a SWF file, which causes an improper memory access condition, a different vulnerability than CVE-2005-2628.

    Source:BassReFLeX
    Published:16 Nov 2005
    7.8
    High

    CVE-2005-3589

    Last Modified: 13 Jun 2016

    Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal crash) via a long USER ftp command.

    Source:Inge Henriksen
    Published:16 Nov 2005
    4.3
    Medium

    CVE-2005-3584

    Last Modified: 26 Jun 2013

    Cross-site scripting (XSS) vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to inject arbitrary web script or HTML via the forum parameter.

    Source:Linux_Drox
    Published:16 Nov 2005
    5
    Medium

    CVE-2005-3579

    Last Modified: 1 Jul 2013

    ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to access arbitrary local files via the querystring.

    Source:Rafi Nahum
    Published:16 Nov 2005
    7.5
    High

    CVE-2005-3578

    Last Modified: 1 Jul 2013

    SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary SQL commands via the sug parameter.

    Source:Rafi Nahum
    Published:16 Nov 2005
    4.3
    Medium

    CVE-2005-3577

    Last Modified: 1 Jul 2013

    Cross-site scripting vulnerability (XSS) in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the sug parameter.

    Source:Rafi Nahum
    Published:16 Nov 2005
    5
    Medium

    CVE-2005-3576

    Last Modified: 1 Jul 2013

    ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the article number in tsurl parameter.

    Source:Rafi Nahum
    Published:16 Nov 2005
    7.5
    High

    CVE-2005-3575

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in show.php in Cyphor 0.19 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:HACKERS PAL
    Published:16 Nov 2005
    5
    Medium

    CVE-2005-3571

    Last Modified: 1 Jul 2013

    PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote attackers to include arbitrary local files via the siteurl parameter when register_globals is enabled. NOTE: It was later reported that PHPFanBase 2.2 is also affected.

    Source:Robin Verton
    Published:16 Nov 2005
    4.3
    Medium

    CVE-2005-3566

    Last Modified: 16 Apr 2026

    Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6) haclus, (7) haconf, (8) hadebug, (9) hagrp, (10) hahb, (11) halog, (12) hareg, (13) hares, (14) hastatus, (15) hasys, (16) hatype, (17) hauser, and (18) tststew.

    Source:Kevin Finisterre
    Published:16 Nov 2005
    7.5
    High

    CVE-2005-3560

    Last Modified: 30 Jun 2013

    Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1, and (5) ZoneAlarm 6.0 allow remote attackers to bypass the "Advanced Program Control and OS Firewall filters" setting via URLs in "HTML Modal Dialogs" (window.location.href) contained within JavaScript tags.

    Source:Tr0y-x
    Published:16 Nov 2005
    5
    Medium

    CVE-2005-3559

    Last Modified: 29 Jun 2013

    Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. (dot dot) in the folder parameter.

    Source:Adam Pointon
    Published:16 Nov 2005
    7.5
    High

    CVE-2005-3558

    Last Modified: 29 Jun 2013

    PHP file inclusion vulnerability in index.php in OSTE 1.0 allows remote attackers to execute arbitrary code via the (1) page and (2) site parameters.

    Published:16 Nov 2005
    4.3
    Medium

    CVE-2005-3556

    Last Modified: 30 Jun 2013

    Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listname parameter in (a) admin/editlist.php, (2) title parameter in (b) admin/spageedit.php, (3) title field in (c) admin/template.php, (4) filter, (5) delete, and (6) start parameters in (d) admin/eventlog.php, (7) id parameter in (e) admin/configure.php, (8) find parameter in (f) admin/users.php, (9) start parameter in (g) admin/admin.php, and (10) action parameter in (h) admin/fckphplist.php.

    Source:Tobias Klein
    Published:16 Nov 2005
    6.5
    Medium

    CVE-2005-3555

    Last Modified: 30 Jun 2013

    Multiple SQL injection vulnerabilities in PHPlist 2.10.1 and earlier allow authenticated remote attackers with administrator privileges to execute arbitrary SQL commands via the id parameter in the (1) editattributes or (2) admin page.

    Source:Tobias Klein
    Published:16 Nov 2005
    5
    Medium

    CVE-2005-3550

    Last Modified: 30 Jun 2013

    Directory traversal vulnerability in admin.php in toendaCMS before 0.6.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the id_user parameter.

    Source:Bernhard Mueller
    Published:16 Nov 2005
    4.3
    Medium

    CVE-2005-3547

    Last Modified: 8 Jan 2018

    Cross-site scripting (XSS) vulnerability in Invision Power Board 2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) adsess, (2) name, and (3) description parameters in admin.php, and the (4) ACP Notes, (5) Member Name, (6) Password, (7) Email Address, (8) Components, and multiple other input fields.

    Source:benjilenoob
    Published:16 Nov 2005
    7.2
    High

    CVE-2005-3546

    Last Modified: 7 Nov 2017

    suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege.

    Source:Xavier de Leon
    Published:16 Nov 2005
    7.5
    High

    CVE-2005-3545

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php of the report module in ibProArcade 2.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.

    Source:B~HFH
    Published:16 Nov 2005
    4.3
    Medium

    CVE-2005-3544

    Last Modified: 5 Jan 2018

    Cross-site scripting (XSS) vulnerability in u2u.php in XMB 1.9.3 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Source:GulfTech Security
    Published:16 Nov 2005
    7.5
    High

    CVE-2005-3539

    Last Modified: 23 Jul 2013

    Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.

    Source:Patrice Fournier
    Published:31 Dec 2005
    7.2
    High

    CVE-2005-3533

    Last Modified: 21 Apr 2016

    Buffer overflow in OSH before 1.7-15 allows local users to execute arbitrary code via a long current working directory and filename.

    Source:Charles Stevenson
    Published:11 Dec 2005
    10
    Critical

    CVE-2005-3524

    Last Modified: 5 Dec 2016

    Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrary code by creating a long directory name, then executing the XPWD command.

    Source:kingcope
    Published:7 Nov 2005
    7.5
    High

    CVE-2005-3523

    Last Modified: 7 Jun 2016

    Format string vulnerability in friendsd2 in GpsDrive allows remote attackers to execute arbitrary code via the dir (direction) field.

    Source:Kevin Finisterre
    Published:7 Nov 2005
    4.3
    Medium

    CVE-2005-3522

    Last Modified: 21 Jun 2013

    Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the grDisp parameter.

    Published:6 Nov 2005
    4.3
    Medium

    CVE-2005-3520

    Last Modified: 21 Jun 2013

    Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web script or HTML via (1) the target_url parameter in upgrade_in_progress_backend.php, (2) the stylesheet parameter in edit_table_cell_type_wysiwyg.php, and the bgcolor parameter in (3) insert_table.php, (4) edit_table_cell_props.php, (5) header.php, (6) edit_table_row_props.php, and (7) edit_table_props.php.

    Source:Secunia Research
    Published:6 Nov 2005
    7.5
    High

    CVE-2005-3519

    Last Modified: 22 Jun 2013

    Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and include arbitrary local files via the (1) INCLUDE_PATH and (2) SQUIZLIB_PATH parameters in new_upgrade_functions.php, (3) the INCLUDE_PATH parameter in init_mysource.php, and the PEAR_PATH parameter in (4) Socket.php, (5) Request.php, (6) Mail.php, (7) Date.php, (8) Span.php, (9) mimeDecode.php, and (10) mime.php.

    Source:Secunia Research
    Published:6 Nov 2005
    7.5
    High

    CVE-2005-3518

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL commands via the old_searches parameter.

    Source:Devil_box
    Published:6 Nov 2005
    4.3
    Medium

    CVE-2005-3516

    Last Modified: 23 Jun 2013

    Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Directory script allows remote attackers to inject arbitrary web script or HTML via the entryID parameter.

    Source:Alireza Hassani
    Published:6 Nov 2005
    4.3
    Medium

    CVE-2005-3515

    Last Modified: 23 Jun 2013

    Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Topsites script allows remote attackers to inject arbitrary web script or HTML via the ID parameter.

    Source:Alireza Hassani
    Published:6 Nov 2005
    4.3
    Medium

    CVE-2005-3514

    Last Modified: 23 Jun 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Forum script allow remote attackers to inject arbitrary web script or HTML via the forumID parameter to (1) newtopic.php, (2) quote.php, (3) index.php, and (4) reply.php.

    Source:Alireza Hassani
    Published:6 Nov 2005
    4.3
    Medium

    CVE-2005-3512

    Last Modified: 26 Jun 2013

    Cross-site scripting (XSS) vulnerability in index.php in VUBB alpha rc1 allows remote attackers to inject arbitrary web script or HTML via the t parameter in a newreply action.

    Source:Alireza Hassani
    Published:6 Nov 2005